Search

Found 418 results in 52ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-14745 high 7.8 7.8 FIX debian debian gnu 9y ago The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, interpret a -1 value as a sorting count instead of an error flag, w…
CVE-2017-14729 high 7.8 7.8 FIX debian debian gnu 9y ago The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, do not ensure a unique PLT entry for a symbol, which allows remote …
CVE-2015-1865 medium 5.1 5.1 FIX debian debian gnu 9y ago fts.c in coreutils 8.4 allows local users to delete arbitrary files.
CVE-2017-14529 medium 5.5 5.5 FIX debian debian sles gnu 9y ago The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles HintName vector entries, which allows remote attack…
CVE-2017-14482 high 8.8 8.8 slesdebian debian gnu 9y ago GNU Emacs before 25.3 allows remote attackers to execute arbitrary code via email with crafted "Content-Type: text/enriched" data containing an x-display XML element that specifies execution of shell…
CVE-2017-14333 high 7.8 7.8 FIX debian debian sles gnu 9y ago The process_version_sections function in readelf.c in GNU Binutils 2.29 allows attackers to cause a denial of service (Integer Overflow, and hang because of a time-consuming loop) or possibly have un…
CVE-2017-12133 medium 5.9 5.9 FIX arch arch slesdebian debian gnu 9y ago Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors rel…
CVE-2017-14130 medium 5.5 5.5 FIX debian debian sles gnu 9y ago The _bfd_elf_parse_attributes function in elf-attrs.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of servi…
CVE-2017-14129 medium 5.5 5.5 FIX debian debian sles gnu 9y ago The read_section function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (parse_comp_u…
CVE-2017-14128 medium 5.5 5.5 FIX debian debian sles gnu 9y ago The decode_line_info function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (read_1_b…
CVE-2017-14062 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2017-14061 critical 9.8 9.8 FIX debian debian gnu 9y ago Integer overflow in the _isBidi function in bidi.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2017-13757 medium 5.5 5.5 FIX debian debian sles gnu 9y ago The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the PLT section size, which allows remote attackers to cause a denial of service (heap-ba…
CVE-2017-13734 medium 6.5 6.5 FIX slesdebian debian gnu 9y ago There is an illegal address access in the _nc_safe_strcat function in strings.c in ncurses 6.0 that will lead to a remote denial of service attack.
CVE-2017-13733 medium 6.5 6.5 FIX slesdebian debian gnu 9y ago There is an illegal address access in the fmt_entry function in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
CVE-2017-13732 medium 6.5 6.5 FIX slesdebian debian gnu 9y ago There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
CVE-2017-13731 medium 6.5 6.5 FIX slesdebian debian gnu 9y ago There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service attack.
CVE-2017-13730 medium 6.5 6.5 FIX slesdebian debian gnu 9y ago There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of service attack.
CVE-2017-13729 medium 6.5 6.5 FIX slesdebian debian gnu 9y ago There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0. It will lead to a remote denial of service attack.
CVE-2017-13728 high 7.5 7.5 FIX slesdebian debian gnu 9y ago There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic. A crafted input will lead to a remote denial of service attack.
CVE-2017-13716 medium 5.5 5.5 debian debian sles gnu 9y ago The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application cr…
CVE-2016-0634 high 7.5 7.5 FIX slesdebian debian gnu 9y ago The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.
CVE-2014-9483 high 7.5 7.5 gnu 9y ago Emacs 24.4 allows remote attackers to bypass security restrictions.
CVE-2017-13710 high 7.5 7.5 FIX debian debian sles gnu 9y ago The setup_group function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (NULL pointer der…
CVE-2015-1395 high 7.5 7.5 FIX fedora fedoraubuntu ubuntudebian debian gnu 9y ago Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a…
CVE-2014-9637 medium 5.5 5.5 FIX fedora fedoraubuntu ubuntudebian debian gnu 9y ago GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
CVE-2017-12836 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu gnu 9y ago CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand…
CVE-2017-12967 medium 6.5 6.5 FIX debian debian sles gnu 9y ago The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (stack-based buffer…
CVE-2017-12961 high 7.5 7.5 FIX debian debian gnu 9y ago There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
CVE-2017-12960 high 7.5 7.5 FIX debian debian gnu 9y ago There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
CVE-2017-12959 high 7.5 7.5 FIX debian debian gnu 9y ago There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of service attack.
CVE-2017-12958 high 7.5 7.5 FIX debian debian gnu 9y ago There is an illegal address access in the function output_hex() in data/data-out.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
CVE-2017-12799 high 7.8 7.8 FIX debian debian sles gnu 9y ago The elf_read_notesfunction in bfd/elf.c in GNU Binutils 2.29 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via…
CVE-2016-4456 high 7.5 7.5 FIX slesdebian debian gnu 9y ago The "GNUTLS_KEYLOGFILE" environment variable in gnutls 3.4.12 allows remote attackers to overwrite and corrupt arbitrary files in the filesystem.
CVE-2017-12459 high 7.8 7.8 FIX debian debian sles gnu 9y ago The bfd_mach_o_read_symtab_strtab function in bfd/mach-o.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause …
CVE-2017-12458 high 7.8 7.8 FIX debian debian sles gnu 9y ago The nlm_swap_auxiliary_headers_in function in bfd/nlmcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause…
CVE-2017-12457 high 7.8 7.8 FIX debian debian sles gnu 9y ago The bfd_make_section_with_flags function in section.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a NUL…
CVE-2017-12456 high 7.8 7.8 FIX debian debian sles gnu 9y ago The read_symbol_stabs_debugging_info function in rddbg.c in GNU Binutils 2.29 and earlier allows remote attackers to cause an out of bounds heap read via a crafted binary file.
CVE-2017-12455 high 7.8 7.8 FIX debian debian sles gnu 9y ago The evax_bfd_print_emh function in vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bo…
CVE-2017-12454 high 7.8 7.8 FIX debian debian sles gnu 9y ago The _bfd_vms_slurp_egsd function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an arbi…
CVE-2017-12453 high 7.8 7.8 FIX debian debian sles gnu 9y ago The _bfd_vms_slurp_eeom function in libbfd.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of boun…
CVE-2017-12452 high 7.8 7.8 FIX debian debian sles gnu 9y ago The bfd_mach_o_i386_canonicalize_one_reloc function in bfd/mach-o-i386.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attac…
CVE-2017-12451 high 7.8 7.8 FIX debian debian sles gnu 9y ago The _bfd_xcoff_read_ar_hdr function in bfd/coff-rs6000.c and bfd/coff64-rs6000.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remo…
CVE-2017-12450 high 7.8 7.8 FIX debian debian sles gnu 9y ago The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out o…
CVE-2017-12449 high 7.8 7.8 FIX debian debian sles gnu 9y ago The _bfd_vms_save_sized_string function in vms-misc.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an ou…
CVE-2017-12448 high 7.8 7.8 FIX debian debian sles gnu 9y ago The bfd_cache_close function in bfd/cache.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a heap use afte…
CVE-2017-12132 medium 5.9 5.9 FIX arch archdebian debian gnu 9y ago The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path…
CVE-2017-11671 medium 4.0 4.0 sles gnu 9y ago Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences…
CVE-2017-11113 high 7.5 7.5 FIX slesdebian debian gnu 9y ago In ncurses 6.0, there is a NULL Pointer Dereference in the _nc_parse_entry function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is used to …
CVE-2017-11112 high 7.5 7.5 FIX slesdebian debian gnu 9y ago In ncurses 6.0, there is an attempted 0xffffffffffffffff access in the append_acs function of tinfo/parse_entry.c. It could lead to a remote denial of service attack if the terminfo library code is u…
CVE-2017-10792 medium 6.5 6.5 FIX debian debian gnu 9y ago There is a NULL Pointer Dereference in the function ll_insert() of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert …
CVE-2017-10791 medium 6.5 6.5 FIX debian debian gnu 9y ago There is an Integer overflow in the hash_int function of the libpspp library in GNU PSPP before 0.11.0. For example, a crash was observed within the library code when attempting to convert invalid SP…
CVE-2017-10790 high 7.5 7.5 FIX slesdebian debian gnu 9y ago The _asn1_check_identifier function in GNU Libtasn1 through 4.12 causes a NULL pointer dereference and crash when reading crafted input that triggers assignment of a NULL value within an asn1_node st…
CVE-2017-10685 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago In ncurses 6.0, there is a format string vulnerability in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
CVE-2017-10684 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
CVE-2015-5180 high 7.5 7.5 FIX slesdebian debianubuntu ubuntu gnu 9y ago res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash).
