Gnu Glibc vulnerabilities
170 known vulnerabilities affecting gnu/glibc.
Total CVEs
170
CISA KEV
1
actively exploited
Public exploits
25
Exploited in wild
1
Severity breakdown
CRITICAL24HIGH67MEDIUM70LOW9
Vulnerabilities
Page 9 of 9
CVE-2003-0689HIGHCVSS 7.5≥ 0, < 2.2.52003-10-20
CVE-2003-0689 [HIGH] CVE-2003-0689: The getgrouplist function in GNU libc (glibc) 2
The getgrouplist function in GNU libc (glibc) 2.2.4 and earlier allows attackers to cause a denial of service (segmentation fault) and execute arbitrary code when a user is a member of a large number of groups, which can cause a buffer overflow.
osv
CVE-2003-0028HIGHCVSS 7.5v2.1v2.1.1+11 more2003-03-25
CVE-2003-0028 [HIGH] CVE-2003-0028: Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external d
Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability than CVE-2002-0391.
nvd
CVE-2002-1265MEDIUMCVSS 5.0v2.0v2.0.1+18 more2002-11-12
CVE-2002-1265 [MEDIUM] CVE-2002-1265: The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism whe
The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang).
nvd
CVE-2002-1146MEDIUMCVSS 5.0≤ 2.2.52002-10-11
CVE-2002-1146 [MEDIUM] CVE-2002-1146: The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earli
The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote attackers to cause a denial of service (cr
nvdosv
CVE-2002-0391CRITICALCVSS 9.8≥ 0, < 2.2.5-132002-08-12
CVE-2002-0391 [CRITICAL] CVE-2002-0391: Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, al
Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd.
osv
CVE-2002-0684HIGHCVSS 7.5≤ 2.2.52002-08-12
CVE-2002-0684 [HIGH] CVE-2002-0684: Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as use
Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr.
nvdosv
CVE-2002-0651HIGHCVSS 7.5≥ 0, < 2.2.5-82002-07-03
CVE-2002-0651 [HIGH] CVE-2002-0651: Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a de
Buffer overflow in the DNS resolver code used in libc, glibc, and libbind, as derived from ISC BIND, allows remote malicious DNS servers to cause a denial of service and possibly execute arbitrary code via the stub resolvers.
osv
CVE-2000-0959LOWCVSS 1.2v2.1.3.102000-12-19
CVE-2000-0959 [LOW] CVE-2000-0959: glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a progr
glibc2 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environmental variables when a program is spawned from a setuid program, which could allow local users to overwrite files via a symlink attack.
nvd
CVE-2000-0824HIGHCVSS 7.2PoCv2.1.12000-11-14
CVE-2000-0824 [HIGH] CVE-2000-0824: The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variab
The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.
nvd
CVE-2000-0335HIGHCVSS 7.5v2.0v2.1+3 more2000-05-03
CVE-2000-0335 [HIGH] CVE-2000-0335: The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query r
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.
nvd
← Previous9 / 9