İçeriğe atla
Noroxi

gnu kayıtları

gnu üreticisine ait 1.208 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
5 · %0,4
Silahlaştırılmış
12 · %1
Pre-auth RCE
104
Düzeltme kaydı olan
%81,4
Yayından KEV’e ortanca
2683 gün

Tüm kayıtlar

1.208 kayıt
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    gnu · bash24 Eyl 2014

  • telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    gnu · inetutils21 Oca 2026

  • GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote att

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100

    gnu · bash30 Eyl 2014

  • Glibc: buffer overflow in ld.so leading to privilege escalation

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %81

    gnu · glibc3 Eki 2023

  • CVE-2011-4862
    68Bu hafta

    Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and

    KritikCVSS 10,0SilahlaştırılmışEPSS %95

    mit · krb5-appl24 Ara 2011

  • CVE-2015-0235
    68Bu hafta

    Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen

    KritikCVSS 10,0SilahlaştırılmışEPSS %95

    gnu · glibc28 Oca 2015

  • CVE-2009-3555
    65Bu hafta

    The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th

    KritikCVSS 9,8Kavram kanıtıEPSS %87

    apache · http server9 Kas 2009

  • CVE-2014-7186
    61Bu hafta

    The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bo

    KritikCVSS 10,0Kavram kanıtıEPSS %70

    gnu · bash28 Eyl 2014

  • CVE-2014-6277
    61Bu hafta

    GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote att

    KritikCVSS 10,0Kavram kanıtıEPSS %70

    gnu · bash27 Eyl 2014

  • CVE-2015-7547
    59Planlayın

    Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc

    YüksekCVSS 8,1Kavram kanıtıEPSS %91

    gnu · glibc18 Şub 2016

  • CVE-2017-13089
    59Planlayın

    GNU Wget: stack overflow in HTTP protocol handling

    YüksekCVSS 8,8Kavram kanıtıEPSS %80

    gnu · wget27 Eki 2017

  • CVE-2014-7187
    59Planlayın

    Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of

    KritikCVSS 10,0Kavram kanıtıEPSS %65

    gnu · bash28 Eyl 2014

  • CVE-2024-2961
    55Planlayın

    The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converti

    YüksekCVSS 7,3SilahlaştırılmışEPSS %88

    gnu · glibc17 Nis 2024

  • CVE-1999-0016
    49Planlayın

    Land IP denial of service.

    OrtaCVSS 5,0Kavram kanıtıEPSS %96

    cisco · ios1 Ara 1997

  • CVE-2016-4971
    49Planlayın

    GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.

    YüksekCVSS 8,8Kavram kanıtıEPSS %46

    gnu · wget30 Haz 2016

  • CVE-2014-4877
    49Planlayın

    Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary fi

    KritikCVSS 9,3SilahlaştırılmışEPSS %40

    gnu · wget29 Eki 2014

  • CVE-2017-5334
    49Planlayın

    Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attacker

    KritikCVSS 9,8İstismar yokEPSS %33

    gnu · gnutls24 Mar 2017

  • CVE-2019-3829
    48Planlayın

    A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7.

    YüksekCVSS 7,5İstismar yokEPSS %59

    gnu · gnutls27 Mar 2019

  • CVE-2017-13090
    46Planlayın

    GNU Wget: heap overflow in HTTP protocol handling

    YüksekCVSS 8,8İstismar yokEPSS %37

    gnu · wget27 Eki 2017

  • CVE-2004-1701
    46Planlayın

    Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execut

    KritikCVSS 10,0Kavram kanıtıEPSS %20

    gnu · cfengine9 Ağu 2004

  • CVE-2004-1170
    45Planlayın

    a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.

    KritikCVSS 10,0Kavram kanıtıEPSS %16

    gnu · a2ps10 Oca 2005

  • CVE-2004-0354
    45Planlayın

    Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code

    KritikCVSS 10,0Kavram kanıtıEPSS %16

    gnu · anubis23 Kas 2004

  • CVE-2008-1948
    44Planlayın

    The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly c

    KritikCVSS 10,0İstismar yokEPSS %12

    gnu · gnutls21 May 2008

  • CVE-2021-26937
    42Planlayın

    encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or

    KritikCVSS 9,8İstismar yokEPSS %9

    gnu · screen9 Şub 2021