CVE-2017-9955 medium 5.5 5.5 FIX debian debian sles gnu 9y ago The get_build_id function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (heap-based b…
CVE-2017-9954 medium 5.5 5.5 FIX debian debian gnu 9y ago The getvalue function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (stack-based buff…
CVE-2017-9778 medium 5.5 5.5 FIX slesdebian debian gnu 9y ago GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file can cause GDB to repeatedly allocate memory until a …
CVE-2017-1000366 high 7.8 8.8 EXPFIX slesarch archdebian debian openstackgnumcafee 9y ago glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note…
CVE-2017-9756 high 7.8 8.8 EXPFIX debian debian sles gnu 9y ago The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspe…
CVE-2017-9755 high 7.8 7.8 FIX debian debian sles gnu 9y ago opcodes/i386-dis.c in GNU Binutils 2.28 does not consider the number of registers for bnd mode, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or p…
CVE-2017-9754 high 7.8 7.8 FIX debian debian sles gnu 9y ago The process_otr function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not validate a certain offset, which allows remote attac…
CVE-2017-9753 high 7.8 7.8 FIX debian debian sles gnu 9y ago The versados_mkobject function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not initialize a certain data structure, which all…
CVE-2017-9752 high 7.8 7.8 FIX debian debian sles gnu 9y ago bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application cr…
CVE-2017-9751 high 7.8 7.8 FIX debian debian sles gnu 9y ago opcodes/rl78-decode.opc in GNU Binutils 2.28 has an unbounded GETBYTE macro, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspec…
CVE-2017-9750 high 7.8 8.8 EXPFIX debian debian sles gnu 9y ago opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly…
CVE-2017-9749 high 7.8 8.8 EXPFIX debian debian sles gnu 9y ago The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via …
CVE-2017-9748 high 7.8 8.8 EXPFIX debian debian sles gnu 9y ago The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buff…
CVE-2017-9747 high 7.8 8.8 EXPFIX debian debian sles gnu 9y ago The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buf…
CVE-2017-9746 high 7.8 8.8 EXPFIX debian debian sles gnu 9y ago The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact…
CVE-2017-9745 high 7.8 7.8 FIX debian debian sles gnu 9y ago The _bfd_vms_slurp_etir function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service…
CVE-2017-9744 high 7.8 7.8 FIX debian debian sles gnu 9y ago The sh_elf_set_mach_from_flags function in bfd/elf32-sh.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of s…
CVE-2017-9743 high 7.8 7.8 FIX debian debian gnu 9y ago The print_insn_score32 function in opcodes/score7-dis.c:552 in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecif…
CVE-2017-9742 high 7.8 8.8 EXPFIX debian debian sles gnu 9y ago The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other…
CVE-2017-7507 high 7.5 7.5 FIX arch archdebian debian gnu 9y ago GnuTLS version 3.5.12 and earlier is vulnerable to a NULL pointer dereference while decoding a status response TLS extension with valid contents. This could lead to a crash of the GnuTLS server appli…
CVE-2014-9984 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon cras…
CVE-2016-4973 high 7.8 7.8 debian debian gnu 9y ago Binaries compiled against targets that use the libssp library in GCC for stack smashing protection (SSP) might allow local users to perform buffer overflow attacks by leveraging lack of the Object Si…
CVE-2017-6891 high 8.8 8.8 FIX arch arch slesdebian debian gnuapache 9y ago Two errors in the "asn1_find_node()" function (lib/parser_aux.c) within GnuTLS libtasn1 version 4.10 can be exploited to cause a stacked-based buffer overflow by tricking a user into processing a spe…
CVE-2017-9044 medium 5.5 5.5 FIX debian debianarch arch sles gnu 9y ago The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-04-12 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted ELF file.
