elfutils project records
33 published records for vendor elfutils project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 90.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-125 Out-of-bounds Read12
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-404 Improper Resource Shutdown or Release3
- CWE-787 Out-of-bounds Write2
- CWE-20 Improper Input Validation2
- CWE-369 Divide By Zero1
The weakness classes this vendor ships most often: where to look.
CWEAll records
33 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-16402No exploit | libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly haveelfutils project · elfutils · CWE-415 | Critical9.8 | — | 3.7% | Sep 3, 2018 |
31Monitor | CVE-2018-8769No exploit | elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupportedelfutils project · elfutils · CWE-125 | High7.8 | — | 0.8% | Mar 18, 2018 |
28Monitor | CVE-2014-0172No exploit | Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.1elfutils project · elfutils · CWE-189 | Medium6.8 | — | 4.0% | Apr 11, 2014 |
27Monitor | CVE-2014-9447No exploit | Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers elfutils project · elfutils · CWE-22 | Medium6.4 | — | 5.0% | Jan 2, 2015 |
27Monitor | CVE-2018-18520No exploit | An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174.elfutils project · elfutils · CWE-119 | Medium6.5 | — | 2.8% | Oct 19, 2018 |
27Monitor | CVE-2019-7149No exploit | A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175.elfutils project · elfutils · CWE-125 | Medium6.5 | — | 2.1% | Jan 28, 2019 |
26Monitor | CVE-2019-7148No exploit | An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174.elfutils project · elfutils · CWE-770 | Medium6.5 | — | 1.6% | Jan 28, 2019 |
23Monitor | CVE-2017-7608No exploit | The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-elfutils project · elfutils · CWE-125 | Medium5.5 | — | 2.1% | Apr 9, 2017 |
23Monitor | CVE-2017-7611No exploit | The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-elfutils project · elfutils · CWE-125 | Medium5.5 | — | 1.8% | Apr 9, 2017 |
23Monitor | CVE-2018-18521No exploit | Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of elfutils project · elfutils · CWE-369 | Medium5.5 | — | 1.8% | Oct 19, 2018 |
23Monitor | CVE-2017-7610No exploit | The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read anelfutils project · elfutils · CWE-125 | Medium5.5 | — | 1.8% | Apr 9, 2017 |
23Monitor | CVE-2017-7612No exploit | The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-reaelfutils project · elfutils · CWE-125 | Medium5.5 | — | 1.8% | Apr 9, 2017 |
23Monitor | CVE-2017-7613No exploit | elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a deelfutils project · elfutils · CWE-20 | Medium5.5 | — | 1.7% | Apr 9, 2017 |
23Monitor | CVE-2017-7607No exploit | The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-reaelfutils project · elfutils · CWE-125 | Medium5.5 | — | 1.7% | Apr 9, 2017 |
22Monitor | CVE-2016-10255No exploit | The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (craelfutils project · elfutils · CWE-119 | Medium5.5 | — | 1.7% | Mar 23, 2017 |
22Monitor | CVE-2017-7609No exploit | elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (elfutils project · elfutils · CWE-20 | Medium5.5 | — | 1.6% | Apr 9, 2017 |
22Monitor | CVE-2018-16062No exploit | dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-baselfutils project · elfutils · CWE-125 | Medium5.5 | — | 1.6% | Aug 28, 2018 |
22Monitor | CVE-2016-10254No exploit | The allocate_elf function in common.h in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted ELelfutils project · elfutils · CWE-119 | Medium5.5 | — | 1.6% | Mar 23, 2017 |
22Monitor | CVE-2019-7146No exploit | In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl.elfutils project · elfutils · CWE-125 | Medium5.5 | — | 1.5% | Jan 28, 2019 |
22Monitor | CVE-2018-18310No exploit | An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174.elfutils project · elfutils · CWE-119 | Medium5.5 | — | 1.4% | Oct 14, 2018 |
22Monitor | CVE-2019-7150No exploit | An issue was discovered in elfutils 0.175.elfutils project · elfutils · CWE-125 | Medium5.5 | — | 1.4% | Jan 28, 2019 |
22Monitor | CVE-2019-7665No exploit | In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf.elfutils project · elfutils · CWE-125 | Medium5.5 | — | 1.3% | Feb 9, 2019 |
22Monitor | CVE-2018-16403No exploit | libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarfelfutils project · elfutils · CWE-125 | Medium5.5 | — | 1.1% | Sep 3, 2018 |
22Monitor | CVE-2019-7664No exploit | In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check.elfutils project · elfutils · CWE-787 | Medium5.5 | — | 1.0% | Feb 9, 2019 |
22Monitor | CVE-2021-33294No exploit | In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of servicelfutils project · elfutils · CWE-835 | Medium5.5 | — | 0.3% | Jul 18, 2023 |
- CVE-2018-1640240Plan
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have
CriticalCVSS 9.8No exploitEPSS 4%elfutils project · elfutilsSep 3, 2018
- CVE-2018-876931Monitor
elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported
HighCVSS 7.8No exploitEPSS 1%elfutils project · elfutilsMar 18, 2018
- CVE-2014-017228Monitor
Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.1
MediumCVSS 6.8No exploitEPSS 4%elfutils project · elfutilsApr 11, 2014
- CVE-2014-944727Monitor
Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers
MediumCVSS 6.4No exploitEPSS 5%elfutils project · elfutilsJan 2, 2015
- CVE-2018-1852027Monitor
An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174.
