Vulnerability index

Browse CVEs

725 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2017-8397 The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 and an invalid… Binutils Patch available Fix from $1,9502017-05-01 HIGH 7.5 CVE-2017-8398 dwarf.c in GNU Binutils 2.28 is vulnerable to an invalid read of size 1 during dumping of debug information from a corrupt binary. This vulnerability… Binutils Patch available Fix from $1,9502017-05-01 HIGH 7.5 CVE-2017-7869 GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function… Gnutls after 3.5.9 Fix from $1,9502017-04-14 HIGH 7.5 CVE-2017-7853 In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in … Osip Patch available Fix from $1,9502017-04-13 CRITICAL 9.8 CVE-2016-10324 In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_… Osip Patch available Fix from $2,3002017-04-13 HIGH 7.5 CVE-2016-10325 In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparse… Osip Patch available Fix from $1,9502017-04-13 HIGH 7.5 CVE-2016-10326 In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/o… Osip Patch available Fix from $1,9502017-04-13 HIGH 7.8 CVE-2015-8107 Format string vulnerability in GNU a2ps 4.14 allows remote attackers to execute arbitrary code. A2ps Mitigation only Fix from $1,9502017-04-13 CRITICAL 9.8 CVE-2017-7614 elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" un… Binutils Patch available Fix from $2,3002017-04-09 HIGH 7.5 CVE-2017-7300 The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that… Binutils Patch available Fix from $1,9502017-03-29 HIGH 7.5 CVE-2017-7301 The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that… Binutils Patch available Fix from $1,9502017-03-29 HIGH 7.5 CVE-2017-7302 The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a swap_std_reloc_out function in bfd/aoutx.h that is … Binutils Patch available Fix from $1,9502017-03-29 HIGH 7.5 CVE-2017-7303 The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 4) because of m… Binutils Patch available Fix from $1,9502017-03-29 HIGH 7.5 CVE-2017-7304 The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 8) because of m… Binutils Patch available Fix from $1,9502017-03-29 MEDIUM 5.5 CVE-2017-7299 The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit … Binutils Patch available Fix from $1,6002017-03-29 HIGH 7.8 CVE-2017-5932 The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character a… Bash Patch available Fix from $1,9502017-03-27 CRITICAL 9.1 CVE-2017-7226 The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-b… Binutils Patch available Fix from $2,3002017-03-22 HIGH 7.5 CVE-2017-7223 GNU assembler in GNU Binutils 2.28 is vulnerable to a global buffer overflow (of size 1) while attempting to unget an EOF character from the input st… Binutils Patch available Fix from $1,9502017-03-22 HIGH 7.5 CVE-2017-7225 The find_nearest_line function in addr2line in GNU Binutils 2.28 does not handle the case where the main file name and the directory name are both em… Binutils Patch available Fix from $1,9502017-03-22 HIGH 7.5 CVE-2017-7227 GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash.… Binutils Patch available Fix from $1,9502017-03-22 MEDIUM 5.5 CVE-2017-7224 The find_nearest_line function in objdump in GNU Binutils 2.28 is vulnerable to an invalid write (of size 1) while disassembling a corrupt binary tha… Binutils Patch available Fix from $1,6002017-03-22 CRITICAL 9.8 CVE-2014-9939 ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects. Binutils after 2.25 Fix from $2,3002017-03-21 MEDIUM 5.5 CVE-2017-7209 The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NULL pointer while reading section contents in a corrupt binary, leadin… Binutils Patch available Fix from $1,6002017-03-21 MEDIUM 5.5 CVE-2017-7210 objdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer over-reads (of size 1 and size 8) while handling corrupt STABS enum type str… Binutils Patch available Fix from $1,6002017-03-21 HIGH 7.8 CVE-2017-5618 GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile… Screen after 4.5.0 Fix from $1,9502017-03-20 HIGH 8.1 CVE-2015-8983 Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent … Glibc after 2.21 Fix from $1,9502017-03-20 MEDIUM 5.9 CVE-2015-8984 The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (appl… Glibc after 2.21 Fix from $1,6002017-03-20 MEDIUM 5.9 CVE-2015-8985 The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion fail… Glibc 2.28+ Fix from $1,6002017-03-20 CRITICAL 9.1 CVE-2017-6969 readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger pro… Binutils No fix yet Fix from $2,3002017-03-17 MEDIUM 5.5 CVE-2017-6965 readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a … Binutils No fix yet Fix from $1,6002017-03-17