Записи gnu
1 208 опубликованных записей вендора gnu.
Профиль для исследователя
- Попали в KEV
- 5 · 0,4 %
- С эксплойтом
- 12 · 1 %
- Pre-auth RCE
- 104
- С записью об исправлении
- 81,4 %
- Медиана: публикация → KEV
- 2683 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer153
- CWE-787 Out-of-bounds Write98
- CWE-125 Out-of-bounds Read93
- CWE-476 NULL Pointer Dereference77
- CWE-190 Integer Overflow or Wraparound46
- CWE-20 Improper Input Validation38
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
1 208 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
99Срочно | CVE-2026-24061Готовый эксплойт | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.gnu · inetutils · CWE-88 | Критическая9,8 | KEV | 99,0 % | 21 янв. 2026 г. |
95Срочно | CVE-2014-6278Готовый эксплойт | GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attgnu · bash · CWE-78 | Высокая8,8 | KEV | 99,6 % | 30 сент. 2014 г. |
85Срочно | CVE-2023-4911Готовый эксплойт | Glibc: buffer overflow in ld.so leading to privilege escalationgnu · glibc · CWE-122 | Высокая7,8 | KEV | 81,4 % | 3 окт. 2023 г. |
68На этой неделе | CVE-2011-4862Готовый эксплойт | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and mit · krb5-appl · CWE-120 | Критическая10,0 | — | 95,0 % | 24 дек. 2011 г. |
68На этой неделе | CVE-2015-0235Готовый эксплойт | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depengnu · glibc · CWE-787 | Критическая10,0 | — | 94,6 % | 28 янв. 2015 г. |
65На этой неделе | CVE-2009-3555Proof of concept | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thapache · http server · CWE-295 | Критическая9,8 | — | 87,3 % | 9 нояб. 2009 г. |
61На этой неделе | CVE-2014-7186Proof of concept | The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bognu · bash · CWE-119 | Критическая10,0 | — | 69,8 % | 28 сент. 2014 г. |
61На этой неделе | CVE-2014-6277Proof of concept | GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attgnu · bash · CWE-78 | Критическая10,0 | — | 69,8 % | 27 сент. 2014 г. |
59В плане | CVE-2015-7547Proof of concept | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc gnu · glibc · CWE-119 | Высокая8,1 | — | 91,0 % | 18 февр. 2016 г. |
59В плане | CVE-2017-13089Proof of concept | GNU Wget: stack overflow in HTTP protocol handlinggnu · wget · CWE-121 | Высокая8,8 | — | 79,9 % | 27 окт. 2017 г. |
59В плане | CVE-2014-7187Proof of concept | Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of gnu · bash · CWE-119 | Критическая10,0 | — | 64,6 % | 28 сент. 2014 г. |
55В плане | CVE-2024-2961Готовый эксплойт | The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when convertignu · glibc · CWE-787 | Высокая7,3 | — | 88,3 % | 17 апр. 2024 г. |
49В плане | CVE-1999-0016Proof of concept | Land IP denial of service.cisco · ios | Средняя5,0 | — | 95,7 % | 1 дек. 1997 г. |
49В плане | CVE-2016-4971Proof of concept | GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.gnu · wget | Высокая8,8 | — | 46,1 % | 30 июн. 2016 г. |
49В плане | CVE-2014-4877Готовый эксплойт | Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary fignu · wget · CWE-22 | Критическая9,3 | — | 39,9 % | 29 окт. 2014 г. |
49В плане | CVE-2017-5334Эксплойта нет | Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackergnu · gnutls · CWE-415 | Критическая9,8 | — | 32,8 % | 24 мар. 2017 г. |
48В плане | CVE-2019-3829Эксплойта нет | A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7.gnu · gnutls · CWE-416 | Высокая7,5 | — | 59,0 % | 27 мар. 2019 г. |
46В плане | CVE-2017-13090Эксплойта нет | GNU Wget: heap overflow in HTTP protocol handlinggnu · wget · CWE-122 | Высокая8,8 | — | 36,6 % | 27 окт. 2017 г. |
46В плане | CVE-2004-1701Proof of concept | Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to executgnu · cfengine | Критическая10,0 | — | 19,5 % | 9 авг. 2004 г. |
45В плане | CVE-2004-1170Proof of concept | a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.gnu · a2ps | Критическая10,0 | — | 16,0 % | 10 янв. 2005 г. |
45В плане | CVE-2004-0354Proof of concept | Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary codegnu · anubis | Критическая10,0 | — | 15,6 % | 23 нояб. 2004 г. |
44В плане | CVE-2008-1948Эксплойта нет | The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly cgnu · gnutls · CWE-189 | Критическая10,0 | — | 12,0 % | 21 мая 2008 г. |
42В плане | CVE-2021-26937Эксплойта нет | encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or gnu · screen · CWE-88 | Критическая9,8 | — | 9,1 % | 9 февр. 2021 г. |
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2026-2406199Срочно
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %gnu · inetutils21 янв. 2026 г.
