cbcvebase.

Gnu Glibc vulnerabilities

169 known vulnerabilities affecting gnu/glibc.

Total CVEs
169
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH66MEDIUM70LOW9

Vulnerabilities

Page 9 of 9
CVE-2019-19126P4LOWCVSS 3.3fixed in 2.312019-11-19
CVE-2019-19126 [LOW] CWE-665 CVE-2019-19126: On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_ On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid program.
nvdosv
CVE-2003-0859P4MEDIUMCVSS 4.9v2.3.22003-12-15
CVE-2003-0859 [MEDIUM] CVE-2003-0859: The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial o The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
nvd
CVE-2004-1382P4LOWCVSS 2.1v2.0v2.0.1+24 more2004-12-31
CVE-2004-1382 [LOW] CVE-2004-1382: The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
nvdosv
CVE-2013-2207P4LOWCVSS 2.6≤ 2.17v2.0+24 more2013-10-09
CVE-2013-2207 [LOW] CWE-264 CVE-2013-2207: pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for t pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.
nvdosv
CVE-2011-1089P4LOWCVSS 3.3≤ 2.13v1.00+56 more2011-04-10
CVE-2011-1089 [LOW] CWE-16 CVE-2011-1089: The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a different vulnerability than CVE-2010-029
nvdosv
CVE-2004-0968P4LOWCVSS 2.1v2.0v2.0.1+24 more2005-02-09
CVE-2004-0968 [LOW] CVE-2004-0968: The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
nvdosv
CVE-2004-1453P4LOWCVSS 2.1v2.0v2.0.1+23 more2004-12-31
CVE-2004-1453 [LOW] CVE-2004-1453: GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.
nvdosv
CVE-2021-27645P4LOWCVSS 2.5≥ 2.29, ≤ 2.332021-02-24
CVE-2021-27645 [LOW] CWE-415 CVE-2021-27645: The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, wh The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c.
nvdosv
CVE-2000-0959P4LOWCVSS 1.2v2.1.3.102000-12-19
CVE-2000-0959 [LOW] CVE-2000-0959: glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a progr glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
nvd
Gnu Glibc vulnerabilities | cvebase