Vulnerabilities > GNU

DATE CVE VULNERABILITY TITLE RISK
2017-08-29 CVE-2017-13734 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
There is an illegal address access in the _nc_safe_strcat function in strings.c in ncurses 6.0 that will lead to a remote denial of service attack.
network
gnu CWE-119
4.3
2017-08-29 CVE-2017-13733 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
There is an illegal address access in the fmt_entry function in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
network
low complexity
gnu CWE-119
6.5
2017-08-29 CVE-2017-13732 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
There is an illegal address access in the function dump_uses() in progs/dump_entry.c in ncurses 6.0 that might lead to a remote denial of service attack.
network
low complexity
gnu CWE-119
6.5
2017-08-29 CVE-2017-13731 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
There is an illegal address access in the function postprocess_termcap() in parse_entry.c in ncurses 6.0 that will lead to a remote denial of service attack.
network
low complexity
gnu CWE-119
6.5
2017-08-29 CVE-2017-13730 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
There is an illegal address access in the function _nc_read_entry_source() in progs/tic.c in ncurses 6.0 that might lead to a remote denial of service attack.
network
low complexity
gnu CWE-119
6.5
2017-08-29 CVE-2017-13729 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Ncurses 6.0
There is an illegal address access in the _nc_save_str function in alloc_entry.c in ncurses 6.0.
network
low complexity
gnu CWE-119
6.5
2017-08-29 CVE-2017-13728 Infinite Loop vulnerability in GNU Ncurses 6.0
There is an infinite loop in the next_char function in comp_scan.c in ncurses 6.0, related to libtic.
network
low complexity
gnu CWE-835
7.5
2017-08-28 CVE-2017-13716 Allocation of Resources Without Limits or Throttling vulnerability in GNU Binutils 2.29
The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).
network
gnu CWE-770
7.1
2017-08-28 CVE-2016-0634 OS Command Injection vulnerability in GNU Bash 4.3
The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.
network
gnu CWE-78
6.0
2017-08-28 CVE-2014-9483 Information Exposure vulnerability in GNU Emacs 24.4
Emacs 24.4 allows remote attackers to bypass security restrictions.
network
low complexity
gnu CWE-200
5.0