Vulnerabilities > GNU > High

DATE CVE VULNERABILITY TITLE RISK
2018-12-26 CVE-2018-20483 Information Exposure vulnerability in GNU Wget
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr.
local
low complexity
gnu CWE-200
7.8
2018-12-20 CVE-2018-1000876 Integer Overflow or Wraparound vulnerability in multiple products
binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow.
local
low complexity
gnu canonical redhat CWE-190
7.8
2018-12-19 CVE-2018-20230 Out-of-bounds Write vulnerability in GNU Pspp 1.2.0
An issue was discovered in PSPP 1.2.0.
local
low complexity
gnu CWE-787
7.8
2018-12-07 CVE-2018-19931 Out-of-bounds Write vulnerability in multiple products
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31.
local
low complexity
gnu netapp canonical CWE-787
7.8
2018-12-04 CVE-2018-19591 Improper Input Validation vulnerability in multiple products
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed.
network
low complexity
gnu fedoraproject CWE-20
7.5
2018-10-18 CVE-2018-18483 Integer Overflow or Wraparound vulnerability in GNU Binutils 2.31
The get_count function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31, allows remote attackers to cause a denial of service (malloc called with the result of an integer-overflowing calculation) or possibly have unspecified other impact via a crafted string, as demonstrated by c++filt.
local
low complexity
gnu CWE-190
7.8
2018-10-03 CVE-2018-17942 Out-of-bounds Write vulnerability in GNU Gnulib
The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing.
network
low complexity
gnu CWE-787
8.8
2018-09-04 CVE-2018-16430 Out-of-bounds Read vulnerability in multiple products
GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
network
low complexity
gnu debian CWE-125
8.8
2018-07-17 CVE-2018-14346 Out-of-bounds Write vulnerability in multiple products
GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).
network
low complexity
debian gnu CWE-787
8.8
2018-06-28 CVE-2018-12934 Allocation of Resources Without Limits or Throttling vulnerability in GNU Binutils 2.30
remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM).
network
low complexity
gnu CWE-770
7.5