gnu kayıtları
gnu üreticisine ait 1.208 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 5 · %0,4
- Silahlaştırılmış
- 12 · %1
- Pre-auth RCE
- 104
- Düzeltme kaydı olan
- %81,4
- Yayından KEV’e ortanca
- 2683 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer153
- CWE-787 Out-of-bounds Write98
- CWE-125 Out-of-bounds Read93
- CWE-476 NULL Pointer Dereference77
- CWE-190 Integer Overflow or Wraparound46
- CWE-20 Improper Input Validation38
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
1.208 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2014-6271Silahlaştırılmış | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Kritik9,8 | KEV | %100,0 | 24 Eyl 2014 |
99Hemen | CVE-2014-7169Silahlaştırılmış | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Kritik9,8 | KEV | %99,9 | 24 Eyl 2014 |
99Hemen | CVE-2026-24061Silahlaştırılmış | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.gnu · inetutils · CWE-88 | Kritik9,8 | KEV | %99,0 | 21 Oca 2026 |
95Hemen | CVE-2014-6278Silahlaştırılmış | GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attgnu · bash · CWE-78 | Yüksek8,8 | KEV | %99,6 | 30 Eyl 2014 |
85Hemen | CVE-2023-4911Silahlaştırılmış | Glibc: buffer overflow in ld.so leading to privilege escalationgnu · glibc · CWE-122 | Yüksek7,8 | KEV | %81,4 | 3 Eki 2023 |
68Bu hafta | CVE-2011-4862Silahlaştırılmış | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and mit · krb5-appl · CWE-120 | Kritik10,0 | — | %95,0 | 24 Ara 2011 |
68Bu hafta | CVE-2015-0235Silahlaştırılmış | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depengnu · glibc · CWE-787 | Kritik10,0 | — | %94,6 | 28 Oca 2015 |
65Bu hafta | CVE-2009-3555Kavram kanıtı | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thapache · http server · CWE-295 | Kritik9,8 | — | %87,3 | 9 Kas 2009 |
61Bu hafta | CVE-2014-7186Kavram kanıtı | The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bognu · bash · CWE-119 | Kritik10,0 | — | %69,8 | 28 Eyl 2014 |
61Bu hafta | CVE-2014-6277Kavram kanıtı | GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attgnu · bash · CWE-78 | Kritik10,0 | — | %69,8 | 27 Eyl 2014 |
59Planlayın | CVE-2015-7547Kavram kanıtı | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc gnu · glibc · CWE-119 | Yüksek8,1 | — | %91,0 | 18 Şub 2016 |
59Planlayın | CVE-2017-13089Kavram kanıtı | GNU Wget: stack overflow in HTTP protocol handlinggnu · wget · CWE-121 | Yüksek8,8 | — | %79,9 | 27 Eki 2017 |
59Planlayın | CVE-2014-7187Kavram kanıtı | Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of gnu · bash · CWE-119 | Kritik10,0 | — | %64,6 | 28 Eyl 2014 |
55Planlayın | CVE-2024-2961Silahlaştırılmış | The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when convertignu · glibc · CWE-787 | Yüksek7,3 | — | %88,3 | 17 Nis 2024 |
49Planlayın | CVE-1999-0016Kavram kanıtı | Land IP denial of service.cisco · ios | Orta5,0 | — | %95,7 | 1 Ara 1997 |
49Planlayın | CVE-2016-4971Kavram kanıtı | GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.gnu · wget | Yüksek8,8 | — | %46,1 | 30 Haz 2016 |
49Planlayın | CVE-2014-4877Silahlaştırılmış | Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary fignu · wget · CWE-22 | Kritik9,3 | — | %39,9 | 29 Eki 2014 |
49Planlayın | CVE-2017-5334İstismar yok | Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackergnu · gnutls · CWE-415 | Kritik9,8 | — | %32,8 | 24 Mar 2017 |
48Planlayın | CVE-2019-3829İstismar yok | A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7.gnu · gnutls · CWE-416 | Yüksek7,5 | — | %59,0 | 27 Mar 2019 |
46Planlayın | CVE-2017-13090İstismar yok | GNU Wget: heap overflow in HTTP protocol handlinggnu · wget · CWE-122 | Yüksek8,8 | — | %36,6 | 27 Eki 2017 |
46Planlayın | CVE-2004-1701Kavram kanıtı | Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to executgnu · cfengine | Kritik10,0 | — | %19,5 | 9 Ağu 2004 |
45Planlayın | CVE-2004-1170Kavram kanıtı | a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.gnu · a2ps | Kritik10,0 | — | %16,0 | 10 Oca 2005 |
