cbcvebase.

Gnu Binutils vulnerabilities

286 known vulnerabilities affecting gnu/binutils.

Total CVEs
286
CISA KEV
0
Public exploits
12
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH121MEDIUM150LOW10

Vulnerabilities

Page 6 of 15
CVE-2017-9745P4HIGHCVSS 7.8v2.282017-06-19
CVE-2017-9745 [HIGH] CWE-119 CVE-2017-9745: The _bfd_vms_slurp_etir function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka The _bfd_vms_slurp_etir function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file du
nvdosv
CVE-2018-7208P4HIGHCVSS 7.8v2.302018-02-18
CVE-2018-7208 [HIGH] CWE-20 CVE-2018-7208: In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka li In the coff_pointerize_aux function in coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, an index is not validated, which allows remote attackers to cause a denial of service (segmentation fault) or possibly have unspecified other impact via a crafted file, as demonstrated by objcopy of a COFF object
nvdosv
CVE-2017-16827P4HIGHCVSS 7.8v2.29.12017-11-15
CVE-2017-16827 [HIGH] CWE-119 CVE-2017-16827: The aout_get_external_symbols function in aoutx.h in the Binary File Descriptor (BFD) library (aka l The aout_get_external_symbols function in aoutx.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (slurp_symtab invalid free and application crash) or possibly have unspecified other impact via a crafted ELF file.
nvdosv
CVE-2017-17121P4HIGHCVSS 7.8v2.29.12017-12-04
CVE-2017-17121 [HIGH] CWE-119 CVE-2017-17121: The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (memory access violation) or possibly have unspecified other impact via a COFF binary in which a relocation refers to a location after the end of the to-be-relocated section.
nvdosv
CVE-2017-12458P4HIGHCVSS 7.8≤ 2.292017-08-04
CVE-2017-12458 [HIGH] CWE-125 CVE-2017-12458: The nlm_swap_auxiliary_headers_in function in bfd/nlmcode.h in the Binary File Descriptor (BFD) libr The nlm_swap_auxiliary_headers_in function in bfd/nlmcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted nlm file.
nvdosv
CVE-2017-12455P4HIGHCVSS 7.8≤ 2.292017-08-04
CVE-2017-12455 [HIGH] CWE-125 CVE-2017-12455: The evax_bfd_print_emh function in vms-alpha.c in the Binary File Descriptor (BFD) library (aka libb The evax_bfd_print_emh function in vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha file.
nvdosv
CVE-2017-12453P4HIGHCVSS 7.8≤ 2.292017-08-04
CVE-2017-12453 [HIGH] CWE-125 CVE-2017-12453: The _bfd_vms_slurp_eeom function in libbfd.c in the Binary File Descriptor (BFD) library (aka libbfd The _bfd_vms_slurp_eeom function in libbfd.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms alpha file.
nvdosv
CVE-2017-12451P4HIGHCVSS 7.8≤ 2.292017-08-04
CVE-2017-12451 [HIGH] CWE-125 CVE-2017-12451: The _bfd_xcoff_read_ar_hdr function in bfd/coff-rs6000.c and bfd/coff64-rs6000.c in the Binary File The _bfd_xcoff_read_ar_hdr function in bfd/coff-rs6000.c and bfd/coff64-rs6000.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds stack read via a crafted COFF image file.
nvdosv
CVE-2017-12452P4HIGHCVSS 7.8≤ 2.292017-08-04
CVE-2017-12452 [HIGH] CWE-125 CVE-2017-12452: The bfd_mach_o_i386_canonicalize_one_reloc function in bfd/mach-o-i386.c in the Binary File Descript The bfd_mach_o_i386_canonicalize_one_reloc function in bfd/mach-o-i386.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted mach-o file.
nvdosv
CVE-2017-12457P4HIGHCVSS 7.8≤ 2.292017-08-04
CVE-2017-12457 [HIGH] CWE-476 CVE-2017-12457: The bfd_make_section_with_flags function in section.c in the Binary File Descriptor (BFD) library (a The bfd_make_section_with_flags function in section.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause a NULL dereference via a crafted file.
