Vulnerabilities > GNU > Binutils > 2.11.2

DATE CVE VULNERABILITY TITLE RISK
2017-08-04 CVE-2017-12454 Out-of-bounds Read vulnerability in GNU Binutils
The _bfd_vms_slurp_egsd function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an arbitrary memory read via a crafted vms alpha file.
network
gnu CWE-125
6.8
2017-08-04 CVE-2017-12453 Out-of-bounds Read vulnerability in GNU Binutils
The _bfd_vms_slurp_eeom function in libbfd.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha file.
network
gnu CWE-125
6.8
2017-08-04 CVE-2017-12452 Out-of-bounds Read vulnerability in GNU Binutils
The bfd_mach_o_i386_canonicalize_one_reloc function in bfd/mach-o-i386.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted mach-o file.
network
gnu CWE-125
6.8
2017-08-04 CVE-2017-12451 Out-of-bounds Read vulnerability in GNU Binutils
The _bfd_xcoff_read_ar_hdr function in bfd/coff-rs6000.c and bfd/coff64-rs6000.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds stack read via a crafted COFF image file.
network
gnu CWE-125
6.8
2017-08-04 CVE-2017-12450 Out-of-bounds Write vulnerability in GNU Binutils
The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted vms alpha file.
network
gnu CWE-787
6.8
2017-08-04 CVE-2017-12449 Out-of-bounds Read vulnerability in GNU Binutils
The _bfd_vms_save_sized_string function in vms-misc.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms file.
network
gnu CWE-125
6.8
2017-08-04 CVE-2017-12448 Use After Free vulnerability in GNU Binutils
The bfd_cache_close function in bfd/cache.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a heap use after free and possibly achieve code execution via a crafted nested archive file.
network
gnu CWE-416
6.8
2017-03-21 CVE-2014-9939 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Binutils
ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
network
low complexity
gnu CWE-119
critical
9.8
2005-12-31 CVE-2005-4808 Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050714 allows user-assisted attackers to have an unknown impact via a crafted .s file.
network
high complexity
gnu canonical
7.6
2005-12-31 CVE-2005-4807 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
network
low complexity
gnu canonical CWE-119
7.5