Vulnerabilities > GNU

DATE CVE VULNERABILITY TITLE RISK
2023-10-03 CVE-2023-4911 Out-of-bounds Write vulnerability in multiple products
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable.
7.8
2023-09-25 CVE-2023-4156 Out-of-bounds Read vulnerability in multiple products
A heap out-of-bounds read flaw was found in builtin.c in the gawk package.
local
low complexity
gnu redhat fedoraproject CWE-125
7.1
2023-09-25 CVE-2023-5156 Memory Leak vulnerability in multiple products
A flaw was found in the GNU C Library.
network
low complexity
gnu redhat CWE-401
7.5
2023-09-18 CVE-2023-4527 Out-of-bounds Read vulnerability in multiple products
A flaw was found in glibc.
network
high complexity
gnu redhat fedoraproject netapp CWE-125
6.5
2023-09-18 CVE-2023-4806 Use After Free vulnerability in multiple products
A flaw was found in glibc.
network
high complexity
gnu redhat fedoraproject CWE-416
5.9
2023-09-14 CVE-2023-25584 Out-of-bounds Read vulnerability in GNU Binutils
An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils.
local
low complexity
gnu CWE-125
7.1
2023-09-14 CVE-2023-25585 Use of Uninitialized Resource vulnerability in GNU Binutils 2.40
A flaw was found in Binutils.
local
low complexity
gnu CWE-908
5.5
2023-09-14 CVE-2023-25586 Use of Uninitialized Resource vulnerability in GNU Binutils 2.40
A flaw was found in Binutils.
local
low complexity
gnu CWE-908
5.5
2023-09-14 CVE-2023-25588 Use of Uninitialized Resource vulnerability in GNU Binutils 2.40
A flaw was found in Binutils.
local
low complexity
gnu CWE-908
5.5
2023-09-13 CVE-2023-4039 Unspecified vulnerability in GNU GCC
**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being detected.
network
high complexity
gnu
4.8