Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2019-16166 GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c. Cflow after 1.6 Fix from $1,6002019-09-09 HIGH 7.5 CVE-2019-15847 The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single cal… Gcc 7.5.0 / 8.4.0+ Fix from $1,9502019-09-02 HIGH 7.8 CVE-2019-15767 In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file. Chess No fix yet Fix from $1,9502019-08-29 HIGH 7.8 CVE-2018-20969 do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-1… Patch after 2.7.6 Fix from $1,9502019-08-16 HIGH 7.5 CVE-2014-10375 handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header. Exosip 5.0.0+ Fix from $1,9502019-08-14 HIGH 7.8 CVE-2019-1010180 GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Co… Gdb 9.1+ Fix from $1,9502019-07-24 MEDIUM 5.5 CVE-2019-1010204 GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds … Binutils after 2.31.1 Fix from $1,6002019-07-23 MEDIUM 5.9 CVE-2019-13636 In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c. Patch after 2.7.6 Fix from $1,6002019-07-17 CRITICAL 9.8 CVE-2019-1010022 GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vec… Glibc No fix yet Fix from $2,3002019-07-15 MEDIUM 5.4 CVE-2019-1010023 GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privil… Glibc No fix yet Fix from $1,6002019-07-15 MEDIUM 5.3 CVE-2019-1010024 GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: g… Glibc No fix yet Fix from $1,6002019-07-15 MEDIUM 5.3 CVE-2019-1010025 GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is:… Glibc No fix yet Fix from $1,6002019-07-15 HIGH 8.1 CVE-2018-12886 stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumst… Gcc after 8.0 Fix from $1,9502019-05-22 CRITICAL 9.8 CVE-2019-5953EPSS 6% Buffer overflow in GNU Wget 1.20.1 and earlier allows remote attackers to cause a denial-of-service (DoS) or may execute an arbitrary code via unspec… Wget after 1.20.1 Fix from $2,3002019-05-17 HIGH 8.8 CVE-2019-11639 An issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum at rec-types.c in librec.a. Recutils No fix yet Fix from $1,9502019-05-01 HIGH 8.8 CVE-2019-11640 An issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_simple at rec-fex.c in librec.a. Recutils No fix yet Fix from $1,9502019-05-01 MEDIUM 6.5 CVE-2019-11637 An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leadin… Recutils No fix yet Fix from $1,6002019-05-01 MEDIUM 6.5 CVE-2019-11638 An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec… Recutils No fix yet Fix from $1,6002019-05-01 CRITICAL 9.8 CVE-2005-3590 The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if … Glibc 2.3.5+ Fix from $2,3002019-04-10 MEDIUM 5.5 CVE-2006-7254 The nscd daemon in the GNU C Library (glibc) before version 2.5 does not close incoming client sockets if they cannot be handled by the daemon, allow… Glibc 2.5+ Fix from $1,6002019-04-10 HIGH 7.5 CVE-2019-9923 pax_decode_header in sparse.c in GNU Tar before 1.32 had a NULL pointer dereference when parsing certain archives that have malformed extended header… Tar 1.32+ Fix from $1,9502019-03-22 HIGH 7.5 CVE-2019-9777 An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write at header_variables… Libredwg No fix yet Fix from $1,9502019-03-14 HIGH 7.5 CVE-2019-9778 An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at dwg.spec. Libredwg No fix yet Fix from $1,9502019-03-14 HIGH 7.5 CVE-2019-9779 An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (earlier than… Libredwg No fix yet Fix from $1,9502019-03-14 CRITICAL 9.1 CVE-2019-9774 An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at bits.c. Libredwg No fix yet Fix from $2,3002019-03-14 CRITICAL 9.1 CVE-2019-9775 An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_CONTROL at dwg.spec. Libredwg No fix yet Fix from $2,3002019-03-14 HIGH 7.5 CVE-2019-9770 An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for t… Libredwg No fix yet Fix from $1,9502019-03-14 HIGH 7.5 CVE-2019-9771 An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bits.c. Libredwg No fix yet Fix from $1,9502019-03-14 HIGH 7.5 CVE-2019-9772 An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dwg.spec. Libredwg No fix yet Fix from $1,9502019-03-14 HIGH 7.5 CVE-2019-9773 An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for t… Libredwg No fix yet Fix from $1,9502019-03-14