Gnu

Glibc

168 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 11.16%
  • Veröffentlicht 07.01.2011 19:00:17
  • Zuletzt bearbeitet 16.06.2026 23:23:41

ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain...

  • EPSS 1.61%
  • Veröffentlicht 14.10.2010 05:58:06
  • Zuletzt bearbeitet 16.06.2026 23:22:20

Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorre...

Exploit
  • EPSS 11.22%
  • Veröffentlicht 01.06.2010 20:30:02
  • Zuletzt bearbeitet 16.06.2026 23:14:31

Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string...

  • EPSS 2.03%
  • Veröffentlicht 01.06.2010 20:30:02
  • Zuletzt bearbeitet 16.06.2026 23:14:32

Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafte...

  • EPSS 0.59%
  • Veröffentlicht 01.06.2010 20:30:02
  • Zuletzt bearbeitet 16.06.2026 23:15:52

The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of ...

  • EPSS 4.51%
  • Veröffentlicht 01.06.2010 20:30:02
  • Zuletzt bearbeitet 16.06.2026 23:16:55

Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through 2.11.1, when the --verify option is used, allows user-assisted remote attackers to execute arbitrary ...

  • EPSS 3.07%
  • Veröffentlicht 14.01.2010 18:30:00
  • Zuletzt bearbeitet 16.06.2026 23:15:14

nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords o...

  • EPSS 0.39%
  • Veröffentlicht 09.02.2005 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:06:45

The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.

  • EPSS 0.36%
  • Veröffentlicht 31.12.2004 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:07:35

The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.

  • EPSS 0.36%
  • Veröffentlicht 31.12.2004 05:00:00
  • Zuletzt bearbeitet 16.06.2026 22:07:44

GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the...