CVE-2011-1071
- EPSS 4.08%
- Veröffentlicht 08.04.2011 15:17:27
- Zuletzt bearbeitet 11.04.2025 00:51:21
The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka...
CVE-2011-0536
- EPSS 0.28%
- Veröffentlicht 08.04.2011 15:17:26
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain...
CVE-2009-5064
- EPSS 0.09%
- Veröffentlicht 30.03.2011 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor s...
- EPSS 0.39%
- Veröffentlicht 02.03.2011 20:00:01
- Zuletzt bearbeitet 03.11.2025 22:15:41
The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expres...
- EPSS 4.66%
- Veröffentlicht 13.01.2011 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (application crash) via a regular expression containing adjacent bounded r...
- EPSS 9.95%
- Veröffentlicht 13.01.2011 19:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular exp...
CVE-2010-3847
- EPSS 4.98%
- Veröffentlicht 07.01.2011 19:00:17
- Zuletzt bearbeitet 11.04.2025 00:51:21
elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted d...
CVE-2010-3856
- EPSS 5.86%
- Veröffentlicht 07.01.2011 19:00:17
- Zuletzt bearbeitet 11.04.2025 00:51:21
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain...
- EPSS 0.79%
- Veröffentlicht 14.10.2010 05:58:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorre...
- EPSS 13.53%
- Veröffentlicht 01.06.2010 20:30:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string...