Vulnerabilities > GNU

DATE CVE VULNERABILITY TITLE RISK
2017-10-18 CVE-2017-15600 NULL Pointer Dereference vulnerability in GNU Libextractor 1.4
In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf_extractor.c.
network
low complexity
gnu CWE-476
7.5
2017-10-18 CVE-2011-5320 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Glibc
scanf and related functions in glibc before 2.15 allow local users to cause a denial of service (segmentation fault) via a large string of 0s.
local
low complexity
gnu CWE-119
6.2
2017-10-11 CVE-2017-15267 NULL Pointer Dereference vulnerability in GNU Libextractor 1.4
In GNU Libextractor 1.4, there is a NULL Pointer Dereference in flac_metadata in flac_extractor.c.
network
low complexity
gnu CWE-476
7.5
2017-10-11 CVE-2017-15266 Divide By Zero vulnerability in GNU Libextractor 1.4
In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor.c via a zero sample rate.
local
low complexity
gnu CWE-369
5.5
2017-10-10 CVE-2017-15225 Missing Release of Resource after Effective Lifetime vulnerability in GNU Binutils 2.29
_bfd_dwarf2_cleanup_debug_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory leak) via a crafted ELF file.
local
low complexity
gnu CWE-772
5.5
2017-10-05 CVE-2017-15025 Divide By Zero vulnerability in GNU Binutils 2.29
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted ELF file.
local
low complexity
gnu CWE-369
5.5
2017-10-05 CVE-2017-15024 Infinite Loop vulnerability in GNU Binutils 2.29
find_abstract_instance_name in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.
local
low complexity
gnu CWE-835
5.5
2017-10-05 CVE-2017-15023 NULL Pointer Dereference vulnerability in GNU Binutils 2.29
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename.
local
low complexity
gnu CWE-476
5.5
2017-10-05 CVE-2017-15022 NULL Pointer Dereference vulnerability in GNU Binutils 2.29
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the DW_AT_name data type, which allows remote attackers to cause a denial of service (bfd_hash_hash NULL pointer dereference, or out-of-bounds access, and application crash) via a crafted ELF file, related to scan_unit_for_symbols and parse_comp_unit.
local
low complexity
gnu CWE-476
5.5
2017-10-05 CVE-2017-15021 Out-of-bounds Read vulnerability in GNU Binutils 2.29
bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to bfd_getl32.
local
low complexity
gnu CWE-125
5.5