Gnu

Glibc

157 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 22.02%
  • Veröffentlicht 29.08.2014 16:55:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment vari...

  • EPSS 0.6%
  • Veröffentlicht 29.07.2014 14:55:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG...

Exploit
  • EPSS 0.6%
  • Veröffentlicht 10.02.2014 18:15:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection ...

  • EPSS 0.67%
  • Veröffentlicht 10.02.2014 18:15:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection ...

  • EPSS 0.87%
  • Veröffentlicht 10.02.2014 18:15:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers...

Exploit
  • EPSS 1.2%
  • Veröffentlicht 12.12.2013 18:55:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that trigg...

Exploit
  • EPSS 18.7%
  • Veröffentlicht 09.10.2013 22:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a heap-base...

Exploit
  • EPSS 0.61%
  • Veröffentlicht 09.10.2013 22:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string that triggers a ...

  • EPSS 0.07%
  • Veröffentlicht 09.10.2013 22:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file sys...

  • EPSS 1.05%
  • Veröffentlicht 09.10.2013 22:55:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted (1) NTFS or (2) CIFS...