Gnu
gnu
1,205 CVEs • 123 products
Products (123)
Click to collapseToggle
Products (123)
Click to collapse
CVEs (1,205)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
GNU Parallel before 20150522 (Nepal), when using (1) --cat or (2) --fifo with --sshlogin, allows local users to write to arbitrary files via a symlink attack on a temporary file. |
GNU Parallel before 20150422, when using (1) --pipe, (2) --tmux, (3) --cat, (4) --fifo, or (5) --compress, allows local users to write to arbitrary files via a symlink attack on a temporary file. |
3Fedoraproject GnuOpensuse3Fedora Libtasn1OpensuseMay 6, 2026 May 12, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate. |
The is_utf8_well_formed function in GNU less before 475 allows remote attackers to have unspecified impact via malformed UTF-8 characters, which triggers an out-of-bounds read. |
4Canonical DebianGnu+1 more4Debian Linux Enterprise LinuxMailman+1 moreMay 6, 2026 Apr 13, 2015 N/A· v4 N/A· v3 7.6 HIGH· v2 Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibtasn1+1 moreMay 6, 2026 Apr 10, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors. |
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow...Show more |
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denia...Show more |
3Canonical GnuSuse4Glibc Suse Linux Enterprise DesktopSuse Linux Enterprise Server+1 moreMay 6, 2026 Mar 27, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of ser...Show more |
GnuTLS before 3.1.0 does not verify that the RSA PKCS #1 signature algorithm matches the signature algorithm in the certificate, which allows remote attackers to conduct downgrade attacks via unspecified vectors. |
3Canonical GnuOpensuse3Glibc OpensuseUbuntu LinuxMay 6, 2026 Feb 24, 2015 N/A· v4 N/A· v3 7.8 HIGH· v2 The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinit...Show more |
4Canonical GnuOpensuse+1 more4Enterprise Linux Server Aus GlibcOpensuse+1 moreMay 6, 2026 Feb 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large...Show more |
cpio 2.11, when using the --no-absolute-filenames option, allows local users to write to arbitrary files via a symlink attack on a file in an archive. |
The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option. |
7Apple DebianGnu+4 more18Communications Application Session Controller Communications Eagle Application ProcessorCommunications Eagle Lnp Application Processor+15 moreMay 6, 2026 Jan 28, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostb...Show more |
3Gnu OpensuseOracle3Opensuse PatchSolarisMay 6, 2026 Jan 21, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 GNU patch 2.7.1 allows remote attackers to write to arbitrary files via a symlink attack in a patch file. |
The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" stri...Show more |
4Canonical DebianFedoraproject+1 more4Binutils Debian LinuxFedora+1 moreMay 6, 2026 Jan 15, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended nam...Show more |
3Canonical FedoraprojectGnu3Binutils FedoraUbuntu LinuxMay 6, 2026 Dec 9, 2014 N/A· v4 N/A· v3 3.6 LOW· v2 Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary...Show more |
3Canonical FedoraprojectGnu3Binutils FedoraUbuntu LinuxMay 6, 2026 Dec 9, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted f...Show more |