CVE-2024-33601
- EPSS 0.1%
- Veröffentlicht 06.05.2024 20:15:11
- Zuletzt bearbeitet 01.08.2025 01:56:26
nscd: netgroup cache may terminate daemon on memory allocation failure The Name Service Cache Daemon's (nscd) netgroup cache uses xmalloc or xrealloc and these functions may terminate the process due to a memory allocation failure resulting in a den...
CVE-2024-33602
- EPSS 0.45%
- Veröffentlicht 06.05.2024 20:15:11
- Zuletzt bearbeitet 18.06.2025 14:40:48
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 ...
CVE-2024-2961
- EPSS 92.84%
- Veröffentlicht 17.04.2024 18:15:15
- Zuletzt bearbeitet 13.02.2025 18:17:58
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neig...
CVE-2023-6246
- EPSS 26.96%
- Veröffentlicht 31.01.2024 14:15:48
- Zuletzt bearbeitet 21.11.2024 08:43:27
A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument...
CVE-2023-6779
- EPSS 0.71%
- Veröffentlicht 31.01.2024 14:15:48
- Zuletzt bearbeitet 21.11.2024 08:44:32
An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_...
CVE-2023-6780
- EPSS 0.23%
- Veröffentlicht 31.01.2024 14:15:48
- Zuletzt bearbeitet 07.02.2025 17:15:29
An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect ca...
CVE-2023-4911
- EPSS 57.7%
- Veröffentlicht 03.10.2023 18:15:10
- Zuletzt bearbeitet 13.02.2026 21:25:07
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launch...
CVE-2023-5156
- EPSS 0.06%
- Veröffentlicht 25.09.2023 16:15:15
- Zuletzt bearbeitet 21.11.2024 08:41:10
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
CVE-2023-4527
- EPSS 0.11%
- Veröffentlicht 18.09.2023 17:15:55
- Zuletzt bearbeitet 24.06.2025 17:31:20
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack con...
CVE-2023-4806
- EPSS 1.9%
- Veröffentlicht 18.09.2023 17:15:55
- Zuletzt bearbeitet 26.09.2025 12:15:32
A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethos...