Debian Glibc vulnerabilities
145 known vulnerabilities affecting debian/glibc.
Total CVEs
145
CISA KEV
1
actively exploited
Public exploits
22
Exploited in wild
4
Severity breakdown
CRITICAL17HIGH42MEDIUM45LOW41
Vulnerabilities
Page 8 of 8
CVE-2013-2207P4LOWCVSS 2.6fixed in glibc 2.21-1 (bookworm)2013
CVE-2013-2207 [LOW] CVE-2013-2207: glibc - pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly che...
pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.
Scope: local
bookworm: resolved (fixed in 2.21-1)
bullseye: resolved (fixed in 2.21-1)
forky: resolved (fixed in 2.21-
debian
CVE-2011-1089P4HIGHCVSS 7.2fixed in glibc 2.13-8 (bookworm)2011
CVE-2011-1089 [HIGH] CVE-2011-1089: glibc - The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlie...
The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-0296.
Scope: local
debian
CVE-2004-0968P4LOWCVSS 2.1fixed in glibc 2.3.2.ds1-19 (bookworm)2004
CVE-2004-0968 [LOW] CVE-2004-0968: glibc - The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite ...
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
Scope: local
bookworm: resolved (fixed in 2.3.2.ds1-19)
bullseye: resolved (fixed in 2.3.2.ds1-19)
forky: resolved (fixed in 2.3.2.ds1-19)
sid: resolved (fixed in 2.3.2.ds1-19)
trixie: resolved (fixed in 2.3.2.ds1-19)
debian
CVE-2004-1453P4LOWCVSS 2.1fixed in glibc 2.3.5 (bookworm)2004
CVE-2004-1453 [LOW] CVE-2004-1453: glibc - GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 be...
GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.
Scope: local
bookworm: resolved (fixed in 2.3.5)
bullseye: resolved (fixed in 2.3.5)
forky: resolved (fixed in 2.
debian
CVE-2021-27645P4LOWCVSS 2.5fixed in glibc 2.31-10 (bookworm)2021
CVE-2021-27645 [LOW] CVE-2021-27645: glibc - The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2...
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c.
Scope: local
bookworm: resolved (fixed in 2.31-10)
bullseye: resolved (fix
debian
← Previous8 / 8