Gnu Glibc vulnerabilities
169 known vulnerabilities affecting gnu/glibc.
Total CVEs
169
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH66MEDIUM70LOW9
Vulnerabilities
Page 7 of 9
CVE-2013-1914P4MEDIUMCVSS 5.0≤ 2.17v2.0.1+34 more2013-04-29
CVE-2013-1914 [MEDIUM] CWE-119 CVE-2013-1914: Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Libr
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.17 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of domain conversion results.
nvdosv
CVE-2022-39046P4MEDIUMCVSS 5.3v2.362022-08-31
CVE-2022-39046 [MEDIUM] CWE-532 CVE-2022-39046: An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a craf
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.
nvdosv
CVE-2014-7817P4MEDIUMCVSS 4.6v2.212014-11-24
CVE-2014-7817 [MEDIUM] CWE-20 CVE-2014-7817: The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which a
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
nvdosv
CVE-2009-5064P4MEDIUMCVSS 6.9≤ 2.1.3v1.00+21 more2011-03-30
CVE-2009-5064 [MEDIUM] CWE-264 CVE-2009-5064: ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges
ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states "This is just nonsense. There are a gazillion other ways to introduce code if people are downloadi
nvdosv
CVE-2012-4424P4MEDIUMCVSS 5.1≤ 2.17v2.0+24 more2013-10-09
CVE-2012-4424 [MEDIUM] CWE-119 CVE-2012-4424: Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and
Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string that triggers a malloc failure and use of the alloca function.
nvdosv
CVE-2013-7424P4MEDIUMCVSS 5.1≤ 2.14.12015-08-26
CVE-2013-7424 [MEDIUM] CWE-17 CVE-2013-7424: The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used
The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.
nvdosv
CVE-2003-0689P4HIGHCVSS 7.5≥ 0, < 2.2.52003-10-20
CVE-2003-0689 [HIGH] CVE-2003-0689: The getgrouplist function in GNU libc (glibc) 2
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.
osv
CVE-2014-6040P4MEDIUMCVSS 5.0≤ 2.19v2.0+27 more2014-12-05
CVE-2014-6040 [MEDIUM] CWE-119 CVE-2014-6040: GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of servic
GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte character value of "0xffff" to the iconv function when converting (1) IBM933, (2) IBM935, (3) IBM937, (4) IBM939, or (5) IBM1364 encoded data to UTF-8.
nvdosv
CVE-2007-3508P4HIGHCVSS 7.2≥ 0, < 2.6-22007-07-03
CVE-2007-3508 [HIGH] CVE-2007-3508: Integer overflow in the process_envvars function in elf/rtld
Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution
osv
CVE-2012-3404P4MEDIUMCVSS 5.0v2.122014-02-10
CVE-2012-3404 [MEDIUM] CWE-189 CVE-2012-3404: The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (stack corruption and crash) via a format string that uses posi
nvdosv
CVE-2012-3405P4MEDIUMCVSS 5.0v2.142014-02-10
CVE-2012-3405 [MEDIUM] CVE-2012-3405: The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other
The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (segmentation fault and crash) via a format string with a large number
nvdosv
CVE-2016-10739P4MEDIUMCVSS 5.3≤ 2.282019-01-21
CVE-2016-10739 [MEDIUM] CWE-20 CVE-2016-10739: In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded HTTP headers or other potentially d
nvdosv
CVE-2026-3904P4MEDIUMCVSS 6.2≥ 2.35, < 2.372026-03-11
CVE-2026-3904 [MEDIUM] CWE-366 CVE-2026-3904: Calling NSS-backed functions that support caching via nscd may call the nscd client side code and i
Calling NSS-backed functions that support caching via nscd may call the
nscd client side code and in the GNU C Library version 2.36 under high
load on x86_64 systems, the client may call memcmp on inputs that are
concurrently modified by other processes or threads and crash.
The nscd client in the GNU C Library uses the memcmp function with
inputs th
nvdosv
CVE-2017-15671P4MEDIUMCVSS 5.9≤ 2.262017-10-20
CVE-2017-15671 [MEDIUM] CWE-772 CVE-2017-15671: The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with
The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak).
nvdosv
CVE-2011-1095P4MEDIUMCVSS 6.2≤ 2.12.2v1.00+55 more2011-04-10
CVE-2011-1095 [MEDIUM] CWE-264 CVE-2011-1095: locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not qu
locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function.
nvdosv
CVE-2012-6656P4MEDIUMCVSS 5.0≤ 2.162014-12-05
CVE-2012-6656 [MEDIUM] CWE-20 CVE-2012-6656: iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to ca
iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when converting IBM930 encoded data to UTF-8.
nvdosv
CVE-2025-0395P4MEDIUMCVSS 6.2≥ 0, < 2.31-13+deb11u12≥ 0, < 2.36-9+deb12u10+1 more2025-01-22
CVE-2025-0395 [MEDIUM] CVE-2025-0395: When the assert() function in the GNU C Library versions 2
When the assert() function in the GNU C Library versions 2.13 to 2.40 fails, it does not allocate enough space for the assertion failure message string and size information, which may lead to a buffer overflow if the message string size aligns to page size.
osv
CVE-2025-8058P4MEDIUMCVSS 5.9≥ 0, < 2.36-9+deb12u13≥ 0, < 2.41-112025-07-23
CVE-2025-8058 [MEDIUM] CVE-2025-8058: The regcomp function in the GNU C library version from 2
The regcomp function in the GNU C library version from 2.4 to 2.41 is subject to a double free if some previous allocation fails. It can be accomplished either by a malloc failure or by using an interposed malloc that injects random malloc failures. The double free can allow buffer manipulation depending of how the regex is constructed. This issue affects all architectures and ABIs supported by the GNU
osv
CVE-2010-3192P4MEDIUMCVSS 5.0fixed in 2.262010-10-14
CVE-2010-3192 [MEDIUM] CWE-200 CVE-2010-3192: Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0
Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorrect program, as demonstrated by a setuid program that contains a stack-based buffer overflow error, rela
nvd
CVE-2026-4438P4MEDIUMCVSS 5.4≥ 2.34, ≤ 2.432026-03-20
CVE-2026-4438 [MEDIUM] CWE-20 CVE-2026-4438: Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library'
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the GNU C library version 2.34 to version 2.43 could result in an invalid DNS hostname being returned to the caller in violation of the DNS specification.
nvdosv