CVE-2017-9043 high 7.8 7.8 FIX debian debianarch arch gnu 9y ago readelf.c in GNU Binutils 2017-04-12 has a "shift exponent too large for type unsigned long" issue, which might allow remote attackers to cause a denial of service (application crash) or possibly hav…
CVE-2017-9042 high 7.8 7.8 FIX debian debianarch arch sles gnu 9y ago readelf.c in GNU Binutils 2017-04-12 has a "cannot be represented in type long" issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified…
CVE-2017-9041 medium 5.5 5.5 FIX debian debianarch arch sles gnu 9y ago GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to MIPS GOT mishandling in the process_mips_…
CVE-2017-9040 medium 5.5 5.5 FIX debian debianarch arch sles gnu 9y ago GNU Binutils 2017-04-03 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash), related to the process_mips_specific function in readelf.c, via a crafte…
CVE-2017-9039 medium 5.5 5.5 FIX debian debianarch arch sles gnu 9y ago GNU Binutils 2.28 allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file with many program headers, related to the get_program_headers function in readelf.c.
CVE-2017-9038 medium 5.5 5.5 FIX debian debianarch arch sles gnu 9y ago GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to the byte_get_little_endian function in el…
CVE-2017-8804 high 7.5 7.5 sles gnu 9y ago The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual…
CVE-2017-8421 medium 5.5 5.5 FIX debian debian sles gnu 9y ago The function coff_set_alignment_hook in coffcode.h in Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a memory leak vulnerability which can cause memory ex…
CVE-2017-8398 high 7.5 7.5 FIX debian debian sles gnu 9y ago dwarf.c in GNU Binutils 2.28 is vulnerable to an invalid read of size 1 during dumping of debug information from a corrupt binary. This vulnerability causes programs that conduct an analysis of binar…
CVE-2017-8397 high 7.5 7.5 FIX debian debian sles gnu 9y ago The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 and an invalid write of size 1 during processing of a corrupt bi…
CVE-2017-8396 high 7.5 7.5 FIX debian debian sles gnu 9y ago The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 because the existing reloc offset range tests didn't catch small…
CVE-2017-8395 high 7.5 7.5 FIX debian debian sles gnu 9y ago The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid write of size 8 because of missing a malloc() return-value check to see if memo…
CVE-2017-8394 high 7.5 7.5 FIX debian debian sles gnu 9y ago The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 4 due to NULL pointer dereferencing of _bfd_elf_large_com_section.…
CVE-2017-8393 high 7.5 7.5 FIX debian debian sles gnu 9y ago The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a global buffer over-read error because of an assumption made by code that runs for objcop…
CVE-2017-8392 high 7.5 7.5 FIX debian debian sles gnu 9y ago The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 8 because of missing a check to determine whether symbols are NULL…
CVE-2017-7869 high 7.5 7.5 FIX slesdebian debian gnu 9y ago GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function in opencdk/read-packet.c. This issue (which is a …
CVE-2017-7853 high 7.5 7.5 FIX slesdebian debian gnu 9y ago In libosip2 in GNU oSIP 4.1.0 and 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a r…
CVE-2016-10326 high 7.5 7.5 FIX slesdebian debian gnu 9y ago In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS.
CVE-2016-10325 high 7.5 7.5 FIX slesdebian debian gnu 9y ago In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote Do…
CVE-2016-10324 critical 9.8 9.8 FIX slesdebian debian gnu 9y ago In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c.