CVE-2024-33602
- EPSS 0.4%
- Veröffentlicht 06.05.2024 20:15:11
- Zuletzt bearbeitet 12.05.2026 12:16:35
nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 ...
CVE-2024-2961
- EPSS 88.33%
- Veröffentlicht 17.04.2024 18:15:15
- Zuletzt bearbeitet 12.05.2026 12:16:34
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neig...
CVE-2023-6246
- EPSS 4.79%
- Veröffentlicht 31.01.2024 14:15:48
- Zuletzt bearbeitet 12.05.2026 11:16:18
A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument...
CVE-2023-6779
- EPSS 3.15%
- Veröffentlicht 31.01.2024 14:15:48
- Zuletzt bearbeitet 12.05.2026 11:16:18
An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_...
CVE-2023-6780
- EPSS 2.71%
- Veröffentlicht 31.01.2024 14:15:48
- Zuletzt bearbeitet 12.05.2026 11:16:18
An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect ca...
CVE-2023-4911
- EPSS 81.42%
- Veröffentlicht 03.10.2023 18:15:10
- Zuletzt bearbeitet 12.05.2026 16:24:45
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launch...
CVE-2023-5156
- EPSS 1.34%
- Veröffentlicht 25.09.2023 16:15:15
- Zuletzt bearbeitet 21.11.2024 08:41:10
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
CVE-2023-4527
- EPSS 1.51%
- Veröffentlicht 18.09.2023 17:15:55
- Zuletzt bearbeitet 12.05.2026 11:16:15
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack con...
CVE-2023-4806
- EPSS 1.44%
- Veröffentlicht 18.09.2023 17:15:55
- Zuletzt bearbeitet 14.07.2026 14:16:31
A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethos...
CVE-2023-4813
- EPSS 1.66%
- Veröffentlicht 12.09.2023 22:15:08
- Zuletzt bearbeitet 26.09.2025 12:15:34
A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database...