cbcvebase.

Gnu Binutils vulnerabilities

286 known vulnerabilities affecting gnu/binutils.

Total CVEs
286
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH121MEDIUM150LOW10

Vulnerabilities

Page 3 of 15
CVE-2019-9077P3HIGHCVSS 7.8v2.322019-02-24
CVE-2019-9077 [HIGH] CWE-787 CVE-2019-9077: An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_spe An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option section.
nvdosv
CVE-2018-12697P3HIGHCVSS 7.5v2.302018-06-23
CVE-2018-12697 [HIGH] CWE-476 CVE-2018-12697: A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.
nvdosv
CVE-2014-8501P3HIGHCVSS 7.5≤ 2.242014-12-09
CVE-2014-8501 [HIGH] CWE-119 CVE-2014-8501: The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remo The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
nvdosv
CVE-2018-20657P3HIGHCVSS 7.5v2.31.12019-01-02
CVE-2018-20657 [HIGH] CVE-2018-20657: The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, has a memory leak via a crafted string, leading to a denial of service (memory consumption), as demonstrated by cxxfilt, a related issue to CVE-2018-12698.
nvd
CVE-2020-19726P3HIGHCVSS 8.8v2.362023-08-22
CVE-2020-19726 [HIGH] CWE-400 CVE-2020-19726: An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attac An issue was discovered in binutils libbfd.c 2.36 relating to the auxiliary symbol data allows attackers to read or write to system memory or cause a denial of service.
nvdosv
CVE-2018-12934P3HIGHCVSS 7.5v2.302018-06-28
CVE-2018-12934 [HIGH] CWE-770 CVE-2018-12934: remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attacker remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt.
nvdosv
CVE-2017-12448P3HIGHCVSS 7.8≤ 2.292017-08-04
CVE-2017-12448 [HIGH] CWE-416 CVE-2017-12448: The bfd_cache_close function in bfd/cache.c in the Binary File Descriptor (BFD) library (aka libbfd) The bfd_cache_close function in bfd/cache.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a heap use after free and possibly achieve code execution via a crafted nested archive file. This issue occurs because incorrect functions are called during an attempt t
nvdosv
CVE-2017-12459P3HIGHCVSS 7.8≤ 2.292017-08-04
CVE-2017-12459 [HIGH] CWE-787 CVE-2017-12459: The bfd_mach_o_read_symtab_strtab function in bfd/mach-o.c in the Binary File Descriptor (BFD) libra The bfd_mach_o_read_symtab_strtab function in bfd/mach-o.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted mach-o file.
nvdosv
CVE-2017-12450P3HIGHCVSS 7.8≤ 2.292017-08-04
CVE-2017-12450 [HIGH] CWE-787 CVE-2017-12450: The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka The alpha_vms_object_p function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap write and possibly achieve code execution via a crafted vms alpha file.
nvdosv
CVE-2017-7227P3HIGHCVSS 7.5v2.282017-03-22
CVE-2017-7227 [HIGH] CWE-119 CVE-2017-7227: GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing GNU linker (ld) in GNU Binutils 2.28 is vulnerable to a heap-based buffer overflow while processing a bogus input script, leading to a program crash. This relates to lack of '\0' termination of a name field in ldlex.l.
nvdosv
CVE-2019-9075P3HIGHCVSS 7.8v2.322019-02-24
CVE-2019-9075 [HIGH] CWE-787 CVE-2019-9075: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is a heap-based buffer overflow in _bfd_archive_64_bit_slurp_armap in archive64.c.
nvdosv
CVE-2018-19931P3HIGHCVSS 7.8≤ 2.312018-12-07
CVE-2018-19931 [HIGH] CWE-787 CVE-2018-19931: An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils through 2.31. There is a heap-based buffer overflow in bfd_elf32_swap_phdr_in in elfcode.h because the number of program headers is not restricted.
nvdosv
CVE-2017-7304P3HIGHCVSS 7.5v2.282017-03-29
CVE-2017-7304 [HIGH] CWE-125 CVE-2017-7304: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulne The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 8) because of missing a check (in the copy_special_section_fields function) for an invalid sh_link field before attempting to follow it. This vulnerability causes Binutils utilities like strip to crash.
nvdosv
CVE-2017-8397P3HIGHCVSS 7.5v2.282017-05-01
CVE-2017-8397 [HIGH] CWE-119 CVE-2017-8397: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulne The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 and an invalid write of size 1 during processing of a corrupt binary containing reloc(s) with negative addresses. This vulnerability causes programs that conduct an analysis of binary programs using the libbfd library, s
nvdosv
CVE-2021-46174P3HIGHCVSS 7.5fixed in 2.382023-08-22
CVE-2021-46174 [HIGH] CWE-787 CVE-2021-46174: Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37. Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37.
nvdosv
CVE-2017-17124P3HIGHCVSS 7.8v2.29.12017-12-04
CVE-2017-17124 [HIGH] CWE-119 CVE-2017-17124: The _bfd_coff_read_string_table function in coffgen.c in the Binary File Descriptor (BFD) library (a The _bfd_coff_read_string_table function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not properly validate the size of the external string table, which allows remote attackers to cause a denial of service (excessive memory consumption, or heap-based buffer overflow and application
nvdosv
CVE-2017-7302P3HIGHCVSS 7.5v2.282017-03-29
CVE-2017-7302 [HIGH] CWE-125 CVE-2017-7302: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a sw The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a swap_std_reloc_out function in bfd/aoutx.h that is vulnerable to an invalid read (of size 4) because of missing checks for relocs that could not be recognised. This vulnerability causes Binutils utilities like strip to crash.
nvdosv
CVE-2017-7300P3HIGHCVSS 7.5v2.282017-03-29
CVE-2017-7300 [HIGH] CWE-125 CVE-2017-7300: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an a The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that is vulnerable to a heap-based buffer over-read (off-by-one) because of an incomplete check for invalid string offsets while loading symbols, leading to a GNU linker (ld) program crash.
nvdosv
CVE-2017-7303P3HIGHCVSS 7.5v2.282017-03-29
CVE-2017-7303 [HIGH] CWE-125 CVE-2017-7303: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulne The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 4) because of missing a check (in the find_link function) for null headers before attempting to match them. This vulnerability causes Binutils utilities like strip to crash.
nvdosv
CVE-2017-8393P3HIGHCVSS 7.5v2.282017-05-01
CVE-2017-8393 [HIGH] CWE-125 CVE-2017-8393: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulne The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to a global buffer over-read error because of an assumption made by code that runs for objcopy and strip, that SHT_REL/SHR_RELA sections are always named starting with a .rel/.rela prefix. This vulnerability causes programs that conduct an analysis
nvdosv
Gnu Binutils vulnerabilities | cvebase