Vulnerabilities > GNU

DATE CVE VULNERABILITY TITLE RISK
2017-08-28 CVE-2016-0634 OS Command Injection vulnerability in GNU Bash 4.3
The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.
network
high complexity
gnu CWE-78
7.5
2017-08-28 CVE-2014-9483 Information Exposure vulnerability in GNU Emacs 24.4
Emacs 24.4 allows remote attackers to bypass security restrictions.
network
low complexity
gnu CWE-200
7.5
2017-08-27 CVE-2017-13710 NULL Pointer Dereference vulnerability in GNU Binutils 2.29
The setup_group function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a group section that is too small.
network
low complexity
gnu CWE-476
7.5
2017-08-25 CVE-2015-1395 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a ..
network
low complexity
fedoraproject canonical gnu CWE-22
7.5
2017-08-25 CVE-2014-9637 Resource Management Errors vulnerability in multiple products
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
local
low complexity
fedoraproject mageia canonical gnu CWE-399
5.5
2017-08-24 CVE-2017-12836 CVS 1.12.x, when configured to use SSH for remote repositories, might allow remote attackers to execute arbitrary code via a repository URL with a crafted hostname, as demonstrated by "-oProxyCommand=id;localhost:/bar."
network
high complexity
gnu canonical debian
7.5
2017-08-19 CVE-2017-12967 Out-of-bounds Read vulnerability in GNU Binutils 2.29
The getsym function in tekhex.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a malformed tekhex binary.
network
low complexity
gnu CWE-125
6.5
2017-08-18 CVE-2017-12961 Improper Input Validation vulnerability in GNU Pspp 0.11.0
There is an assertion abort in the function parse_attributes() in data/sys-file-reader.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
network
low complexity
gnu CWE-20
7.5
2017-08-18 CVE-2017-12960 Reachable Assertion vulnerability in GNU Pspp 0.11.0
There is a reachable assertion abort in the function dict_rename_var() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to remote denial of service.
network
low complexity
gnu CWE-617
7.5
2017-08-18 CVE-2017-12959 Reachable Assertion vulnerability in GNU Pspp 0.11.0
There is a reachable assertion abort in the function dict_add_mrset() in data/dictionary.c of the libpspp library in GNU PSPP before 1.0.1 that will lead to a remote denial of service attack.
network
low complexity
gnu CWE-617
7.5