Vulnerabilities > GNU > Patch > 2.7

DATE CVE VULNERABILITY TITLE RISK
2021-12-22 CVE-2021-45261 Release of Invalid Pointer or Reference vulnerability in GNU Patch 2.7
An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.
network
gnu CWE-763
4.3
2020-03-25 CVE-2019-20633 Double Free vulnerability in GNU Patch
GNU patch through 2.7.6 contains a free(p_line[p_end]) Double Free vulnerability in the function another_hunk in pch.c that can cause a denial of service via a crafted patch file.
network
gnu CWE-415
4.3
2019-11-25 CVE-2015-1396 Path Traversal vulnerability in multiple products
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4.
network
low complexity
gnu debian CWE-22
6.4
2019-08-16 CVE-2018-20969 OS Command Injection vulnerability in GNU Patch
do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character.
network
gnu CWE-78
critical
9.3
2019-07-17 CVE-2019-13636 Link Following vulnerability in GNU Patch
In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files.
network
high complexity
gnu CWE-59
5.9
2018-02-13 CVE-2018-6952 Double Free vulnerability in GNU Patch
A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.
network
low complexity
gnu CWE-415
5.0
2018-02-13 CVE-2018-6951 NULL Pointer Dereference vulnerability in multiple products
An issue was discovered in GNU patch through 2.7.6.
network
low complexity
gnu canonical CWE-476
5.0
2018-02-13 CVE-2016-10713 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Patch
An issue was discovered in GNU patch before 2.7.6.
network
gnu CWE-119
4.3
2017-08-25 CVE-2015-1395 Path Traversal vulnerability in multiple products
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a ..
network
low complexity
fedoraproject canonical gnu CWE-22
7.8
2017-08-25 CVE-2014-9637 Resource Management Errors vulnerability in multiple products
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
7.1