Vulnerabilities
Vulnerable Software
Gnu:  Security Vulnerabilities
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
CVSS Score
5.5
EPSS Score
0.002
Published
2022-01-14
GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excessive CPU and memory resources.
CVSS Score
5.5
EPSS Score
0.003
Published
2022-01-14
The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
CVSS Score
9.8
EPSS Score
0.004
Published
2022-01-14
The deprecated compatibility function clnt_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its hostname argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a stack protector enabled) arbitrary code execution.
CVSS Score
9.8
EPSS Score
0.004
Published
2022-01-14
LibreDWG 0.12.4.4313 through 0.12.4.4367 has an out-of-bounds write in dwg_free_BLOCK_private (called from dwg_free_BLOCK and dwg_free_object).
CVSS Score
6.5
EPSS Score
0.002
Published
2022-01-01
An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.
CVSS Score
5.5
EPSS Score
0.004
Published
2021-12-22
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
CVSS Score
7.8
EPSS Score
0.002
Published
2021-12-15
LibreDWG v0.12.3 was discovered to contain a NULL pointer dereference via out_dxfb.c.
CVSS Score
7.5
EPSS Score
0.004
Published
2021-12-02
LibreDWG v0.12.3 was discovered to contain a heap-buffer overflow via decode_preR13.
CVSS Score
9.8
EPSS Score
0.004
Published
2021-12-02
In GNU Mailman before 2.1.38, a list member or moderator can get a CSRF token and craft an admin request (using that token) to set a new admin password or make other changes.
CVSS Score
8.8
EPSS Score
0.003
Published
2021-12-02


Contact Us

Shodan ® - All rights reserved