Search: "gnu"

1221 CVEs found

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and application exit) via crafted input data, such as data that triggers a...

Published: 2025-05-03
Products: 1
Vendors:
gnu
CVE-2025-31177
5.5 MEDIUM

gnuplot is affected by a heap buffer overflow at function utf8_copy_one.

Published: 2025-05-07
Products: 1
Vendors:
gnuplot
CVE-2025-47814
4.5 MEDIUM

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_read_xml_member) in zip-reader.c.

Published: 2025-05-10
Products: 1
Vendors:
gnu
CVE-2025-47815
4.5 MEDIUM

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_member_read_all) in zip-reader.c.

Published: 2025-05-10
Products: 1
Vendors:
gnu

libpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related to extra content at the end of a document.

Published: 2025-05-10
Products: 1
Vendors:
gnu

Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid bi...

Published: 2025-05-16
Products: 1
Vendors:
gnu

libpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt function, leading to a heap-based buffer over-read.

Published: 2025-05-16
Products: 1
Vendors:
gnu

A vulnerability was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. It has been declared as problematic. This vulnerability affects the function calloc of the file pspp-convert.c. The mani...

Published: 2025-05-20
Products: 1
Vendors:
gnu
CVE-2025-5244
5.3 MEDIUM

A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation...

Published: 2025-05-27
Products: 1
Vendors:
gnu
CVE-2025-5245
5.3 MEDIUM

A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation le...

Published: 2025-05-27
Products: 1
Vendors:
gnu
CVE-2025-5278
4.4 MEDIUM

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted...

Published: 2025-05-27
Products: 0
CVE-2025-5702
5.6 MEDIUM

The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers...

Published: 2025-06-05
Products: 3
Vendors:
gnu
CVE-2025-5745
5.6 MEDIUM

The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector registers v20 to v31 without saving contents from the caller (those register...

Published: 2025-06-05
Products: 2
Vendors:
gnu
CVE-2025-5898
5.3 MEDIUM

A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The ma...

Published: 2025-06-09
Products: 0
CVE-2025-5899
5.3 MEDIUM

A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-...

Published: 2025-06-09
Products: 0

A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipul...

Published: 2025-06-16
Products: 0
CVE-2025-49431
6.5 MEDIUM

Missing Authorization vulnerability in Gnuget MF Plus WPML mf-plus-wpml allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MF Plus WPML: from n/a through <= 1.1...

Published: 2025-07-04
Products: 0
CVE-2024-37656
6.1 MEDIUM

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the insufficient URL parameter verification in bbs/logout.php.

Published: 2025-07-07
Products: 1
Vendors:
sir
CVE-2024-37657
6.1 MEDIUM

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via thebbs/login.php component.

Published: 2025-07-07
Products: 1
Vendors:
sir
CVE-2024-37658
6.1 MEDIUM

An open redirect vulnerability in gnuboard5 v.5.5.16 allows a remote attacker to obtain sensitive information via the bbs/member_confirm.php.

Published: 2025-07-07
Products: 1
Vendors:
sir