Gnu Glibc vulnerabilities
169 known vulnerabilities affecting gnu/glibc.
Total CVEs
169
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH66MEDIUM70LOW9
Vulnerabilities
Page 6 of 9
CVE-2020-1751P4HIGHCVSS 7.0fixed in 2.312020-04-17
CVE-2020-1751 [HIGH] CWE-787 CVE-2020-1751: An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
nvdosv
CVE-2020-1752P4HIGHCVSS 7.0fixed in 2.32.02020-04-30
CVE-2020-1752 [HIGH] CWE-416 CVE-2020-1752: A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the ti
A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that, when processed by the glob function, w
nvdosv
CVE-2010-0830P4MEDIUMCVSS 5.1v2.0.1v2.0.2+36 more2010-06-01
CVE-2010-0830 [MEDIUM] CWE-189 CVE-2010-0830: Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the
Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through 2.11.1, when the --verify option is used, allows user-assisted remote attackers to execute arbitrary code via a crafted ELF program with a negative value for a certain d_tag structure member in the ELF hea
nvdosv
CVE-2016-4429P4MEDIUMCVSS 5.9fixed in 2.242016-06-10
CVE-2016-4429 [MEDIUM] CWE-787 CVE-2016-4429: Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (
Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets.
nvdosv
CVE-2010-0296P4HIGHCVSS 7.2≤ 2.11.1v2.0+37 more2010-06-01
CVE-2010-0296 [HIGH] CWE-20 CVE-2010-0296: The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlie
The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain privileges, via a crafted mount reque
nvdosv
CVE-2017-12133P4MEDIUMCVSS 5.9≤ 2.252017-09-07
CVE-2017-12133 [MEDIUM] CWE-416 CVE-2017-12133: Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library
Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path.
nvdosv
CVE-2023-6780P4MEDIUMCVSS 5.3≥ 2.37, < 2.392024-01-31
CVE-2023-6780 [MEDIUM] CWE-131 CVE-2023-6780: An integer overflow was found in the __vsyslog_internal function of the glibc library. This function
An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long message, leading to an incorrect calculation of the buffer size to store the message, resulting in undefined behavior. This issue affects
nvdosv
CVE-2019-25013P4MEDIUMCVSS 5.9≤ 2.322021-01-04
CVE-2019-25013 [MEDIUM] CWE-125 CVE-2019-25013: The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid mu
The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.
nvdosv
CVE-2015-1473P4MEDIUMCVSS 6.4≤ 2.202015-04-08
CVE-2015-1473 [MEDIUM] CWE-119 CVE-2015-1473: The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite memory locations beyond the stack boun
nvdosv
CVE-2024-33600P4MEDIUMCVSS 5.9≥ 2.15, < 2.402024-05-06
CVE-2024-33600 [MEDIUM] CWE-476 CVE-2024-33600: nscd: Null pointer crashes after notfound response If the Name Service Cache Daemon's (nscd) cache
nscd: Null pointer crashes after notfound response
If the Name Service Cache Daemon's (nscd) cache fails to add a not-found
netgroup response to the cache, the client request can result in a null
pointer dereference. This flaw was introduced in glibc 2.15 when the
cache was added to nscd.
This vulnerability is only present in the nscd binary.
nvdosv
CVE-2016-10228P4MEDIUMCVSS 5.9≤ 2.252017-03-02
CVE-2016-10228 [MEDIUM] CWE-20 CVE-2016-10228: The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with mult
The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.
nvdosv
CVE-2015-5277P4HIGHCVSS 7.2≤ 2.192015-12-17
CVE-2015-5277 [HIGH] CWE-119 CVE-2015-5277: The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library
The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.
nvdosv
CVE-2013-7423P4MEDIUMCVSS 5.0fixed in 2.202015-02-24
CVE-2013-7423 [MEDIUM] CWE-17 CVE-2013-7423: The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not
The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.
nvdosv
CVE-2023-4813P4MEDIUMCVSS 5.9fixed in 2.362023-09-12
CVE-2023-4813 [MEDIUM] CWE-416 CVE-2023-4813: A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory
A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
nvdosv
CVE-2023-4806P4MEDIUMCVSS 5.9v2.332023-09-18
CVE-2023-4806 [MEDIUM] CWE-416 CVE-2023-4806: A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may ac
A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The r
nvdosv
CVE-2025-5702P4MEDIUMCVSS 5.6≥ 2.39, < 2.39-209≥ 2.40, < 2.40-139+1 more2025-06-05
CVE-2025-5702 [MEDIUM] CWE-665 CVE-2025-5702: The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and
The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the call
nvdosv
CVE-2025-5745P4MEDIUMCVSS 5.6≥ 2.40, < 2.40-136≥ 2.41, < 2.41-572025-06-05
CVE-2025-5745 [MEDIUM] CWE-665 CVE-2025-5745: The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and
The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and potentially altering control flow of the ca
nvdosv
CVE-2014-8121P4MEDIUMCVSS 5.0≤ 2.212015-03-27
CVE-2014-8121 [MEDIUM] CWE-17 CVE-2014-8121: DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or l
DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up on a database while iterating over it, which triggers the file pointer to be reset.
nvdosv
CVE-2013-4458P4MEDIUMCVSS 5.0≤ 2.18v2.0+25 more2013-12-12
CVE-2013-4458 [MEDIUM] CWE-119 CVE-2013-4458: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Libr
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of AF_INET6 address results. NOTE: this vulnerability exists because of an incomplet
nvdosv
CVE-2017-12132P4MEDIUMCVSS 5.9≤ 2.252017-08-01
CVE-2017-12132 [MEDIUM] CWE-770 CVE-2017-12132: The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS suppo
The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation.
nvdosv