45Planlayın | CVE-2004-0354Kavram kanıtı | Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary codegnu · anubis | Kritik10,0 | — | %15,6 | 23 Kas 2004 |
44Planlayın | CVE-2008-1948İstismar yok | The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly cgnu · gnutls · CWE-189 | Kritik10,0 | — | %12,0 | 21 May 2008 |
42Planlayın | CVE-2021-26937İstismar yok | encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or gnu · screen · CWE-88 | Kritik9,8 | — | %9,1 | 9 Şub 2021 |
- CVE-2014-627199Hemen
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2014-716999Hemen
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2026-2406199Hemen
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99gnu · inetutils21 Oca 2026
- CVE-2014-627895Hemen
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote att
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100gnu · bash30 Eyl 2014
- CVE-2023-491185Hemen
Glibc: buffer overflow in ld.so leading to privilege escalation
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %81gnu · glibc3 Eki 2023
- CVE-2011-486268Bu hafta
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and
KritikCVSS 10,0SilahlaştırılmışEPSS %95mit · krb5-appl24 Ara 2011
- CVE-2015-023568Bu hafta
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-depen
KritikCVSS 10,0SilahlaştırılmışEPSS %95gnu · glibc28 Oca 2015
- CVE-2009-355565Bu hafta
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th
KritikCVSS 9,8Kavram kanıtıEPSS %87apache · http server9 Kas 2009
- CVE-2014-718661Bu hafta
The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bo
KritikCVSS 10,0Kavram kanıtıEPSS %70gnu · bash28 Eyl 2014
- CVE-2014-627761Bu hafta
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote att
KritikCVSS 10,0Kavram kanıtıEPSS %70gnu · bash27 Eyl 2014
- CVE-2015-754759Planlayın
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc
YüksekCVSS 8,1Kavram kanıtıEPSS %91gnu · glibc18 Şub 2016
- CVE-2017-1308959Planlayın
GNU Wget: stack overflow in HTTP protocol handling
YüksekCVSS 8,8Kavram kanıtıEPSS %80gnu · wget27 Eki 2017
- CVE-2014-718759Planlayın
Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of
KritikCVSS 10,0Kavram kanıtıEPSS %65gnu · bash28 Eyl 2014
- CVE-2024-296155Planlayın
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converti
YüksekCVSS 7,3SilahlaştırılmışEPSS %88gnu · glibc17 Nis 2024
- CVE-1999-001649Planlayın
Land IP denial of service.
OrtaCVSS 5,0Kavram kanıtıEPSS %96cisco · ios1 Ara 1997
- CVE-2016-497149Planlayın
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted FTP resource.
YüksekCVSS 8,8Kavram kanıtıEPSS %46gnu · wget30 Haz 2016
- CVE-2014-487749Planlayın
Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary fi
KritikCVSS 9,3SilahlaştırılmışEPSS %40gnu · wget29 Eki 2014
- CVE-2017-533449Planlayın
Double free vulnerability in the gnutls_x509_ext_import_proxy function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attacker
KritikCVSS 9,8İstismar yokEPSS %33gnu · gnutls24 Mar 2017
- CVE-2019-382948Planlayın
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7.
YüksekCVSS 7,5İstismar yokEPSS %59gnu · gnutls27 Mar 2019
- CVE-2017-1309046Planlayın
GNU Wget: heap overflow in HTTP protocol handling
YüksekCVSS 8,8İstismar yokEPSS %37gnu · wget27 Eki 2017
- CVE-2004-170146Planlayın
Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execut
KritikCVSS 10,0Kavram kanıtıEPSS %20gnu · cfengine9 Ağu 2004
- CVE-2004-117045Planlayın
a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
KritikCVSS 10,0Kavram kanıtıEPSS %16gnu · a2ps10 Oca 2005
- CVE-2004-035445Planlayın
Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code
KritikCVSS 10,0Kavram kanıtıEPSS %16gnu · anubis23 Kas 2004
- CVE-2008-194844Planlayın
The _gnutls_server_name_recv_params function in lib/ext_server_name.c in libgnutls in gnutls-serv in GnuTLS before 2.2.4 does not properly c
KritikCVSS 10,0İstismar yokEPSS %12gnu · gnutls21 May 2008
- CVE-2021-2693742Planlayın
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or
KritikCVSS 9,8İstismar yokEPSS %9gnu · screen9 Şub 2021