Search

Found 386 results in 81ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-7227 high 7.5 7.5 FIX debian debianarch arch sles gnu 9y ago GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash. This relates to lack of '\0' termination of a nam…
CVE-2017-7225 high 7.5 7.5 FIX debian debianarch arch gnu 9y ago The find_nearest_line function in addr2line in GNU Binutils 2.28 does not handle the case where the main file name and the directory name are both empty, triggering a NULL pointer dereference and an …
CVE-2017-7224 medium 5.5 5.5 FIX debian debianarch arch gnu 9y ago The find_nearest_line function in objdump in GNU Binutils 2.28 is vulnerable to an invalid write (of size 1) while disassembling a corrupt binary that contains an empty function name, leading to a pr…
CVE-2017-7223 high 7.5 7.5 FIX debian debianarch arch gnu 9y ago GNU assembler in GNU Binutils 2.28 is vulnerable to a global buffer overflow (of size 1) while attempting to unget an EOF character from the input stream, potentially leading to a program crash.
CVE-2017-7210 medium 5.5 5.5 FIX debian debianarch arch gnu 9y ago objdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer over-reads (of size 1 and size 8) while handling corrupt STABS enum type strings in a crafted object file, leading to program …
CVE-2017-7209 medium 5.5 5.5 FIX debian debianarch arch gnu 9y ago The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NULL pointer while reading section contents in a corrupt binary, leading to a program crash.
CVE-2017-5618 high 7.8 7.8 FIX debian debian gnu 9y ago GNU screen before 4.5.1 allows local users to modify arbitrary files and consequently gain root privileges by leveraging improper checking of logfile permissions.
CVE-2015-8985 medium 5.9 5.9 FIX slesdebian debian gnu 9y ago The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion failure and application crash) via vectors related to …
CVE-2015-8984 medium 5.9 5.9 FIX debian debian gnu 9y ago The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash) via a malformed pattern, which trig…
CVE-2015-8983 high 8.1 8.1 FIX slesdebian debian gnu 9y ago Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (applicatio…
CVE-2017-6966 medium 5.5 5.5 FIX debian debianarch arch gnu 9y ago readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid s…
CVE-2017-6965 medium 5.5 5.5 FIX debian debianarch arch sles gnu 9y ago readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow.
CVE-2015-8982 high 8.1 8.1 FIX slesdebian debian gnu 9y ago Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc6) before 2.21 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary co…
CVE-2017-6508 medium 6.1 6.1 FIX arch arch slesdebian debian gnu 9y ago CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in the host subcomponent of a URL.
CVE-2016-10228 medium 5.9 5.9 FIX slesdebian debian rocky gnu 9y ago RHSA-2021:1585: glibc security, bug fix, and enhancement update (Moderate)
CVE-2016-4493 medium 5.5 5.5 FIX slesdebian debian gnu 9y ago The demangle_template_value_parm and do_hpacc_template_literal functions in cplus-dem.c in libiberty allow remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted b…
CVE-2016-4492 medium 4.4 4.4 FIX slesdebian debian gnu 9y ago Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
CVE-2016-4491 medium 5.5 5.5 FIX slesdebian debian gnu 9y ago The d_print_comp function in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, which triggers infinite recursion and…
CVE-2016-4490 medium 5.5 5.5 FIX slesdebian debian gnu 9y ago Integer overflow in cp-demangle.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to inconsistent use of the long and in…
CVE-2016-4489 medium 5.5 5.5 FIX slesdebian debian gnu 9y ago Integer overflow in the gnu_special function in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to the "demangling of virtu…
CVE-2016-4488 medium 5.5 5.5 FIX slesdebian debian gnu 9y ago Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "ktypevec."
CVE-2016-4487 medium 5.5 5.5 FIX slesdebian debian gnu 9y ago Use-after-free vulnerability in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary, related to "btypevec."
CVE-2016-2226 high 7.8 8.8 EXPFIX slesdebian debian gnu 9y ago Integer overflow in the string_appends function in cplus-dem.c in libiberty allows remote attackers to execute arbitrary code via a crafted executable, which triggers a buffer overflow.
CVE-2017-5357 high 7.5 7.5 FIX arch arch slesdebian debian gnu 9y ago regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free.
CVE-2016-5417 high 7.5 7.5 FIX debian debian gnu 9y ago Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (me…
CVE-2016-6131 high 7.5 7.5 FIX slesdebian debian gnu 9y ago The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.
CVE-2016-2781 medium 4.6 4.6 FIX debian debian gnu 9y ago chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.
CVE-2016-9401 medium 5.5 5.5 FIX debian debian sles rhel gnu 10y ago popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
CVE-2016-7543 high 8.4 8.4 FIX debian debian slesfedora fedora gnu 10y ago Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
CVE-2016-8605 medium 5.3 5.3 FIX slesarch archfedora fedora gnu 10y ago The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permi…
CVE-2016-6321 high 7.5 7.5 FIX slesarch archdebian debian gnu 10y ago Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files v…
CVE-2016-6323 high 7.5 7.5 FIX slesdebian debianfedora fedora gnu 10y ago The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-depe…
CVE-2016-7444 high 7.5 7.5 FIX slesarch archdebian debian gnu 10y ago The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to …
CVE-2016-7098 high 8.1 9.1 EXPFIX slesdebian debian gnu 10y ago Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP …
CVE-2016-6263 high 7.5 7.5 FIX slesdebian debian gnu 10y ago The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data.
CVE-2016-6262 high 7.5 7.5 FIX slesdebian debiansuse suse gnu 10y ago idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE…
CVE-2016-6261 high 7.5 7.5 FIX slesdebian debiansuse suse gnu 10y ago The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input.
CVE-2015-8948 high 7.5 7.5 FIX slesdebian debiansuse suse gnu 10y ago idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.
CVE-2016-7123 high 8.8 8.8 sles gnu 10y ago Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.
CVE-2016-6893 high 8.8 8.8 sles gnu 10y ago Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that m…
CVE-2016-4971 high 8.8 9.8 EXPFIX slesubuntu ubuntudebian debian gnu 10y ago GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
CVE-2016-4429 medium 5.9 5.9 FIX slesdebian debianubuntu ubuntu gnu 10y ago Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecif…
CVE-2016-3706 high 7.5 7.5 FIX slesdebian debiansuse suse gnu 10y ago Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vecto…
CVE-2016-3075 high 7.5 7.5 FIX slesdebian debiansuse suse gnu 10y ago Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack …
CVE-2016-1234 high 7.5 7.5 FIX slesdebian debiansuse suse gnu 10y ago Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) …
CVE-2016-4008 medium 5.9 5.9 FIX slesdebian debiansuse suse gnu 10y ago The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infini…
CVE-2016-2856 high 8.4 9.4 EXPFIX debian debianubuntu ubuntu gnu 10y ago pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubuntu 12.04 LTS and before 2.19-0ubuntu6.8 on Ubuntu 14.04 LTS; and the glibc pack…
CVE-2016-2037 medium 6.5 6.5 FIX slesdebian debian gnu 10y ago The cpio_safer_name_suffix function in util.c in cpio 2.11 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted cpio file.
CVE-2015-7547 high 8.1 9.1 EXPFIX debian debianubuntu ubuntususe suse hpsophossuse 10y ago Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a den…
CVE-2015-8777 medium 5.5 5.5 FIX slesdebian debian gnu 11y ago The process_envvars function in elf/rtld.c in the GNU C Library (aka glibc or libc6) before 2.23 allows local users to bypass a pointer-guarding protection mechanism via a zero value of the LD_POINTE…
CVE-2015-5277 high 7.2 FIX debian debianubuntu ubuntu rhel gnu 11y ago The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corrup…
CVE-2015-8370 high 7.4 7.4 FIX slesdebian debianfedora fedora gnu 11y ago Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via …
CVE-2015-5276 medium 5.0 gnu 11y ago The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-dependent…
CVE-2015-6806 medium 5.0 FIX slesdebian debian gnu 11y ago The MScrollV function in ansi.c in GNU screen 4.3.1 and earlier does not properly limit recursion, which allows remote attackers to cause a denial of service (stack consumption) via an escape sequenc…
CVE-2015-1781 medium 6.8 FIX debian debiansuse suseubuntu ubuntu susegnu 11y ago Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash…
CVE-2015-3308 high 7.5 FIX debian debianubuntu ubuntu gnu 11y ago Double free vulnerability in lib/x509/x509_ext.c in GnuTLS before 3.3.14 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted CRL distribution …
CVE-2013-7424 medium 5.1 FIX debian debian gnu 11y ago The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execu…
CVE-2015-6251 medium 5.0 FIX debian debian gnu 11y ago Double free vulnerability in GnuTLS before 3.3.17 and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service via a long DistinguishedName (DN) entry in a certificate.
CVE-2014-8155 medium 4.3 FIX debian debian gnu 11y ago GnuTLS before 2.9.10 does not verify the activation and expiration dates of CA certificates, which allows man-in-the-middle attackers to spoof servers via a certificate issued by a CA certificate tha…
CVE-2015-2059 high 7.5 FIX debian debiansuse susefedora fedora gnu 11y ago The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 c…
CVE-2015-4156 low 3.6 FIX suse susedebian debian gnu 11y ago GNU Parallel before 20150522 (Nepal), when using (1) --cat or (2) --fifo with --sshlogin, allows local users to write to arbitrary files via a symlink attack on a temporary file.
CVE-2015-4155 low 3.6 FIX debian debian gnu 11y ago GNU Parallel before 20150422, when using (1) --pipe, (2) --tmux, (3) --cat, (4) --fifo, or (5) --compress, allows local users to write to arbitrary files via a symlink attack on a temporary file.
CVE-2015-3622 medium 4.3 FIX slesdebian debiansuse suse gnu 11y ago The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.