nvdosv
CVE-2025-1153P4MEDIUMCVSS 5.9v2.43v2.442025-02-10
CVE-2025-1153 [MEDIUM] CWE-119 CVE-2025-1153: A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vuln A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2
nvdosv
CVE-2018-7643P4HIGHCVSS 7.8v2.302018-03-02
CVE-2018-7643 [HIGH] CWE-190 CVE-2018-7643: The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a The display_debug_ranges function in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (integer overflow and application crash) or possibly have unspecified other impact via a crafted ELF file, as demonstrated by objdump.
nvdosv
CVE-2018-6543P4HIGHCVSS 7.8v2.302018-02-02
CVE-2018-6543 [HIGH] CWE-190 CVE-2018-6543: In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in o In GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()` with 0 size. A crafted ELF file allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvdosv
CVE-2017-16830P4HIGHCVSS 7.8v2.29.12017-11-15
CVE-2017-16830 [HIGH] CWE-190 CVE-2017-16830: The print_gnu_property_note function in readelf.c in GNU Binutils 2.29.1 does not have integer-overf The print_gnu_property_note function in readelf.c in GNU Binutils 2.29.1 does not have integer-overflow protection on 32-bit platforms, which allows remote attackers to cause a denial of service (segmentation violation and application crash) or possibly have unspecified other impact via a crafted ELF file.
nvdosv
CVE-2017-9043P4HIGHCVSS 7.8v2.282017-05-18
CVE-2017-9043 [HIGH] CWE-20 CVE-2017-9043: readelf.c in GNU Binutils 2017-04-12 has a "shift exponent too large for type unsigned long" issue, readelf.c in GNU Binutils 2017-04-12 has a "shift exponent too large for type unsigned long" issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file.
nvdosv
CVE-2017-16831P4HIGHCVSS 7.8v2.29.12017-11-15
CVE-2017-16831 [HIGH] CWE-190 CVE-2017-16831: coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2 coffgen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, does not validate the symbol count, which allows remote attackers to cause a denial of service (integer overflow and application crash, or excessive memory allocation) or possibly have unspecified other impact via a crafted PE file.
nvdosv
CVE-2017-16826P4HIGHCVSS 7.8v2.29.12017-11-15
CVE-2017-16826 [HIGH] CWE-119 CVE-2017-16826: The coff_slurp_line_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka li The coff_slurp_line_table function in coffcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted PE file.
nvdosv
CVE-2017-17126P4HIGHCVSS 7.8v2.29.12017-12-04
CVE-2017-17126 [HIGH] CWE-119 CVE-2017-17126: The load_debug_section function in readelf.c in GNU Binutils 2.29.1 allows remote attackers to cause The load_debug_section function in readelf.c in GNU Binutils 2.29.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via an ELF file that lacks section headers.
nvdosv
CVE-2017-12456P4HIGHCVSS 7.8≤ 2.292017-08-04
CVE-2017-12456 [HIGH] CWE-125 CVE-2017-12456: The read_symbol_stabs_debugging_info function in rddbg.c in GNU Binutils 2.29 and earlier allows rem The read_symbol_stabs_debugging_info function in rddbg.c in GNU Binutils 2.29 and earlier allows remote attackers to cause an out of bounds heap read via a crafted binary file.
nvdosv
CVE-2017-12449P4HIGHCVSS 7.8≤ 2.292017-08-04
CVE-2017-12449 [HIGH] CWE-125 CVE-2017-12449: The _bfd_vms_save_sized_string function in vms-misc.c in the Binary File Descriptor (BFD) library (a The _bfd_vms_save_sized_string function in vms-misc.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29 and earlier, allows remote attackers to cause an out of bounds heap read via a crafted vms file.
nvdosv
Gnu Binutils vulnerabilities | cvebase