cbcvebase.

Gnu Binutils vulnerabilities

286 known vulnerabilities affecting gnu/binutils.

Total CVEs
286
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH121MEDIUM150LOW10

Vulnerabilities

Page 11 of 15
CVE-2017-6965P4MEDIUMCVSS 5.5v2.282017-03-17
CVE-2017-6965 [MEDIUM] CWE-119 CVE-2017-6965: readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files contai readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow.
nvdosv
CVE-2020-35493P4MEDIUMCVSS 5.5fixed in 2.34vbinutils 2.342021-01-04
CVE-2020-35493 [MEDIUM] CWE-20 CVE-2020-35493: A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be p A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.
nvdosv
CVE-2022-48064P4MEDIUMCVSS 5.5fixed in 2.402023-08-22
CVE-2022-48064 [MEDIUM] CWE-770 CVE-2022-48064: GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.
nvdosv
CVE-2022-48063P4MEDIUMCVSS 5.5fixed in 2.402023-08-22
CVE-2022-48063 [MEDIUM] CWE-400 CVE-2022-48063: GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.
nvdosv
CVE-2024-57360P4MEDIUMCVSS 5.5≥ 0, < 2.34-6ubuntu1.10≥ 0, < 2.38-4ubuntu2.7+1 more2025-02-26
CVE-2024-57360 [MEDIUM] binutils vulnerabilities binutils vulnerabilities It was discovered that GNU binutils in nm tool is affected by an incorrect access control. An attacker could possibly use this issue to cause a crash. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 24.10. (CVE-2024-57360) It was discovered that GNU binutils incorrectly handled certain inputs. An attacker could possibly use this issue to cause a crash or execute arbitrary code. (CVE-2025-0840)
osv
CVE-2025-69646P4MEDIUMCVSS 5.5v2.442026-03-06
CVE-2025-69646 [MEDIUM] CWE-400 CVE-2025-69646: Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with ma Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted
nvd
CVE-2016-4492P4MEDIUMCVSS 4.4≥ 0, < 2.27.51.20161102-12017-02-24
CVE-2016-4492 [MEDIUM] CVE-2016-4492: Buffer overflow in the do_type function in cplus-dem Buffer overflow in the do_type function in cplus-dem.c in libiberty allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted binary.
osv
CVE-2018-10535P4MEDIUMCVSS 5.5v2.302018-04-29
CVE-2018-10535 [MEDIUM] CWE-476 CVE-2018-10535: The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), a The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not validate the output_section pointer in the case of a symtab entry with a "SECTION" type that has a "0" value, which allows remote attackers to cause a denial of service (NULL pointer dereference and applica
nvdosv
CVE-2018-6759P4MEDIUMCVSS 5.5v2.302018-02-06
CVE-2018-6759 [MEDIUM] CWE-20 CVE-2018-6759: The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka The bfd_get_debug_link_info_1 function in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, has an unchecked strnlen operation. Remote attackers could leverage this vulnerability to cause a denial of service (segmentation fault) via a crafted ELF file.
nvdosv
CVE-2017-9039P4MEDIUMCVSS 5.5v2.282017-05-18
CVE-2017-9039 [MEDIUM] CWE-770 CVE-2017-9039: GNU Binutils 2.28 allows remote attackers to cause a denial of service (memory consumption) via a cr GNU Binutils 2.28 allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file with many program headers, related to the get_program_headers function in readelf.c.
nvdosv
CVE-2017-15021P4MEDIUMCVSS 5.5v2.292017-10-05
CVE-2017-15021 [MEDIUM] CWE-125 CVE-2017-15021: bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as d bfd_get_debug_link_info_1 in opncls.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to bfd_getl32.
nvdosv
CVE-2018-8945P4MEDIUMCVSS 5.5v2.302018-03-22
CVE-2018-8945 [MEDIUM] CWE-20 CVE-2018-8945: The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd) The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (segmentation fault) via a large attribute section.
nvdosv
CVE-2017-15939P4MEDIUMCVSS 5.5v2.292017-10-27
CVE-2017-15939 [MEDIUM] CVE-2017-15939: dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2. dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file table, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename. NOTE: this issue is caused by an incomplete
nvdosv
CVE-2017-9044P4MEDIUMCVSS 5.5v2.282017-05-18
CVE-2017-9044 [MEDIUM] CWE-125 CVE-2017-9044: The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-04-12 allows remote The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-04-12 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted ELF file.
nvdosv
CVE-2017-14529P4MEDIUMCVSS 5.5v2.292017-09-18
CVE-2017-14529 [MEDIUM] CWE-125 CVE-2017-14529: The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), The pe_print_idata function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles HintName vector entries, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PE file, related to the bfd_getl16 function.
nvdosv
CVE-2017-13757P4MEDIUMCVSS 5.5v2.292017-08-29
CVE-2017-13757 [MEDIUM] CWE-125 CVE-2017-13757: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not validate the PLT section size, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to elf_i386_get_synthetic_symtab in elf32-i386.c and elf_x86_64_get_syntheti
nvdosv
CVE-2018-17360P4MEDIUMCVSS 5.5v2.31.12018-09-23
CVE-2018-17360 [MEDIUM] CWE-125 CVE-2018-17360: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer over-read in bfd_getl32 in libbfd.c allows an attacker to cause a denial of service through a crafted PE file. This vulnerability can be triggered by the executable objdump.
nvdosv
CVE-2018-17985P4MEDIUMCVSS 5.5v2.312018-10-04
CVE-2018-17985 [MEDIUM] CWE-400 CVE-2018-17985: An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Ther An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption problem caused by the cplus_demangle_type function making recursive calls to itself in certain scenarios involving many 'P' characters.
nvdosv
CVE-2018-9996P4MEDIUMCVSS 5.5v2.302018-04-10
CVE-2018-9996 [MEDIUM] CWE-674 CVE-2018-9996: An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.
nvd
CVE-2017-7299P4MEDIUMCVSS 5.5v2.282017-03-29
CVE-2017-7299 [MEDIUM] CWE-125 CVE-2017-7299: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an i The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit relocs (bfd_elf_final_link function in bfd/elflink.c) does not check the format of the input file before trying to read the ELF reloc section header. The vulnerability leads to a GNU linker (ld) program c
nvdosv
Gnu Binutils vulnerabilities | cvebase