Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2017-1000455 GuixSD prior to Git commit 5e66574a128937e7f2fcf146d146225703ccfd5d used POSIX hard links incorrectly, leading the creation of setuid executables in … Guixsd after 0.13.0 Fix from $1,6002018-01-02 HIGH 8.8 CVE-2017-17531 gozilla.c in GNU GLOBAL 4.8.6 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow… Global Mitigation only Fix from $1,9502017-12-14 MEDIUM 6.5 CVE-2017-17440 GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Imp… Libextractor Patch available Fix from $1,6002017-12-06 HIGH 8.1 CVE-2017-17426 The malloc function in the GNU C Library (aka glibc or libc6) 2.26 could return a memory block that is too small if an attempt is made to allocate an… Glibc No fix yet Fix from $1,9502017-12-05 HIGH 7.8 CVE-2017-17121 The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (m… Binutils No fix yet Fix from $1,9502017-12-04 HIGH 7.8 CVE-2017-17122 The dump_relocs_in_section function in objdump.c in GNU Binutils 2.29.1 does not check for reloc count integer overflows, which allows remote attacke… Binutils Patch available Fix from $1,9502017-12-04 HIGH 7.8 CVE-2017-17124 The _bfd_coff_read_string_table function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1… Binutils No fix yet Fix from $1,9502017-12-04 HIGH 7.8 CVE-2017-17125 nm.c and objdump.c in GNU Binutils 2.29.1 mishandle certain global symbols, which allows remote attackers to cause a denial of service (_bfd_elf_get_… Binutils Patch available Fix from $1,9502017-12-04 HIGH 7.8 CVE-2017-17126 The load_debug_section function in readelf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (invalid memory access and a… Binutils Patch available Fix from $1,9502017-12-04 MEDIUM 5.5 CVE-2017-17123 The coff_slurp_reloc_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, al… Binutils No fix yet Fix from $1,6002017-12-04 MEDIUM 5.5 CVE-2017-17080 elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate sizes of core notes, which a… Binutils Mitigation only Fix from $1,6002017-11-30 HIGH 7.8 CVE-2017-16826 The coff_slurp_line_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, all… Binutils Patch available Fix from $1,9502017-11-15 HIGH 7.8 CVE-2017-16827 The aout_get_external_symbols function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, al… Binutils Patch available Fix from $1,9502017-11-15 HIGH 7.8 CVE-2017-16828 The display_debug_frames function in dwarf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (integer overflow and heap-b… Binutils Patch available Fix from $1,9502017-11-15 HIGH 7.8 CVE-2017-16829 The _bfd_elf_parse_gnu_properties function in elf-properties.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binuti… Binutils Patch available Fix from $1,9502017-11-15 HIGH 7.8 CVE-2017-16830 The print_gnu_property_note function in readelf.c in GNU Binutils 2.29.1 does not have integer-overflow protection on 32-bit platforms, which allows … Binutils Patch available Fix from $1,9502017-11-15 HIGH 7.8 CVE-2017-16831 coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate the symbol count, which … Binutils Patch available Fix from $1,9502017-11-15 HIGH 7.8 CVE-2017-16832 The pe_bfd_read_buildid function in peicode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does n… Binutils Patch available Fix from $1,9502017-11-15 MEDIUM 5.5 CVE-2017-1000383 GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files … Emacs after 25.3.0 Fix from $1,6002017-10-31 HIGH 7.8 CVE-2017-15996 elfcomm.c in readelf in GNU Binutils 2.29 allows remote attackers to cause a denial of service (excessive memory allocation) or possibly have unspeci… Binutils Patch available Fix from $1,9502017-10-29 HIGH 7.5 CVE-2017-15938 dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, miscalculates DW_FORM_ref_addr die refs in th… Binutils Patch available Fix from $1,9502017-10-27 MEDIUM 5.5 CVE-2017-15939 dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file t… Binutils Patch available Fix from $1,6002017-10-27 MEDIUM 5.5 CVE-2017-15922 In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c. Libextractor No fix yet Fix from $1,6002017-10-26 CRITICAL 9.8 CVE-2017-15804 The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the… Glibc after 2.26 Fix from $2,3002017-10-22 CRITICAL 9.8 CVE-2017-15670 The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow in the glob function in glob.… Glibc after 2.26 Fix from $2,3002017-10-20 MEDIUM 5.9 CVE-2017-15671 The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory … Glibc after 2.26 Fix from $1,6002017-10-20 HIGH 7.5 CVE-2017-15600 In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf_extractor.c. Libextractor No fix yet Fix from $1,9502017-10-18 HIGH 7.5 CVE-2017-15601 In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/png_extractor.c, related to pr… Libextractor No fix yet Fix from $1,9502017-10-18 HIGH 7.5 CVE-2017-15602 In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extrac… Libextractor No fix yet Fix from $1,9502017-10-18 MEDIUM 6.2 CVE-2011-5320 scanf and related functions in glibc before 2.15 allow local users to cause a denial of service (segmentation fault) via a large string of 0s. Glibc after 2.14.1 Fix from $1,6002017-10-18