Vulnerabilities > GNU > Binutils > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-09-30 | CVE-2017-14939 | Out-of-bounds Read vulnerability in GNU Binutils 2.29 decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles a length calculation, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to read_1_byte. | 5.5 |
2017-09-30 | CVE-2017-14938 | Allocation of Resources Without Limits or Throttling vulnerability in GNU Binutils 2.29 _bfd_elf_slurp_version_tables in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file. | 5.5 |
2017-09-30 | CVE-2017-14934 | Infinite Loop vulnerability in GNU Binutils 2.29 process_debug_info in dwarf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file that contains a negative size value in a CU structure. | 5.5 |
2017-09-30 | CVE-2017-14933 | Infinite Loop vulnerability in GNU Binutils 2.29 read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file. | 5.5 |
2017-09-30 | CVE-2017-14932 | Infinite Loop vulnerability in GNU Binutils 2.29 decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite loop) via a crafted ELF file. | 5.5 |
2017-09-30 | CVE-2017-14930 | Missing Release of Resource after Effective Lifetime vulnerability in GNU Binutils 2.29 Memory leak in decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file. | 5.5 |
2017-09-18 | CVE-2017-14529 | Out-of-bounds Read vulnerability in GNU Binutils 2.29 The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles HintName vector entries, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PE file, related to the bfd_getl16 function. | 5.5 |
2017-09-04 | CVE-2017-14130 | Out-of-bounds Read vulnerability in GNU Binutils 2.29 The _bfd_elf_parse_attributes function in elf-attrs.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (_bfd_elf_attr_strdup heap-based buffer over-read and application crash) via a crafted ELF file. | 5.5 |
2017-09-04 | CVE-2017-14129 | Out-of-bounds Read vulnerability in GNU Binutils 2.29 The read_section function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (parse_comp_unit heap-based buffer over-read and application crash) via a crafted ELF file. | 5.5 |
2017-09-04 | CVE-2017-14128 | Out-of-bounds Read vulnerability in GNU Binutils 2.29 The decode_line_info function in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (read_1_byte heap-based buffer over-read and application crash) via a crafted ELF file. | 5.5 |