Vulnerabilities > GNU > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-31 CVE-2017-1000383 Information Exposure vulnerability in GNU Emacs
GNU Emacs version 25.3.1 (and other versions most likely) ignores umask when creating a backup save file ("[ORIGINAL_FILENAME]~") resulting in files that may be world readable or otherwise accessible in ways not intended by the user running the emacs binary.
local
low complexity
gnu CWE-200
5.5
2017-10-27 CVE-2017-15939 NULL Pointer Dereference vulnerability in GNU Binutils 2.29
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file table, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename.
local
low complexity
gnu CWE-476
5.5
2017-10-26 CVE-2017-15922 Out-of-bounds Read vulnerability in GNU Libextractor 1.4
In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.
local
low complexity
gnu CWE-125
5.5
2017-10-20 CVE-2017-15671 Missing Release of Resource after Effective Lifetime vulnerability in GNU Glibc
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).
network
high complexity
gnu CWE-772
5.9
2017-10-18 CVE-2011-5320 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in GNU Glibc
scanf and related functions in glibc before 2.15 allow local users to cause a denial of service (segmentation fault) via a large string of 0s.
local
low complexity
gnu CWE-119
6.2
2017-10-11 CVE-2017-15266 Divide By Zero vulnerability in GNU Libextractor 1.4
In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor.c via a zero sample rate.
local
low complexity
gnu CWE-369
5.5
2017-10-10 CVE-2017-15225 Missing Release of Resource after Effective Lifetime vulnerability in GNU Binutils 2.29
_bfd_dwarf2_cleanup_debug_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (memory leak) via a crafted ELF file.
local
low complexity
gnu CWE-772
5.5
2017-10-05 CVE-2017-15025 Divide By Zero vulnerability in GNU Binutils 2.29
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted ELF file.
local
low complexity
gnu CWE-369
5.5
2017-10-05 CVE-2017-15024 Infinite Loop vulnerability in GNU Binutils 2.29
find_abstract_instance_name in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.
local
low complexity
gnu CWE-835
5.5
2017-10-05 CVE-2017-15023 NULL Pointer Dereference vulnerability in GNU Binutils 2.29
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename.
local
low complexity
gnu CWE-476
5.5