- CVE-2014-627895Срочно
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote att
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %gnu · bash30 сент. 2014 г.
- CVE-2023-491185Срочно
Glibc: buffer overflow in ld.so leading to privilege escalation
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 81 %gnu · glibc3 окт. 2023 г.
- CVE-2011-486268На этой неделе
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and
КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %mit · krb5-appl24 дек. 2011 г.
- CVE-2015-023568На этой неделе
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen
КритическаяCVSS 10,0Готовый эксплойтEPSS 95 %gnu · glibc28 янв. 2015 г.
- CVE-2009-355565На этой неделе
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th
КритическаяCVSS 9,8Proof of conceptEPSS 87 %apache · http server9 нояб. 2009 г.
- CVE-2014-718661На этой неделе
The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bo
КритическаяCVSS 10,0Proof of conceptEPSS 70 %gnu · bash28 сент. 2014 г.
- CVE-2014-627761На этой неделе
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote att
КритическаяCVSS 10,0Proof of conceptEPSS 70 %gnu · bash27 сент. 2014 г.
- CVE-2015-754759В плане
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc
ВысокаяCVSS 8,1Proof of conceptEPSS 91 %gnu · glibc18 февр. 2016 г.
- CVE-2017-1308959В плане
GNU Wget: stack overflow in HTTP protocol handling
ВысокаяCVSS 8,8Proof of conceptEPSS 80 %gnu · wget27 окт. 2017 г.
- CVE-2014-718759В плане
Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of
КритическаяCVSS 10,0Proof of conceptEPSS 65 %gnu · bash28 сент. 2014 г.
- CVE-2024-296155В плане
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converti
ВысокаяCVSS 7,3Готовый эксплойтEPSS 88 %gnu · glibc17 апр. 2024 г.
- CVE-1999-001649В плане
Land IP denial of service.
СредняяCVSS 5,0Proof of conceptEPSS 96 %cisco · ios1 дек. 1997 г.
- CVE-2016-497149В плане
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
ВысокаяCVSS 8,8Proof of conceptEPSS 46 %gnu · wget30 июн. 2016 г.
- CVE-2014-487749В плане
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary fi
КритическаяCVSS 9,3Готовый эксплойтEPSS 40 %gnu · wget29 окт. 2014 г.
- CVE-2017-533449В плане
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attacker
КритическаяCVSS 9,8Эксплойта нетEPSS 33 %gnu · gnutls24 мар. 2017 г.
- CVE-2019-382948В плане
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7.
ВысокаяCVSS 7,5Эксплойта нетEPSS 59 %gnu · gnutls27 мар. 2019 г.
- CVE-2017-1309046В плане
GNU Wget: heap overflow in HTTP protocol handling
ВысокаяCVSS 8,8Эксплойта нетEPSS 37 %gnu · wget27 окт. 2017 г.
- CVE-2004-170146В плане
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execut
КритическаяCVSS 10,0Proof of conceptEPSS 20 %gnu · cfengine9 авг. 2004 г.
- CVE-2004-117045В плане
a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
КритическаяCVSS 10,0Proof of conceptEPSS 16 %gnu · a2ps10 янв. 2005 г.
- CVE-2004-035445В плане
Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code
КритическаяCVSS 10,0Proof of conceptEPSS 16 %gnu · anubis23 нояб. 2004 г.
- CVE-2008-194844В плане
The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly c
КритическаяCVSS 10,0Эксплойта нетEPSS 12 %gnu · gnutls21 мая 2008 г.
- CVE-2021-2693742В плане
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or
КритическаяCVSS 9,8Эксплойта нетEPSS 9 %gnu · screen9 февр. 2021 г.