MediumCVSS 6.5No exploitEPSS 3%elfutils project · elfutilsOct 19, 2018
- CVE-2019-714927Monitor
A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175.
MediumCVSS 6.5No exploitEPSS 2%elfutils project · elfutilsJan 28, 2019
- CVE-2019-714826Monitor
An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174.
MediumCVSS 6.5No exploitEPSS 2%elfutils project · elfutilsJan 28, 2019
- CVE-2017-760823Monitor
The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-
MediumCVSS 5.5No exploitEPSS 2%elfutils project · elfutilsApr 9, 2017
- CVE-2017-761123Monitor
The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-
MediumCVSS 5.5No exploitEPSS 2%elfutils project · elfutilsApr 9, 2017
- CVE-2018-1852123Monitor
Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of
MediumCVSS 5.5No exploitEPSS 2%elfutils project · elfutilsOct 19, 2018
- CVE-2017-761023Monitor
The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read an
MediumCVSS 5.5No exploitEPSS 2%elfutils project · elfutilsApr 9, 2017
- CVE-2017-761223Monitor
The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-rea
MediumCVSS 5.5No exploitEPSS 2%elfutils project · elfutilsApr 9, 2017
- CVE-2017-761323Monitor
elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a de
MediumCVSS 5.5No exploitEPSS 2%elfutils project · elfutilsApr 9, 2017
- CVE-2017-760723Monitor
The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-rea
MediumCVSS 5.5No exploitEPSS 2%elfutils project · elfutilsApr 9, 2017
- CVE-2016-1025522Monitor
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (cra
MediumCVSS 5.5No exploitEPSS 2%elfutils project · elfutilsMar 23, 2017
- CVE-2017-760922Monitor
elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (
MediumCVSS 5.5No exploitEPSS 2%elfutils project · elfutilsApr 9, 2017
- CVE-2018-1606222Monitor
dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-bas
MediumCVSS 5.5No exploitEPSS 2%elfutils project · elfutilsAug 28, 2018
- CVE-2016-1025422Monitor
The allocate_elf function in common.h in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted EL
MediumCVSS 5.5No exploitEPSS 2%elfutils project · elfutilsMar 23, 2017
- CVE-2019-714622Monitor
In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl.
MediumCVSS 5.5No exploitEPSS 2%elfutils project · elfutilsJan 28, 2019
- CVE-2018-1831022Monitor
An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174.
MediumCVSS 5.5No exploitEPSS 1%elfutils project · elfutilsOct 14, 2018
- CVE-2019-715022Monitor
An issue was discovered in elfutils 0.175.
MediumCVSS 5.5No exploitEPSS 1%elfutils project · elfutilsJan 28, 2019
- CVE-2019-766522Monitor
In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf.
MediumCVSS 5.5No exploitEPSS 1%elfutils project · elfutilsFeb 9, 2019
- CVE-2018-1640322Monitor
libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf
MediumCVSS 5.5No exploitEPSS 1%elfutils project · elfutilsSep 3, 2018
- CVE-2019-766422Monitor
In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check.
MediumCVSS 5.5No exploitEPSS 1%elfutils project · elfutilsFeb 9, 2019
- CVE-2021-3329422Monitor
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of servic
MediumCVSS 5.5No exploitEPSS 0%elfutils project · elfutilsJul 18, 2023