Gnu
gnu
1,205 CVEs • 123 products
Products (123)
Click to collapseToggle
Products (123)
Click to collapse
CVEs (1,205)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-...Show more |
GNU Serveez through 0.2.2 has an Information Leak. An attacker may send an HTTP POST request to the /cgi-bin/reader URI. The attacker must include a Content-length header with a large positive value that, when represente...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraGlibc+1 moreJun 17, 2026 Nov 19, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to re...Show more |
gnusound 0.7.5 has format string issue |
2Debian Gnu2Debian Linux FribidiJun 17, 2026 Nov 13, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering...Show more |
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode. |
Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts. |
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By...Show more |
idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string. |
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365. |
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012. |
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012. |
2Canonical Gnu2Aspell Ubuntu LinuxJun 17, 2026 Oct 14, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character. |
3Canonical GnuOpensuse3Binutils LeapUbuntu LinuxJun 17, 2026 Oct 10, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstr...Show more |
3Canonical GnuOpensuse3Binutils LeapUbuntu LinuxJun 17, 2026 Oct 10, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application c...Show more |
GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c. |
GNU cflow through 1.6 has a use-after-free in the reference function in parser.c. |
The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occur...Show more |
In GNU Chess 6.2.5, there is a stack-based buffer overflow in the cmd_load function in frontend/cmd.cc via a crafted chess position in an EPD file. |
3Debian FedoraprojectGnu3Debian Linux FedoraLibextractorJun 17, 2026 Aug 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c. |