Gnu

Binutils

249 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Published 22.03.2017 16:59:00
  • Last modified 20.04.2025 01:37:25

GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash. This relates to lack of '\0' termination of a name field in ldlex.l.

  • EPSS 0.38%
  • Published 21.03.2017 06:59:00
  • Last modified 20.04.2025 01:37:25

ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.

  • EPSS 0.31%
  • Published 21.03.2017 06:59:00
  • Last modified 20.04.2025 01:37:25

The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NULL pointer while reading section contents in a corrupt binary, leading to a program crash.

  • EPSS 0.31%
  • Published 21.03.2017 06:59:00
  • Last modified 20.04.2025 01:37:25

objdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer over-reads (of size 1 and size 8) while handling corrupt STABS enum type strings in a crafted object file, leading to program crash.

Exploit
  • EPSS 0.25%
  • Published 17.03.2017 09:59:00
  • Last modified 20.04.2025 01:37:25

readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow.

Exploit
  • EPSS 0.28%
  • Published 17.03.2017 09:59:00
  • Last modified 20.04.2025 01:37:25

readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invoca...

Exploit
  • EPSS 0.46%
  • Published 17.03.2017 09:59:00
  • Last modified 20.04.2025 01:37:25

readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.

Exploit
  • EPSS 6.06%
  • Published 15.01.2015 15:59:14
  • Last modified 12.04.2025 10:46:40

The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.

Exploit
  • EPSS 0.06%
  • Published 09.12.2014 23:59:07
  • Last modified 12.04.2025 10:46:40

Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) ...

Exploit
  • EPSS 4.45%
  • Published 09.12.2014 23:59:06
  • Last modified 12.04.2025 10:46:40

Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.