Gnu
gnu
1,205 CVEs • 123 products
Products (123)
Click to collapseToggle
Products (123)
Click to collapse
CVEs (1,205)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types. |
chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. |
3Debian GnuRedhat8Bash Debian LinuxEnterprise Linux Desktop+5 moreMay 13, 2026 Jan 23, 2017 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address. |
Stack-based buffer overflow in the ValidateMove function in frontend/move.cc in GNU Chess (aka gnuchess) before 6.2.4 might allow context-dependent attackers to execute arbitrary code via a large input, as demonstrated w...Show more |
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables. |
2Fedoraproject Gnu2Fedora GuileMay 6, 2026 Jan 12, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack. |
2Fedoraproject Gnu2Fedora GuileMay 6, 2026 Jan 12, 2017 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithreaded application, other threads could end up creating files with insecure permissions. For example,...Show more |
Directory traversal vulnerability in the safer_name_suffix function in GNU tar 1.14 through 1.29 might allow remote attackers to bypass an intended protection mechanism and write to arbitrary files via vectors related to...Show more |
3Fedoraproject GnuOpensuse3Fedora GlibcOpensuseMay 6, 2026 Oct 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to ca...Show more |
The gnutls_ocsp_resp_check_crt function in lib/x509/ocsp.c in GnuTLS before 3.4.15 and 3.5.x before 3.5.4 does not verify the serial length of an OCSP response, which might allow remote attackers to bypass an intended ce...Show more |
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open. |
The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data. |
3Canonical GnuOpensuse4Leap LibidnOpensuse+1 moreMay 6, 2026 Sep 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948. |
3Canonical GnuOpensuse3Leap LibidnUbuntu LinuxMay 6, 2026 Sep 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input. |
3Canonical GnuOpensuse4Leap LibidnOpensuse+1 moreMay 6, 2026 Sep 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read. |
Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators. |
Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that modify an option, as d...Show more |
4Canonical GnuOracle+1 more4Pan Os SolarisUbuntu Linux+1 moreMay 6, 2026 Jun 30, 2016 N/A· v4 8.8 HIGH· v3 4.3 MEDIUM· v2 GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource. |
3Canonical GnuOpensuse4Glibc LeapOpensuse+1 moreMay 6, 2026 Jun 10, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via...Show more |
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent...Show more |