Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2018-17942 The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a tr… Gnulib 2018-09-23+ Fix from $1,9502018-10-03 MEDIUM 6.5 CVE-2018-17794 An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_… Binutils Mitigation only Fix from $1,6002018-09-30 MEDIUM 5.5 CVE-2018-17358 An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exist… Binutils No fix yet Fix from $1,6002018-09-23 MEDIUM 5.5 CVE-2018-17359 An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory access exist… Binutils No fix yet Fix from $1,6002018-09-23 MEDIUM 5.5 CVE-2018-17360 An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read … Binutils Patch available Fix from $1,6002018-09-23 MEDIUM 5.5 CVE-2018-1000654 GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser ag… Libtasn1 No fix yet Fix from $1,6002018-08-20 MEDIUM 6.5 CVE-2018-14524 dwg_decode_eed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwg_free_eed in free.c) because it does not properly manage the obj-… Libredwg 0.6+ Fix from $1,6002018-07-23 MEDIUM 6.5 CVE-2018-14471 dwg_obj_block_control_get_block_headers in dwg_api.c in GNU LibreDWG 0.5.1048 allows remote attackers to cause a denial of service (NULL pointer dere… Libredwg 0.6+ Fix from $1,6002018-07-20 MEDIUM 6.5 CVE-2018-14443 get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV). Libredwg 0.6+ Fix from $1,6002018-07-20 MEDIUM 6.5 CVE-2018-13796 An issue was discovered in GNU Mailman before 2.1.28. A crafted URL can cause arbitrary text to be displayed on a web page from a trusted site. Mailman 2.1.28+ Fix from $1,6002018-07-12 HIGH 7.5 CVE-2018-12934 remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OO… Binutils No fix yet Fix from $1,9502018-06-28 MEDIUM 5.5 CVE-2018-12641 An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling… Binutils No fix yet Fix from $1,6002018-06-22 CRITICAL 9.8 CVE-2017-18269 An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.… Glibc after 2.27 Fix from $2,3002018-05-18 MEDIUM 5.5 CVE-2018-9996 An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions… Binutils No fix yet Fix from $1,6002018-04-10 MEDIUM 5.5 CVE-2018-9138 An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion occurs in the C++ demangling … Binutils Mitigation only Fix from $1,6002018-03-30 CRITICAL 9.8 CVE-2014-5044EPSS 6% Multiple integer overflows in libgfortran might allow remote attackers to execute arbitrary code or cause a denial of service (Fortran application cr… Libgfortran 4.8+ Fix from $2,3002018-03-07 MEDIUM 5.5 CVE-2018-7570 The assign_file_positions_for_non_load_sections function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Bin… Binutils Patch available Fix from $1,6002018-02-28 CRITICAL 9.8 CVE-2017-18201 An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c. Libcdio 2.0.0+ Fix from $2,3002018-02-26 HIGH 8.8 CVE-2017-18198 print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or… Libcdio 1.0.0+ Fix from $1,9502018-02-24 MEDIUM 6.5 CVE-2017-18199 realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted i… Libcdio 1.0.0+ Fix from $1,6002018-02-24 HIGH 7.5 CVE-2018-6952EPSS 8% A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6. Patch after 2.7.6 Fix from $1,9502018-02-13 MEDIUM 5.5 CVE-2016-10713 An issue was discovered in GNU patch before 2.7.6. Out-of-bounds access within pch_write_line() in pch.c can possibly lead to DoS via a crafted input… Patch 2.7.6+ Fix from $1,6002018-02-13 MEDIUM 5.5 CVE-2018-6872 The elf_parse_notes function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote at… Binutils Patch available Fix from $1,6002018-02-09 MEDIUM 5.5 CVE-2018-6759 The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, has… Binutils Mitigation only Fix from $1,6002018-02-06 CRITICAL 9.8 CVE-2018-6551 The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not … Glibc after 2.26 Fix from $2,3002018-02-02 HIGH 7.8 CVE-2018-6543 In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()` with 0 size… Binutils No fix yet Fix from $1,9502018-02-02 HIGH 7.8 CVE-2017-1000408 A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that… Glibc No fix yet Fix from $1,9502018-02-01 HIGH 7.0 CVE-2017-1000409 A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note th… Glibc No fix yet Fix from $1,9502018-02-01 HIGH 7.8 CVE-2018-6323EPSS 6% The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsign… Binutils No fix yet Fix from $1,9502018-01-26 HIGH 7.1 CVE-2017-18018 In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-… Coreutils after 8.29 Fix from $1,9502018-01-04