Search: "gnu"

1222 CVEs found

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may b...

Published: 2024-04-17
Products: 22
Vendors:
netapp debian gnu
CVE-2024-24157
6.1 MEDIUM

Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea48618d957332d90f6d40e4 is vulnerable to Cross Site Scripting (XSS) via board.py.

Published: 2024-05-14
Products: 1
Vendors:
sir
CVE-2023-52750
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: arm64: Restrict CPU_BIG_ENDIAN to GNU as or LLVM IAS 15.x or newer Prior to LLVM 15.0.0, LLVM's integrated assembler would incorre...

Published: 2024-05-21
Products: 5
Vendors:
linux

In the Linux kernel, the following vulnerability has been resolved: sata_fsl: fix UAF in sata_fsl_port_stop when rmmod sata_fsl When the `rmmod sata_fsl.ko` command is executed in the PPC64 GNU/Linu...

Published: 2024-05-24
Products: 10
Vendors:
linux
CVE-2024-36107
5.3 MEDIUM

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. `If-Modified-Since` and `If-Unmodified-Since` headers when used with anonymous requests by sending a r...

Published: 2024-05-28
Products: 0
CVE-2024-5742
6.7 MEDIUM

A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the per...

Published: 2024-06-12
Products: 5
Vendors:
redhat gnu
CVE-2024-38428
9.1 CRITICAL

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent...

Published: 2024-06-16
Products: 1
Vendors:
gnu
CVE-2024-38448
9.1 CRITICAL

htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.

Published: 2024-06-16
Products: 0

Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.

Published: 2024-08-12
Products: 1
Vendors:
sir

gettext.js is a GNU gettext port for node and the browser. There is a cross-site scripting (XSS) injection if `.po` dictionary definition files are corrupted. This vulnerability has been patched in ve...

Published: 2024-08-16
Products: 0

calamares-nixos-extensions provides Calamares branding and modules for NixOS, a distribution of GNU/Linux. Users who installed NixOS through the graphical installer who used manual disk partitioning t...

Published: 2024-08-16
Products: 0
CVE-2024-39097
6.1 MEDIUM

There is an Open Redirect vulnerability in Gnuboard v6.0.4 and below via the `url` parameter in login path.

Published: 2024-08-26
Products: 1
Vendors:
sir

guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly...

Published: 2024-11-17
Products: 0

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that...

Published: 2024-11-27
Products: 1
Vendors:
gnu

GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.

Published: 2024-12-05
Products: 0

MinIO is a high-performance, S3 compatible object store, open sourced under GNU AGPLv3 license. Minio is subject to a privilege escalation in IAM import API, all users are impacted since MinIO commit ...

Published: 2024-12-16
Products: 0

GNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.

Published: 2024-12-29
Products: 1
Vendors:
gnu
CVE-2024-56738
5.3 MEDIUM

GNU GRUB (aka GRUB2) through 2.12 does not use a constant-time algorithm for grub_crypto_memcmp and thus allows side-channel attacks.

Published: 2024-12-29
Products: 1
Vendors:
gnu
CVE-2025-0395
6.2 MEDIUM

When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer...

Published: 2025-01-22
Products: 0
CVE-2025-0840
5.0 MEDIUM

A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument...

Published: 2025-01-29
Products: 1
Vendors:
gnu