Gnu

Glibc

168 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 3.92%
  • Veröffentlicht 06.10.2014 23:55:08
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.

  • EPSS 18.1%
  • Veröffentlicht 29.08.2014 16:55:11
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment vari...

  • EPSS 2.69%
  • Veröffentlicht 29.07.2014 14:55:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG...

Exploit
  • EPSS 2.23%
  • Veröffentlicht 10.02.2014 18:15:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection ...

  • EPSS 2.09%
  • Veröffentlicht 10.02.2014 18:15:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection ...

  • EPSS 3.16%
  • Veröffentlicht 10.02.2014 18:15:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers...

Exploit
  • EPSS 4.15%
  • Veröffentlicht 12.12.2013 18:55:10
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that trigg...

Exploit
  • EPSS 16.67%
  • Veröffentlicht 09.10.2013 22:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a heap-base...

Exploit
  • EPSS 3.38%
  • Veröffentlicht 09.10.2013 22:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string that triggers a ...

  • EPSS 0.35%
  • Veröffentlicht 09.10.2013 22:55:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file sys...