Uclibc Ng Project
uclibc-ng_project
7 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (7)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Anker UclibcUclibc Ng Project3Eufy Homebase 2 Firmware UclibcUclibc NgJun 17, 2026 Sep 29, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger th...Show more |
2Uclibc Uclibc Ng Project2Uclibc Uclibc NgJun 17, 2026 May 6, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2. |
1Uclibc Ng Project 1Uclibc Ng Jun 17, 2026 May 3, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 uClibc-ng versions prior to 1.0.37 are vulnerable to integer wrap-around in functions malloc-simple. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a cra...Show more |
2Uclibc Uclibc Ng Project2Uclibc Uclibc NgJun 17, 2026 Nov 10, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames...Show more |
The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet. |
The __decode_dotted function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via vectors involving compressed items in a reply. |
2Uclibc Uclibc Ng Project2Uclibc Uclibc NgMay 13, 2026 Jan 27, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the memset function. |