Search: "gnu"

1221 CVEs found

A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipula...

Published: 2025-02-17
Products: 1
Vendors:
elfutils_project
CVE-2022-49666
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: powerpc/memhotplug: Add add_pages override for PPC With commit ffa0b64e3be5 ("powerpc: Fix virt_addr_valid() for 64-bit Book3E & 3...

Published: 2025-02-26
Products: 17
Vendors:
linux

When AdaCore Ada Web Server 25.0.0 is linked with GnuTLS, the default behaviour of AWS.Client is vulnerable to a man-in-the-middle attack because of lack of verification of an HTTPS server's certifica...

Published: 2025-02-26
Products: 2
Vendors:
debian adacore

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify sig...

Published: 2025-03-19
Products: 2
Vendors:
gnupg

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kagla GNUCommerce gnucommerce allows Reflected XSS.This issue affects GNUCommerce: from n/a throug...

Published: 2025-03-26
Products: 0

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kagla GNUPress gnupress allows Reflected XSS.This issue affects GNUPress: from n/a through <= 0.2....

Published: 2025-03-26
Products: 0
CVE-2025-31176
6.2 MEDIUM

A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.

Published: 2025-03-27
Products: 4
Vendors:
redhat gnuplot
CVE-2025-31178
6.2 MEDIUM

A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.

Published: 2025-03-27
Products: 4
Vendors:
redhat gnuplot
CVE-2025-31179
6.2 MEDIUM

A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.

Published: 2025-03-27
Products: 4
Vendors:
redhat gnuplot
CVE-2025-31180
6.2 MEDIUM

A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.

Published: 2025-03-27
Products: 4
Vendors:
redhat gnuplot
CVE-2025-31181
6.2 MEDIUM

A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.

Published: 2025-03-27
Products: 4
Vendors:
redhat gnuplot

MinIO is a High Performance Object Storage released under GNU Affero General Public License v3.0. The signature component of the authorization may be invalid, which would mean that as a client you can...

Published: 2025-04-03
Products: 0

A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdu...

Published: 2025-04-04
Products: 2
Vendors:
gnu
CVE-2025-3359
6.2 MEDIUM

A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.

Published: 2025-04-07
Products: 0
CVE-2025-30985
9.8 CRITICAL

Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affects GNUCommerce: from n/a through <= 1.5.4.

Published: 2025-04-15
Products: 0
CVE-2025-32776
5.5 MEDIUM

OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linux. By writing specially crafted data to the `matrix_custom_frame` file, an attac...

Published: 2025-04-15
Products: 0
CVE-2025-43919
5.8 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at /mailman/private/mailman (aka the private archive authentica...

Published: 2025-04-20
Products: 1
Vendors:
gnu
CVE-2025-43920
5.4 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), in certain external archiver configurations, allows unauthenticated attackers to execute arbitrary OS commands via shell metacharacters in an email ...

Published: 2025-04-20
Products: 1
Vendors:
gnu
CVE-2025-43921
5.3 MEDIUM

GNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to create lists via the /mailman/create endpoint. NOTE: multiple third parties report that they are unable to repro...

Published: 2025-04-20
Products: 1
Vendors:
gnu
CVE-2025-47153
6.5 MEDIUM

Certain build processes for libuv and Node.js for 32-bit systems, such as for the nodejs binary package through nodejs_20.19.0+dfsg-2_i386.deb for Debian GNU/Linux, have an inconsistent off_t size (e....

Published: 2025-05-01
Products: 0