cbcvebase.

Gnu Glibc vulnerabilities

169 known vulnerabilities affecting gnu/glibc.

Total CVEs
169
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH66MEDIUM70LOW9

Vulnerabilities

Page 1 of 9
CVE-2023-4911P1HIGHCVSS 7.8KEVPoCRansomware≥ 2.34, < 2.392023-10-03
CVE-2023-4911 [HIGH] CWE-122 CVE-2023-4911: A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GL A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launching binaries with SUID permission to execute code with elevated privileges.
nvdosv
CVE-2015-7547P1HIGHCVSS 8.1ExploitedPoCv2.9v2.10+19 more2016-02-18
CVE-2015-7547 [HIGH] CWE-119 CVE-2015-7547: Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or A
nvdosv
CVE-2024-2961P1HIGHCVSS 7.3ExploitedPoC≥ 2.1.93, < 2.402024-04-17
CVE-2024-2961 [HIGH] CWE-787 CVE-2024-2961: The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer pas The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
nvdosv
CVE-2018-1000001P2HIGHCVSS 7.8ExploitedPoC≤ 2.262018-01-31
CVE-2018-1000001 [HIGH] CWE-787 CVE-2018-1000001: In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be use In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.
nvdosv
CVE-2015-0235P2CRITICALCVSS 10.0PoC≥ 2.0, < 2.182015-01-28
CVE-2015-0235 [CRITICAL] CWE-787 CVE-2015-0235: Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x ve Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
nvdosv
CVE-2014-5119P3HIGHCVSS 7.5PoCfixed in 2.202014-08-29
CVE-2014-5119 [HIGH] CWE-189 CVE-2014-5119: Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.
nvdosv
CVE-2008-1391P3HIGHCVSS 7.5PoC≥ 0, < 2.11-12008-03-27
CVE-2008-1391 [HIGH] CVE-2008-1391: Multiple integer overflows in libc in NetBSD 4 Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.
osv
CVE-2012-4412P3HIGHCVSS 7.5PoC≤ 2.17v2.0+24 more2013-10-09
CVE-2012-4412 [HIGH] CWE-189 CVE-2012-4412: Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier al Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a heap-based buffer overflow.
nvdosv
CVE-2023-6246P3HIGHCVSS 7.8PoC≥ 2.36, < 2.392024-01-31
CVE-2023-6246 [HIGH] CWE-122 CVE-2023-6246: A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or called with the ident argument set to NULL, and the program name (the basename of argv[0]) is bigger than 1024 bytes, resulting in an a
nvdosv
CVE-2010-4052P3MEDIUMCVSS 5.0PoCv1.00v1.01+26 more2011-01-13
CVE-2010-4052 [MEDIUM] CWE-399 CVE-2010-4052: Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or lib Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by a {10,}{10,}{10,}{10,} sequence in
nvdosv
CVE-2011-2702P3MEDIUMCVSS 6.8PoC≤ 2.12.2v2.12+1 more2014-10-27
CVE-2011-2702 [MEDIUM] CWE-94 CVE-2011-2702: Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Stream Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allows context-dependent attackers to execute arbitrary code via a negative length parameter to (1) memcpy-ssse3-rep.S, (2) memcpy-ssse3.S, or (3) memset-sse2.S in sysdeps/i386/i686/multiarch/, which triggers a
nvd
CVE-2010-3847P3MEDIUMCVSS 6.9PoC≤ 2.11.2v1.00+53 more2011-01-07
CVE-2010-3847 [MEDIUM] CWE-59 CVE-2010-3847: elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory.
nvdosv
CVE-2017-1000366P3HIGHCVSS 7.8PoC≤ 2.252017-06-19
CVE-2017-1000366 [HIGH] CWE-119 CVE-2017-1000366: glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate th glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these issues are not directly exploita
nvdosv
CVE-2010-4051P3MEDIUMCVSS 5.0PoCv1.00v1.01+26 more2011-01-13
CVE-2010-4051 [MEDIUM] CVE-2010-4051: The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x thro The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (application crash) via a regular expression containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation, as demonstrated by a {10,}{10,}{10,}{10,}{10,} seque
nvdosv
CVE-2016-2856P3HIGHCVSS 8.4PoC≥ 0, < 2.21-12016-03-14
CVE-2016-2856 [HIGH] CVE-2016-2856: pt_chown in the glibc package before 2 pt_chown in the glibc package before 2.19-18+deb8u4 on Debian jessie; the elibc package before 2.15-0ubuntu10.14 on Ubuntu 12.04 LTS and before 2.19-0ubuntu6.8 on Ubuntu 14.04 LTS; and the glibc package before 2.21-0ubuntu4.2 on Ubuntu 15.10 and before 2.23-0ubuntu1 on Ubuntu 16.04 LTS and 16.10 lacks a namespace check associated with file-descriptor passing, which allows local users to capture keystrokes and spoof data,
osv
CVE-2010-3856P3HIGHCVSS 7.2PoC≤ 2.11.2v1.00+53 more2011-01-07
CVE-2010-3856 [HIGH] CWE-264 CVE-2010-3856: ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not pr ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library directory, as demonstrated by libpcp
nvdosv
CVE-2011-1071P3MEDIUMCVSS 5.1PoC≤ 2.12.1v1.00+54 more2011-04-08
CVE-2011-1071 [MEDIUM] CWE-399 CVE-2011-1071: The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-depen The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898, CVE-2010-1917, and CVE-2007-4782, as ori
nvdosv
CVE-2017-1000408P3HIGHCVSS 7.8PoCv2.1.12018-02-01
CVE-2017-1000408 [HIGH] CVE-2017-1000408: A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_ A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366.
nvdosv
CVE-2009-5029P3MEDIUMCVSS 6.8PoC≤ 2.14v2.0+13 more2013-05-02
CVE-2009-5029 [MEDIUM] CWE-189 CVE-2009-5029: Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attacke Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.
nvdosv
CVE-2013-4788P3MEDIUMCVSS 5.1PoC≤ 2.17v2.0+25 more2013-10-04
CVE-2013-4788 [MEDIUM] CWE-20 CVE-2013-4788: The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control execution flow by leveraging a buffer-overflow vulnerability in an application and using the known zero va
nvdosv
Gnu Glibc vulnerabilities | cvebase