Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Binutils MEDIUM 5.5
CVE-2022-35205

An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial o…

Patch available
Fix from $1,600 2023-08-22
Binutils MEDIUM 5.5
CVE-2022-35206

Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c.

Patch available
Fix from $1,600 2023-08-22
Binutils HIGH 7.5
CVE-2021-46174

Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.

Fix: 2.38+
Fix from $1,950 2023-08-22
Binutils HIGH 7.5
CVE-2020-35342

GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers …

Fix: 2.34+
Fix from $1,950 2023-08-22
Binutils MEDIUM 5.5
CVE-2020-21490

An issue was discovered in GNU Binutils 2.34. It is a memory leak when process microblaze-dis.c. This one will consume memory on each insn disassembl…

Fix: 2.34+
Fix from $1,600 2023-08-22
Binutils HIGH 8.8
CVE-2020-19726

An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a…

No fix yet
Fix from $1,950 2023-08-22
Binutils MEDIUM 5.5
CVE-2020-19724

A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted comm…

Fix: 2.34+
Fix from $1,600 2023-08-22
Indent MEDIUM 5.5
CVE-2023-40305

GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.

No fix yet
Fix from $1,600 2023-08-14
Inetutils HIGH 7.8
CVE-2023-40303

GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rs…

Fix: after 2.4
Fix from $1,950 2023-08-14
Gdb MEDIUM 5.5
CVE-2023-39128

GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_decode at /gdb/ada-lang.c.

No fix yet
Fix from $1,600 2023-07-25
Gdb MEDIUM 5.5
CVE-2023-39129

GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym() at /gdb/coff-pe-read.c.

Mitigation only
Fix from $1,600 2023-07-25
Gdb MEDIUM 5.5
CVE-2023-39130

GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function pe_as16() at /gdb/coff-pe-read.c.

Mitigation only
Fix from $1,600 2023-07-25
Grub2 HIGH 8.1
CVE-2022-28733

Integer underflow in grub_net_recv_ip4_packets; A malicious crafted IP packet can lead to an integer underflow in grub_net_recv_ip4_packets() functio…

Fix: 2.06-3+
Fix from $1,950 2023-07-20
Grub2 HIGH 7.8
CVE-2022-28735

The GRUB2's shim_lock verifier allows non-kernel files to be loaded on shim-powered secure boot systems. Allowing such files to be loaded may lead to…

Fix: 2.06-3+
Fix from $1,950 2023-07-20
Grub2 HIGH 7.8
CVE-2022-28736

There's a use-after-free vulnerability in grub_cmd_chainloader() function; The chainloader command is used to boot up operating systems that doesn't …

Fix: 2.06-3+
Fix from $1,950 2023-07-20
Grub2 HIGH 7.0
CVE-2022-28734

Out-of-bounds write when handling split HTTP headers; When handling split HTTP headers, GRUB2 HTTP code accidentally moves its internal data buffer p…

Fix: 2.06-3+
Fix from $1,950 2023-07-20
Binutils MEDIUM 6.5
CVE-2021-32256

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.

No fix yet
Fix from $1,600 2023-07-18
Glibc MEDIUM 5.5
CVE-2015-20109

end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a d…

Fix: 2.22+
Fix from $1,600 2023-06-25
Libredwg HIGH 8.8
CVE-2023-36271

LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_wcs2nlen at bits.c.

Fix: after 0.12.5
Fix from $1,950 2023-06-23
Libredwg HIGH 8.8
CVE-2023-36272

LibreDWG v0.10 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_utf8_to_TU at bits.c.

Fix: after 0.12.5
Fix from $1,950 2023-06-23
Libredwg HIGH 8.8
CVE-2023-36273

LibreDWG v0.12.5 was discovered to contain a heap buffer overflow via the function bit_calc_CRC at bits.c.

No fix yet
Fix from $1,950 2023-06-23
Libredwg HIGH 8.8
CVE-2023-36274

LibreDWG v0.11 to v0.12.5 was discovered to contain a heap buffer overflow via the function bit_write_TF at bits.c.

Fix: after 0.12.5
Fix from $1,950 2023-06-23
Cflow HIGH 7.5
CVE-2023-2789

A vulnerability was found in GNU cflow 1.7. It has been rated as problematic. This issue affects the function func_body/parse_variable_declaration of…

No fix yet
Fix from $1,950 2023-05-18
Binutils MEDIUM 6.5
CVE-2023-1972

A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.

Fix: after 2.40
Fix from $1,600 2023-05-17
Mailman MEDIUM 6.3
CVE-2021-34337

An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the …

Fix: 3.3.5+
Fix from $1,600 2023-04-15
Screen MEDIUM 6.5
CVE-2023-24626

socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users t…

Fix: after 4.9.0
Fix from $1,600 2023-04-08
Binutils HIGH 7.8
CVE-2023-1579

Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64.

Patch available
Fix from $1,950 2023-04-03
Org Mode HIGH 7.8
CVE-2023-28617

org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or dire…

Fix: after 9.6.1
Fix from $1,950 2023-03-19
Emacs HIGH 7.8
CVE-2023-27986

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-q…

Fix: after 28.2
Fix from $1,950 2023-03-09
Emacs HIGH 7.8
CVE-2023-27985

emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack …

Fix: after 28.2
Fix from $1,950 2023-03-09