CVE-2015-2775 high 7.6 slesubuntu ubuntudebian debian gnu 11y ago Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
CVE-2015-1473 medium 6.4 FIX debian debianubuntu ubuntu gnu 11y ago The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca functi…
CVE-2015-1472 high 7.5 FIX debian debianubuntu ubuntu gnu 11y ago The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attac…
CVE-2014-8121 medium 5.0 FIX debian debiansuse suseubuntu ubuntu gnu 11y ago DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to …
CVE-2015-0282 medium 5.0 FIX debian debian gnu 11y ago GnuTLS before 3.1.0 does not verify that the RSA PKCS #1 signature algorithm matches the signature algorithm in the certificate, which allows remote attackers to conduct downgrade attacks via unspeci…
CVE-2014-9402 high 7.8 FIX debian debianubuntu ubuntususe suse gnu 11y ago The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denia…
CVE-2013-7423 medium 5.0 FIX slesdebian debianubuntu ubuntu gnu 11y ago The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended l…
CVE-2015-1197 low 1.9 FIX debian debian gnu 11y ago cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive.
CVE-2015-1345 low 2.1 FIX debian debiansuse suse gnu 12y ago The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.
CVE-2015-1196 medium 4.3 FIX suse susedebian debian gnu 12y ago GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file.
CVE-2014-9471 high 7.5 FIX debian debianubuntu ubuntu gnu 12y ago The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=…
CVE-2014-8738 medium 5.0 FIX debian debianfedora fedoraubuntu ubuntu gnu 12y ago The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a…
CVE-2014-8737 low 3.6 FIX debian debianubuntu ubuntufedora fedora gnu 12y ago Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcop…
CVE-2014-8504 high 7.5 FIX debian debianubuntu ubuntufedora fedora gnu 12y ago Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified i…
CVE-2014-8503 high 7.5 FIX debian debianubuntu ubuntufedora fedora gnu 12y ago Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified i…
CVE-2014-8502 high 7.5 FIX debian debianubuntu ubuntufedora fedora gnu 12y ago Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspe…
CVE-2014-8501 high 7.5 FIX debian debianubuntu ubuntufedora fedora gnu 12y ago The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified…
CVE-2014-8485 high 7.5 FIX debian debianubuntu ubuntufedora fedora gnu 12y ago The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section g…
CVE-2014-8484 medium 5.0 FIX slesdebian debianubuntu ubuntu gnu 12y ago The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
CVE-2014-6040 medium 5.0 FIX debian debian gnu 12y ago GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte character value of "0xffff" to the iconv function …
CVE-2012-6656 medium 5.0 FIX debian debianubuntu ubuntu gnu 12y ago iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the ico…
CVE-2014-9112 medium 5.0 FIX debian debian gnu 12y ago Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block value in a cpio archive.
CVE-2014-7817 medium 4.6 FIX debian debiansuse suseubuntu ubuntu gnu 12y ago The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containin…
CVE-2014-8564 medium 5.0 FIX debian debiansuse suseubuntu ubuntu gnu 12y ago The _gnutls_ecc_ansi_x963_export function in gnutls_ecc.c in GnuTLS 3.x before 3.1.28, 3.2.x before 3.2.20, and 3.3.x before 3.3.10 allows remote attackers to cause a denial of service (out-of-bounds…
CVE-2011-2702 medium 7.8 EXPFIX debian debian gnu 12y ago Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allows context-dependent attackers to execute arbitrary…
CVE-2014-3564 medium 6.8 FIX debian debianubuntu ubuntu gnu 12y ago Multiple heap-based buffer overflows in the status_handler function in (1) engine-gpgsm.c and (2) engine-uiserver.c in GPGME before 1.5.1 allow remote attackers to cause a denial of service (crash) a…
CVE-2014-4043 high 7.5 FIX debian debiansuse suse gnu 12y ago The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-…
CVE-2014-5119 high 8.5 EXPFIX debian debian gnu 12y ago Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code …
CVE-2014-2524 low 3.3 suse susefedora fedora gnu 12y ago The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.
CVE-2014-0475 medium 6.8 FIX debian debian gnu 12y ago Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecifie…
CVE-2014-3465 medium 5.0 FIX debian debian gnu 12y ago The gnutls_x509_dn_oid_name function in lib/x509/common.c in GnuTLS 3.0 before 3.1.20 and 3.2.x before 3.2.10 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cra…
CVE-2014-3469 medium 5.0 FIX debian debiansuse suse rhel gnuredhat 12y ago The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NU…
CVE-2014-3468 high 7.5 FIX debian debiansuse suse rhel gnuredhat 12y ago The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds ac…
CVE-2014-3467 medium 5.0 FIX debian debiansuse suse rhel gnuredhat 12y ago Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data.
CVE-2014-3466 medium 6.8 FIX debian debian gnu 12y ago Buffer overflow in the read_server_hello function in lib/gnutls_handshake.c in GnuTLS before 3.1.25, 3.2.x before 3.2.15, and 3.3.x before 3.3.4 allows remote servers to cause a denial of service (me…
CVE-2013-4577 low 2.1 FIX debian debian gnu 12y ago A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the f…
CVE-2013-6889 medium 4.9 FIX debian debian gnu 12y ago GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option.