Skip to content
Noroxi

gnu records

1,208 published records for vendor gnu.

Researcher profile

Entered KEV
5 · 0.4%
Weaponized
12 · 1%
Pre-auth RCE
104
With a fix record
81.4%
Median publish → KEV
2683 days

All records

1,208 records
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    gnu · inetutilsJan 21, 2026

  • GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote att

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    gnu · bashSep 30, 2014

  • Glibc: buffer overflow in ld.so leading to privilege escalation

    HighCVSS 7.8KEVWeaponizedEPSS 81%

    gnu · glibcOct 3, 2023

  • CVE-2011-4862
    68This week

    Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and

    CriticalCVSS 10.0WeaponizedEPSS 95%

    mit · krb5-applDec 24, 2011

  • CVE-2015-0235
    68This week

    Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen

    CriticalCVSS 10.0WeaponizedEPSS 95%

    gnu · glibcJan 28, 2015

  • CVE-2009-3555
    65This week

    The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th

    CriticalCVSS 9.8Proof of conceptEPSS 87%

    apache · http serverNov 9, 2009

  • CVE-2014-7186
    61This week

    The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bo

    CriticalCVSS 10.0Proof of conceptEPSS 70%

    gnu · bashSep 28, 2014

  • CVE-2014-6277
    61This week

    GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote att

    CriticalCVSS 10.0Proof of conceptEPSS 70%

    gnu · bashSep 27, 2014

  • Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc

    HighCVSS 8.1Proof of conceptEPSS 91%

    gnu · glibcFeb 18, 2016

  • GNU Wget: stack overflow in HTTP protocol handling

    HighCVSS 8.8Proof of conceptEPSS 80%

    gnu · wgetOct 27, 2017

  • Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of

    CriticalCVSS 10.0Proof of conceptEPSS 65%

    gnu · bashSep 28, 2014

  • The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converti

    HighCVSS 7.3WeaponizedEPSS 88%

    gnu · glibcApr 17, 2024

  • Land IP denial of service.

    MediumCVSS 5.0Proof of conceptEPSS 96%

    cisco · iosDec 1, 1997

  • GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

    HighCVSS 8.8Proof of conceptEPSS 46%

    gnu · wgetJun 30, 2016

  • Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary fi

    CriticalCVSS 9.3WeaponizedEPSS 40%

    gnu · wgetOct 29, 2014

  • Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attacker

    CriticalCVSS 9.8No exploitEPSS 33%

    gnu · gnutlsMar 24, 2017

  • A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7.

    HighCVSS 7.5No exploitEPSS 59%

    gnu · gnutlsMar 27, 2019

  • GNU Wget: heap overflow in HTTP protocol handling

    HighCVSS 8.8No exploitEPSS 37%

    gnu · wgetOct 27, 2017

  • Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execut

    CriticalCVSS 10.0Proof of conceptEPSS 20%

    gnu · cfengineAug 9, 2004

  • a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.

    CriticalCVSS 10.0Proof of conceptEPSS 16%

    gnu · a2psJan 10, 2005

  • Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code

    CriticalCVSS 10.0Proof of conceptEPSS 16%

    gnu · anubisNov 23, 2004

  • The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly c

    CriticalCVSS 10.0No exploitEPSS 12%

    gnu · gnutlsMay 21, 2008

  • encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or

    CriticalCVSS 9.8No exploitEPSS 9%

    gnu · screenFeb 9, 2021