← Back

Gnu

gnu

1,205 CVEs • 123 products

Products (123)

Click to collapse
Toggle
Binutils
binutils
Glibc
glibc
Libredwg
libredwg
Gnutls
gnutls
Grub2
grub2
Mailman
mailman
Emacs
emacs
Ncurses
ncurses
Wget
wget
Tar
tar
Bash
bash
Pspp
pspp
Patch
patch
Gcc
gcc
Recutils
recutils
Gzip
gzip
Libtasn1
libtasn1
Libextractor
libextractor
Cpio
cpio
Groff
groff
Privacy Guard
privacy_guard
Coreutils
coreutils
Libiberty
libiberty
Screen
screen
Gdb
gdb
Mailutils
mailutils
Inetutils
inetutils
Adns
adns
Gnump3d
gnump3d
Cfengine
cfengine
Radius
radius
Libmicrohttpd
libmicrohttpd
Libidn
libidn
Enscript
enscript
Sharutils
sharutils
A2ps
a2ps
Libcdio
libcdio
Osip
osip
Org Mode
org_mode
Ed
ed
Chess
chess
Aspell
aspell
Nano
nano
Libidn2
libidn2
Cflow
cflow
Fribidi
fribidi
Hurd
hurd
Savane
savane
Inet
inet
Fileutils
fileutils
Zebra
zebra
Gnats
gnats
Less
less
Gnubiff
gnubiff
Phpbook
phpbook
Gnash
gnash
Eglibc
eglibc
Fingerd
fingerd
Wget2
wget2
Sed
sed
Xemacs
xemacs
Findutils
findutils
Lsh
lsh
Cvs
cvs
Libtool
libtool
Anubis
anubis
Gettext
gettext
Texinfo
texinfo
Gv
gv
Gpgme
gpgme
M4
m4
Gnu Screen
gnu_screen
Automake
automake
Grep
grep
Grub
grub
Parallel
parallel
Guile
guile
Guix
guix
Bison
bison
Indent
indent
Make
make
Userv
userv
G++
g++
Flim
flim
Ksymoops
ksymoops
Queue
queue
Gnumail
gnumail
Libtool Ltdl
libtool-ltdl
Iceweasel
iceweasel
Flash Player
flash_player
Gimp
gimp
Tramp
tramp
Sccs
sccs
Grub Legacy
grub_legacy
Ibackup
ibackup
Classpath
classpath
Escript
escript

CVEs (1,205)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gnu
1Screen
Apr 16, 2026
Apr 23, 2002
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Buffer overflow in the Braille module for GNU screen 3.9.11, when HAVE_BRAILLE is defined, allows local users to execute arbitrary code.
6Debian
FreebsdGnu+3 more
6Debian Linux
FreebsdLinux+3 more
Jul 23, 2026
Mar 8, 2002
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in ncurses 5.0, and the ncurses4 compatibility package as used in Red Hat Linux, allows local users to gain privileges, related to "routines for moving the physical cursor and scrolling."
11Freeradius
GnuIcradius+8 more
11Freeradius
IcradiusOpenradius+8 more
Apr 16, 2026
Mar 4, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Multiple RADIUS implementations do not properly validate the Vendor-Length of the Vendor-Specific attribute, which allows remote attackers to cause a denial of service (crash) via a Vendor-Length that is less than 2.
12Ascend
FreeradiusGnu+9 more
12Freeradius
IcradiusOpenradius+9 more
Apr 16, 2026
Mar 4, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in digest calculation function of multiple RADIUS implementations allows remote attackers to cause a denial of service and possibly execute arbitrary code via shared secret data.
1Gnu
1Groff
Apr 16, 2026
Feb 27, 2002
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in the preprocessor in groff 1.16 and earlier allows remote attackers to gain privileges via lpd in the LPRng printing system.
3Debian
GnuRedhat
3Debian Linux
EnscriptLinux
Apr 16, 2026
Jan 31, 2002
N/A· v4
N/A· v3
3.6 LOW· v2
GNU Enscript 1.6.1 and earlier allows local users to overwrite arbitrary files of the Enscript user via a symlink attack on temporary files.
1Gnu
1Mailman
Apr 16, 2026
Dec 21, 2001
N/A· v4
N/A· v3
5.1 MEDIUM· v2
Cross-site scripting vulnerability in Mailman email archiver before 2.08 allows attackers to obtain sensitive information or authentication credentials via a malicious link that is accessed by other web users.
1Gnu
1Gzip
Apr 16, 2026
Nov 18, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server.
1Gnu
1Mailman
Apr 16, 2026
Sep 5, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during auth...Show more
Mailman 2.0.x before 2.0.6 allows remote attackers to gain access to list administrative pages when there is an empty site or list password, which is not properly handled during the call to the crypt function during authentication.Show less
2Gnu
Slackware
2Findutils
Slackware Linux
Apr 16, 2026
Aug 31, 2001
N/A· v4
N/A· v3
7.2 HIGH· v2
GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to writ...Show more
GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.Show less
1Gnu
1Privacy Guard
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.
2Gnu
Xemacs
2Emacs
Xemacs
Apr 16, 2026
Aug 7, 2001
N/A· v4
N/A· v3
1.2 LOW· v2
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.
2Gnu
Jgroff
2Groff
Jgroff
Apr 16, 2026
Jul 26, 2001
N/A· v4
N/A· v3
7.5 HIGH· v2
Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the pl...Show more
Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.Show less
1Gnu
1Tar
Apr 16, 2026
Jul 12, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
1Gnu
1Mailman
Apr 16, 2026
May 3, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.
1Gnu
1Privacy Guard
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.
1Gnu
1Privacy Guard
Apr 16, 2026
Feb 12, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.
1Gnu
1Ed
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
4.6 MEDIUM· v2
GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.
1Gnu
1Privacy Guard
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
GnuPG (gpg) 1.0.3 does not properly check all signatures of a file containing multiple documents, which allows an attacker to modify contents of all documents but the first without detection.
5Freebsd
GnuImmunix+2 more
5Freebsd
ImmunixLinux+2 more
Jul 23, 2026
Dec 19, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.