cbcvebase.

Gnu Gdb vulnerabilities

12 known vulnerabilities affecting gnu/gdb.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM8

Vulnerabilities

Page 1 of 1
CVE-2014-9939P3CRITICALCVSS 9.8≥ 0, < 7.10-12017-03-21
CVE-2014-9939 [CRITICAL] CVE-2014-9939: ihex ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
osv
CVE-2019-1010180P3HIGHCVSS 7.8fixed in 9.1vAll versions (At least as of date 2018-09-16)2019-07-24
CVE-2019-1010180 [HIGH] CWE-125 CVE-2019-1010180: GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: De GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is: The main gdb module. The attack vector is: Open an ELF for debugging. The fixed version is: Not fixed yet.
nvd
CVE-2014-8501P3HIGHCVSS 7.5≥ 0, < 7.7.1-0ubuntu5~14.04.3≥ 0, < 7.11.1-0ubuntu1~16.52017-07-26
CVE-2014-8501 [HIGH] gdb vulnerabilities gdb vulnerabilities Hanno Böck discovered that gdb incorrectly handled certain malformed AOUT headers in PE executables. If a user or automated system were tricked into processing a specially crafted binary, a remote attacker could use this issue to cause gdb to crash, resulting in a denial of service, or possibly execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS. (CVE-2014-8501) It was discovered that gdb incorrectly handled printing
osv
CVE-2005-1705P4HIGHCVSS 7.2≤ 6.32005-05-24
CVE-2005-1705 [HIGH] CVE-2005-1705: gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.
nvdosv
CVE-2011-4355P4MEDIUMCVSS 6.9≤ 7.4.1v4.18+27 more2013-03-05
CVE-2011-4355 [MEDIUM] CWE-264 CVE-2011-4355: GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certa GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain privileges via crafted files such as Python scripts.
nvdosv
CVE-2006-4146P4MEDIUMCVSS 5.1v6.52006-08-31
CVE-2006-4146 [MEDIUM] CWE-119 CVE-2006-4146: Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU D Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU Debugger (GDB) 6.5 allows user-assisted attackers, or restricted users, to execute arbitrary code via a crafted file with a location block (DW_FORM_block) that contains a large number of operations.
nvdosv
CVE-2023-39128P4MEDIUMCVSS 5.5v13.0.50.20220805-git2023-07-25
CVE-2023-39128 [MEDIUM] CWE-787 CVE-2023-39128: GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_d GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_decode at /gdb/ada-lang.c.
nvd
CVE-2023-39129P4MEDIUMCVSS 5.5v13.0.50.20220805-git2023-07-25
CVE-2023-39129 [MEDIUM] CWE-416 CVE-2023-39129: GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym() at /gdb/coff-pe-read.c.
nvd
CVE-2023-39130P4MEDIUMCVSS 5.5v13.0.50.20220805-git2023-07-25
CVE-2023-39130 [MEDIUM] CWE-787 CVE-2023-39130: GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function pe_as16() at /gdb/coff-pe-read.c.
nvd
CVE-2017-9778P4MEDIUMCVSS 5.5≤ 8.02017-06-21
CVE-2017-9778 [MEDIUM] CWE-20 CVE-2017-9778: GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A mal GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file can cause GDB to repeatedly allocate memory until a process limit is reached. This can, for example, impede efforts to analyze malware with GDB.
nvdosv
CVE-2020-16599P4MEDIUMCVSS 5.5≥ 0, < 7.11.1-0ubuntu1~16.5+esm1≥ 0, < 8.1.1-0ubuntu1+esm1+2 more2024-06-20
CVE-2020-16599 [MEDIUM] gdb vulnerabilities gdb vulnerabilities It was discovered that gdb incorrectly handled certain memory operations when parsing an ELF file. An attacker could possibly use this issue to cause a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-4285) It was discovered that gdb incorrectly handled memory leading to a heap based buffer overflow. An attacker could use this issue to cause a
osv
CVE-2005-1704P4MEDIUMCVSS 4.6≤ 6.32005-05-24
CVE-2005-1704 [MEDIUM] CWE-189 CVE-2005-1704: Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow.
nvdosv
Gnu Gdb vulnerabilities | cvebase