Gnu
gnu
1,205 CVEs • 123 products
Products (123)
Click to collapseToggle
Products (123)
Click to collapse
CVEs (1,205)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical FedoraprojectGnu+1 more4Fedora GnutlsLeap+1 moreJun 17, 2026 Sep 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs...Show more |
GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug...Show more |
4Canonical GnuOpensuse+1 more7Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+4 moreJun 17, 2026 Jul 31, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized m...Show more |
4Canonical GnuOpensuse+1 more7Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+4 moreJun 17, 2026 Jul 31, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to re...Show more |
There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a z...Show more |
4Debian GnuOpensuse+1 more4Debian Linux Grub2Leap+1 moreJun 17, 2026 Jul 30, 2020 N/A· v4 8.2 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an u...Show more |
In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further...Show more |
8Canonical DebianGnu+5 more15Active Iq Unified Manager Debian LinuxEnterprise Linux+12 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream),...Show more |
7Canonical DebianGnu+4 more14Debian Linux Enterprise LinuxEnterprise Linux Atomic Host+11 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitra...Show more |
7Canonical DebianGnu+4 more14Debian Linux Enterprise LinuxEnterprise Linux Atomic Host+11 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure b...Show more |
GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files. |
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c. |
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec. |
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity_data.spec. |
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a stack overflow in bits.c, possibly related to bit_read_TF. |
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to denial of service in bit_calc_CRC in bits.c, related to a for loop. |
An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in decode_R13_R2000 in decode.c, a different vulnerability than CVE-2019-20011. |
An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_LWPOLYLINE in dwg.spec. |
3Canonical DebianGnu3Debian Linux MailmanUbuntu LinuxJun 17, 2026 Jun 24, 2020 N/A· v4 4.3 MEDIUM· v3 2.6 LOW· v2 GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page. |
3Fedoraproject GnuOpensuse3Adns FedoraLeapNov 21, 2024 Jun 18, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered. |