Vulnerabilities > GNU > Binutils

DATE CVE VULNERABILITY TITLE RISK
2023-09-14 CVE-2023-25584 Out-of-bounds Read vulnerability in GNU Binutils
An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
local
low complexity
gnu CWE-125
7.1
2023-09-14 CVE-2023-25585 Use of Uninitialized Resource vulnerability in GNU Binutils 2.40
A flaw was found in Binutils.
local
low complexity
gnu CWE-908
5.5
2023-09-14 CVE-2023-25586 Use of Uninitialized Resource vulnerability in GNU Binutils 2.40
A flaw was found in Binutils.
local
low complexity
gnu CWE-908
5.5
2023-09-14 CVE-2023-25588 Use of Uninitialized Resource vulnerability in GNU Binutils 2.40
A flaw was found in Binutils.
local
low complexity
gnu CWE-908
5.5
2023-08-22 CVE-2020-19724 Memory Leak vulnerability in GNU Binutils
A memory consumption issue in get_data function in binutils/nm.c in GNU nm before 2.34 allows attackers to cause a denial of service via crafted command.
local
low complexity
gnu CWE-401
5.5
2023-08-22 CVE-2020-19726 Unspecified vulnerability in GNU Binutils 2.36
An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.
network
low complexity
gnu
8.8
2023-08-22 CVE-2020-21490 Memory Leak vulnerability in GNU Binutils
An issue was discovered in GNU Binutils 2.34.
local
low complexity
gnu CWE-401
5.5
2023-08-22 CVE-2020-35342 Improper Initialization vulnerability in GNU Binutils
GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.
network
low complexity
gnu CWE-665
7.5
2023-08-22 CVE-2021-46174 Out-of-bounds Write vulnerability in GNU Binutils
Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.
network
low complexity
gnu CWE-787
7.5
2023-08-22 CVE-2022-35205 Reachable Assertion vulnerability in GNU Binutils 2.38.50
An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service.
local
low complexity
gnu CWE-617
5.5