cbcvebase.

Gnu Binutils vulnerabilities

286 known vulnerabilities affecting gnu/binutils.

Total CVEs
286
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH121MEDIUM150LOW10

Vulnerabilities

Page 2 of 15
CVE-2017-6969P3CRITICALCVSS 9.1v2.282017-03-17
CVE-2017-6969 [CRITICAL] CWE-125 CVE-2017-6969: readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.
nvdosv
CVE-2025-7546P3HIGHCVSS 7.8v2.452025-07-13
CVE-2025-7546 [HIGH] CWE-119 CVE-2025-7546: A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of
nvdosv
CVE-2018-12699P3CRITICALCVSS 9.8v2.302018-06-23
CVE-2018-12699 [CRITICAL] CWE-787 CVE-2018-12699: finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-base finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
nvdosv
CVE-2024-53589P3HIGHCVSS 8.4≥ 0, < 2.44-12024-12-05
CVE-2024-53589 [HIGH] CVE-2024-53589: GNU objdump 2 GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.
osv
CVE-2025-1179P3HIGHCVSS 7.5v2.432025-02-11
CVE-2025-1179 [HIGH] CWE-119 CVE-2025-1179: A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issu A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit
nvdosv
CVE-2025-5245P3HIGHCVSS 7.8fixed in 2.45v2.0+44 more2025-05-27
CVE-2025-5245 [HIGH] CWE-119 CVE-2025-5245: A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the f A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended
nvdosv
CVE-2025-69650P3HIGHCVSS 7.5≤ 2.462026-03-06
CVE-2025-69650 [HIGH] CWE-415 CVE-2025-69650: GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF bi GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), lead
nvd
CVE-2017-7226P3CRITICALCVSS 9.1v2.282017-03-22
CVE-2017-7226 [CRITICAL] CWE-125 CVE-2017-7226: The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distribute The pe_ILF_object_p function in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a heap-based buffer over-read of size 4049 because it uses the strlen function instead of strnlen, leading to program crashes in several utilities such as addr2line, size, and strings. It could lead to informat
nvdosv
CVE-2017-7614P3CRITICALCVSS 9.8v2.282017-04-09
CVE-2017-7614 [CRITICAL] CWE-476 CVE-2017-7614: elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2 elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an "int main() {return 0;}" program.
nvdosv
CVE-2018-12698P3HIGHCVSS 7.5v2.302018-06-23
CVE-2018-12698 [HIGH] CVE-2018-12698: demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attac demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.
nvdosv
CVE-2014-8504P3HIGHCVSS 7.5≤ 2.242014-12-09
CVE-2014-8504 [HIGH] CWE-119 CVE-2014-8504: Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.
nvdosv
CVE-2014-8503P3HIGHCVSS 7.5≤ 2.242014-12-09
CVE-2014-8503 [HIGH] CWE-119 CVE-2014-8503: Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.
nvdosv
CVE-2019-1010180P3HIGHCVSS 7.8≥ 0, < 2.32.51.20190707-12019-07-24
CVE-2019-1010180 [HIGH] CVE-2019-1010180: GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is: The main gdb module. The attack vector is: Open an ELF for debugging. The fixed version is: Not fixed yet.
osv
CVE-2026-6846P3HIGHCVSS 7.8≤ 2.462026-04-22
CVE-2026-6846 [HIGH] CWE-122 CVE-2026-6846: A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a speciall A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or
nvd
CVE-2020-35342P3HIGHCVSS 7.5fixed in 2.342023-08-22
CVE-2020-35342 [HIGH] CWE-665 CVE-2020-35342: GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak.
nvdosv
CVE-2025-69649P3HIGHCVSS 7.5≤ 2.462026-03-06
CVE-2025-69649 [HIGH] CWE-476 CVE-2025-69649: GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a c GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corrupti
nvd
CVE-2021-3530P3HIGHCVSS 7.5v2.36vGNU Binutils version before and including 2.362021-06-02
CVE-2021-3530 [HIGH] CWE-674 CVE-2021-3530: A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in A flaw was discovered in GNU libiberty within demangle_path() in rust-demangle.c, as distributed in GNU Binutils version 2.36. A crafted symbol can cause stack memory to be exhausted leading to a crash.
nvdosv
CVE-2018-1000876P3HIGHCVSS 7.8fixed in 2.322018-12-20
CVE-2018-1000876 [HIGH] CWE-190 CVE-2018-1000876: binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dyna binutils version 2.32 and earlier contains a Integer Overflow vulnerability in objdump, bfd_get_dynamic_reloc_upper_bound,bfd_canonicalize_dynamic_reloc that can result in Integer overflow trigger heap overflow. Successful exploitation allows execution of arbitrary code.. This attack appear to be exploitable via Local. This vulnerability appears t
nvdosv
CVE-2014-8502P3HIGHCVSS 7.5≤ 2.242014-12-09
CVE-2014-8502 [HIGH] CWE-119 CVE-2014-8502: Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a truncated export table in a PE file.
nvdosv
CVE-2016-6131P3HIGHCVSS 7.5≥ 0, < 2.27.51.20161102-12017-02-07
CVE-2016-6131 [HIGH] CVE-2016-6131: The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the refe The demangler in GNU Libiberty allows remote attackers to cause a denial of service (infinite loop, stack overflow, and crash) via a cycle in the references of remembered mangled types.
osv
Gnu Binutils vulnerabilities | cvebase