← Back

Gnu

gnu

1,205 CVEs • 123 products

Products (123)

Click to collapse
Toggle
Binutils
binutils
Glibc
glibc
Libredwg
libredwg
Gnutls
gnutls
Grub2
grub2
Mailman
mailman
Emacs
emacs
Ncurses
ncurses
Wget
wget
Tar
tar
Bash
bash
Pspp
pspp
Patch
patch
Gcc
gcc
Recutils
recutils
Gzip
gzip
Libtasn1
libtasn1
Libextractor
libextractor
Cpio
cpio
Groff
groff
Privacy Guard
privacy_guard
Coreutils
coreutils
Libiberty
libiberty
Screen
screen
Gdb
gdb
Mailutils
mailutils
Inetutils
inetutils
Adns
adns
Gnump3d
gnump3d
Cfengine
cfengine
Radius
radius
Libmicrohttpd
libmicrohttpd
Libidn
libidn
Enscript
enscript
Sharutils
sharutils
A2ps
a2ps
Libcdio
libcdio
Osip
osip
Org Mode
org_mode
Ed
ed
Chess
chess
Aspell
aspell
Nano
nano
Libidn2
libidn2
Cflow
cflow
Fribidi
fribidi
Hurd
hurd
Savane
savane
Inet
inet
Fileutils
fileutils
Zebra
zebra
Gnats
gnats
Less
less
Gnubiff
gnubiff
Phpbook
phpbook
Gnash
gnash
Eglibc
eglibc
Fingerd
fingerd
Wget2
wget2
Sed
sed
Xemacs
xemacs
Findutils
findutils
Lsh
lsh
Cvs
cvs
Libtool
libtool
Anubis
anubis
Gettext
gettext
Texinfo
texinfo
Gv
gv
Gpgme
gpgme
M4
m4
Gnu Screen
gnu_screen
Automake
automake
Grep
grep
Grub
grub
Parallel
parallel
Guile
guile
Guix
guix
Bison
bison
Indent
indent
Make
make
Userv
userv
G++
g++
Flim
flim
Ksymoops
ksymoops
Queue
queue
Gnumail
gnumail
Libtool Ltdl
libtool-ltdl
Iceweasel
iceweasel
Flash Player
flash_player
Gimp
gimp
Tramp
tramp
Sccs
sccs
Grub Legacy
grub_legacy
Ibackup
ibackup
Classpath
classpath
Escript
escript

CVEs (1,205)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gnu
1Glibc
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
1.2 LOW· v2
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
1Gnu
1Cfengine
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.
1Gnu
1Groff
Apr 16, 2026
Dec 19, 2000
N/A· v4
N/A· v3
10.0 HIGH· v2
GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is execute...Show more
GNU Groff uses the current working directory to find a device description file, which allows a local user to gain additional privileges by including a malicious postpro directive in the description file, which is executed when another user runs groff.Show less
1Gnu
1Mailman
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.
1Gnu
1Glibc
Apr 16, 2026
Nov 14, 2000
N/A· v4
N/A· v3
7.2 HIGH· v2
The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by spe...Show more
The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.Show less
1Gnu
2G++
Gcc
Apr 16, 2026
Nov 1, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows.
1Gnu
1Userv
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions.
3Conectiva
GnuRedhat
3Linux
LinuxMailman
Apr 16, 2026
Oct 20, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.
2Gnu
Isc
2Bind
Glibc
Apr 16, 2026
May 3, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.
1Gnu
1Emacs
Apr 16, 2026
Apr 18, 2000
N/A· v4
N/A· v3
4.6 MEDIUM· v2
read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.
1Gnu
1Emacs
Apr 16, 2026
Apr 18, 2000
N/A· v4
N/A· v3
3.6 LOW· v2
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.
1Gnu
1Emacs
Apr 16, 2026
Apr 18, 2000
N/A· v4
N/A· v3
2.1 LOW· v2
Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.
1Gnu
1Make
Apr 16, 2026
Feb 1, 2000
N/A· v4
N/A· v3
6.2 MEDIUM· v2
GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.
1Gnu
1Gnumeric
Apr 16, 2026
Aug 5, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.
1Gnu
1Fingerd
Apr 16, 2026
Jul 21, 1999
N/A· v4
N/A· v3
7.2 HIGH· v2
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files v...Show more
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.Show less
1Gnu
1Bash
Apr 16, 2026
Apr 20, 1999
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.
1Gnu
1Wget
Apr 16, 2026
Jan 2, 1999
N/A· v4
N/A· v3
5.0 MEDIUM· v2
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
9Caldera
FreebsdGnu+6 more
11Aix
FreebsdInet+8 more
Apr 16, 2026
Dec 10, 1997
N/A· v4
N/A· v3
7.5 HIGH· v2
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
6Cisco
GnuHp+3 more
8Hp Ux
InetIos+5 more
Apr 16, 2026
Dec 1, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Land IP denial of service.
3Gnu
HpLinux
3Hp Ux
InetLinux Kernel
Apr 16, 2026
Nov 1, 1997
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Denial of service of inetd on Linux through SYN and RST packets.