Vulnerabilities > Elfutils Project

DATE CVE VULNERABILITY TITLE RISK
2017-04-09 CVE-2017-7608 Out-of-bounds Read vulnerability in multiple products
The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
local
low complexity
elfutils-project debian canonical CWE-125
5.5
2017-04-09 CVE-2017-7607 Out-of-bounds Read vulnerability in Elfutils Project Elfutils 0.168
The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.
local
low complexity
elfutils-project CWE-125
5.5
2017-03-23 CVE-2016-10255 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Elfutils Project Elfutils
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory allocation failure.
local
low complexity
elfutils-project CWE-119
5.5
2017-03-23 CVE-2016-10254 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Elfutils Project Elfutils
The allocate_elf function in common.h in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted ELF file, which triggers a memory allocation failure.
local
low complexity
elfutils-project CWE-119
5.5