Vulnerabilities > GNU

DATE CVE VULNERABILITY TITLE RISK
2019-01-16 CVE-2019-6460 NULL Pointer Dereference vulnerability in GNU Recutils 1.8
An issue was discovered in GNU Recutils 1.8.
network
low complexity
gnu CWE-476
6.5
2019-01-16 CVE-2019-6459 Memory Leak vulnerability in GNU Recutils 1.8
An issue was discovered in GNU Recutils 1.8.
network
low complexity
gnu CWE-401
6.5
2019-01-16 CVE-2019-6458 Memory Leak vulnerability in GNU Recutils 1.8
An issue was discovered in GNU Recutils 1.8.
network
low complexity
gnu CWE-401
6.5
2019-01-16 CVE-2019-6457 Memory Leak vulnerability in GNU Recutils 1.8
An issue was discovered in GNU Recutils 1.8.
network
low complexity
gnu CWE-401
6.5
2019-01-16 CVE-2019-6456 NULL Pointer Dereference vulnerability in GNU Recutils 1.8
An issue was discovered in GNU Recutils 1.8.
network
low complexity
gnu CWE-476
6.5
2019-01-16 CVE-2019-6455 Double Free vulnerability in GNU Recutils 1.8
An issue was discovered in GNU Recutils 1.8.
network
low complexity
gnu CWE-415
6.5
2019-01-15 CVE-2018-20712 Out-of-bounds Read vulnerability in GNU Binutils 2.31.1
A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1.
network
low complexity
gnu CWE-125
6.5
2019-01-04 CVE-2018-20673 Integer Overflow or Wraparound vulnerability in GNU Binutils 2.31.1
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.
local
low complexity
gnu CWE-190
5.5
2019-01-04 CVE-2018-20671 Integer Overflow or Wraparound vulnerability in GNU Binutils
load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size.
local
low complexity
gnu CWE-190
5.5
2019-01-02 CVE-2018-20657 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.
network
low complexity
gnu f5 CWE-772
7.5