Gnu
gnu
1,205 CVEs • 123 products
Products (123)
Click to collapseToggle
Products (123)
Click to collapse
CVEs (1,205)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack. |
Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command. |
GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is execute...Show more |
Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion. |
The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by spe...Show more |
The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows. |
GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions. |
3Conectiva GnuRedhat3Linux LinuxMailmanApr 16, 2026 Oct 20, 2000 N/A· v4 N/A· v3 4.6 MEDIUM· v2 The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges. |
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results. |
read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords. |
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack. |
Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess. |
GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands. |
The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code. |
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files v...Show more |
The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute. |
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself. |
9Caldera FreebsdGnu+6 more11Aix FreebsdInet+8 moreApr 16, 2026 Dec 10, 1997 N/A· v4 N/A· v3 7.5 HIGH· v2 FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce. |
6Cisco GnuHp+3 more8Hp Ux InetIos+5 moreApr 16, 2026 Dec 1, 1997 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Land IP denial of service. |
Denial of service of inetd on Linux through SYN and RST packets. |