cbcvebase.

Gnu Glibc vulnerabilities

169 known vulnerabilities affecting gnu/glibc.

Total CVEs
169
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH66MEDIUM70LOW9

Vulnerabilities

Page 5 of 9
CVE-2021-38604P3HIGHCVSS 7.5≤ 2.342021-08-12
CVE-2021-38604 [HIGH] CVE-2021-38604: In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandl In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix.
nvdosv
CVE-2019-9192P3HIGHCVSS 7.5≤ 2.292019-02-26
CVE-2019-9192 [HIGH] CVE-2019-9192: In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern
nvd
CVE-2025-4802P3HIGHCVSS 7.8≥ 2.27, ≤ 2.382025-05-16
CVE-2025-4802 [HIGH] CWE-426 CVE-2025-4802: Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2. Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
nvdosv
CVE-2015-1472P3HIGHCVSS 7.5≤ 2.202015-04-08
CVE-2015-1472 [HIGH] CWE-119 CVE-2015-1472: The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing wide characters that are improperly
nvdosv
CVE-2014-4043P3HIGHCVSS 7.5≤ 2.192014-10-06
CVE-2014-4043 [HIGH] CWE-94 CVE-2014-4043: The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument i The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
nvdosv
CVE-2016-6323P3HIGHCVSS 7.5≤ 2.242016-10-07
CVE-2016-6323 [HIGH] CWE-284 CVE-2016-6323: The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution con The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation.
nvdosv
CVE-2010-0015P3HIGHCVSS 7.5v2.7v2.10.22010-01-14
CVE-2010-0015 [HIGH] CWE-255 CVE-2010-0015: nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10 nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function.
nvdosv
CVE-2012-3406P3MEDIUMCVSS 6.8v2.5v2.122014-02-10
CVE-2012-3406 [MEDIUM] CVE-2012-3406: The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probabl The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (crash) or possi
nvdosv
CVE-2026-6238P3MEDIUMCVSS 6.5≥ 2.22026-04-28
CVE-2026-6238 [MEDIUM] CWE-126 CVE-2026-6238: The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitial
nvd
CVE-2016-5417P3HIGHCVSS 7.5≤ 2.232017-02-17
CVE-2016-5417 [HIGH] CWE-399 CVE-2016-5417: Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU Memory leak in the __res_vinit function in the IPv6 name server management code in libresolv in GNU C Library (aka glibc or libc6) before 2.24 allows remote attackers to cause a denial of service (memory consumption) by leveraging partial initialization of internal resolver data structures.
nvdosv
CVE-2002-0651P4HIGHCVSS 7.5≥ 0, < 2.2.5-82002-07-03
CVE-2002-0651 [HIGH] CVE-2002-0651: Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a de Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers.
osv
CVE-2023-4527P3MEDIUMCVSS 6.5≥ 2.36, < 2.36.113≥ 2.37, < 2.37.38+1 more2023-09-18
CVE-2023-4527 [MEDIUM] CWE-121 CVE-2023-4527: A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
nvdosv
CVE-2023-5156P4HIGHCVSS 7.5≥ 2.34, < 2.392023-09-25
CVE-2023-5156 [HIGH] CVE-2023-5156: A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
nvdosv
CVE-2019-6488P4HIGHCVSS 7.8≤ 2.282019-01-18
CVE-2019-6488 [HIGH] CWE-404 CVE-2019-6488: The string component in the GNU C Library (aka glibc or libc6) through 2.28, when running on the x32 The string component in the GNU C Library (aka glibc or libc6) through 2.28, when running on the x32 architecture, incorrectly attempts to use a 64-bit register for size_t in assembly codes, which can lead to a segmentation fault or possibly unspecified other impact, as demonstrated by a crash in __memmove_avx_unaligned_erms in sysdeps/x86_64/multiarch/
nvdosv
CVE-2009-5155P4HIGHCVSS 7.5fixed in 2.282019-02-26
CVE-2009-5155 [HIGH] CWE-19 CVE-2009-5155: In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses al In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
nvdosv
CVE-2013-4237P4MEDIUMCVSS 6.8≤ 2.18v2.0+25 more2013-10-09
CVE-2013-4237 [MEDIUM] CWE-119 CVE-2013-4237: sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context- sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted (1) NTFS or (2) CIFS image.
nvdosv
CVE-2014-0475P4MEDIUMCVSS 6.8≤ 2.19v2.0+27 more2014-07-29
CVE-2014-0475 [MEDIUM] CWE-22 CVE-2014-0475: Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow Multiple directory traversal vulnerabilities in GNU C Library (aka glibc or libc6) before 2.20 allow context-dependent attackers to bypass ForceCommand restrictions and possibly have other unspecified impact via a .. (dot dot) in a (1) LC_*, (2) LANG, or other locale environment variable.
nvdosv
CVE-2002-0684P4HIGHCVSS 7.5≤ 2.2.52002-08-12
CVE-2002-0684 [HIGH] CVE-2002-0684: Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as use Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.
nvdosv
CVE-2008-1367P4HIGHCVSS 7.5≥ 0, < 2.7-82008-03-17
CVE-2008-1367 [HIGH] CVE-2008-1367: gcc 4 gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, which can prevent the direction flag (DF) from being reset in violation of ABI conventions and cause data to be copied in the wrong direction during signal handling in the Linux kernel, which might allow context-dependent attackers to trigger memory corruption. NOTE: this issue was originally reported for CPU co
osv
CVE-2012-0864P4MEDIUMCVSS 6.8v2.142013-05-02
CVE-2012-0864 [MEDIUM] CWE-189 CVE-2012-0864: Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other version Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory via a large number of arguments.
nvd
Gnu Glibc vulnerabilities | cvebase