cbcvebase.

Libdwarf Project Libdwarf vulnerabilities

45 known vulnerabilities affecting libdwarf_project/libdwarf.

Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH14MEDIUM24LOW1

Vulnerabilities

Page 1 of 3
CVE-2016-9558P3CRITICALCVSS 9.8≥ 1999-12-14, < 2016-11-242017-02-28
CVE-2016-9558 [CRITICAL] CWE-190 CVE-2016-9558: (1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 20161124 allow remote a (1) libdwarf/dwarf_leb.c and (2) dwarfdump/print_frames.c in libdwarf before 20161124 allow remote attackers to have unspecified impact via a crafted bit pattern in a signed leb number, aka a "negation overflow."
nvd
CVE-2016-9480P3CRITICALCVSS 9.1v2016-10-212016-11-29
CVE-2016-9480 [CRITICAL] CWE-119 CVE-2016-9480: libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a de libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.
nvd
CVE-2017-9052P3CRITICALCVSS 9.8v2017-03-212017-05-18
CVE-2017-9052 [CRITICAL] CWE-119 CVE-2017-9052: An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A heap-based buffer ove An issue, also known as DW201703-006, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in dwarf_formsdata() is due to a failure to check a pointer for being in bounds (in a few places in this function) and a failure in a check in dwarf_attr_list().
nvd
CVE-2017-9055P3CRITICALCVSS 9.8v2017-03-212017-05-18
CVE-2017-9055 [CRITICAL] CWE-125 CVE-2017-9055: An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In dwarf_formsdata() a An issue, also known as DW201703-001, was discovered in libdwarf 2017-03-21. In dwarf_formsdata() a few data types were not checked for being in bounds, leading to a heap-based buffer over-read.
nvd
CVE-2017-9054P3CRITICALCVSS 9.8v2017-03-212017-05-18
CVE-2017-9054 [CRITICAL] CWE-125 CVE-2017-9054: An issue, also known as DW201703-002, was discovered in libdwarf 2017-03-21. In _dwarf_decode_s_leb1 An issue, also known as DW201703-002, was discovered in libdwarf 2017-03-21. In _dwarf_decode_s_leb128_chk() a byte pointer was dereferenced just before it was checked for being in bounds, leading to a heap-based buffer over-read.
nvd
CVE-2017-9053P3CRITICALCVSS 9.1v2017-03-212017-05-18
CVE-2017-9053 [CRITICAL] CWE-125 CVE-2017-9053: An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer ove An issue, also known as DW201703-005, was discovered in libdwarf 2017-03-21. A heap-based buffer over-read in _dwarf_read_loc_expr_op() is due to a failure to check a pointer for being in bounds (in a few places in this function).
nvd
CVE-2016-5044P3HIGHCVSS 7.5≥ 1999-12-14, < 2016-09-232017-02-17
CVE-2016-5044 [HIGH] CWE-787 CVE-2016-5044: The WRITE_UNALIGNED function in dwarf_elf_access.c in libdwarf before 20160923 allows remote attacke The WRITE_UNALIGNED function in dwarf_elf_access.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds write and crash) via a crafted DWARF section.
nvd
CVE-2016-9275P3HIGHCVSS 7.5≥ 1999-12-14, < 2016-11-242017-03-23
CVE-2016-9275 [HIGH] CWE-787 CVE-2016-9275: Heap-based buffer overflow in the _dwarf_skim_forms function in libdwarf/dwarf_macro5.c in Libdwarf Heap-based buffer overflow in the _dwarf_skim_forms function in libdwarf/dwarf_macro5.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).
nvd
CVE-2022-39170P3HIGHCVSS 8.8v0.4.12022-09-02
CVE-2022-39170 [HIGH] CWE-415 CVE-2022-39170: libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c. libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
nvd
CVE-2016-5036P3HIGHCVSS 7.5≥ 1999-12-14, < 2016-09-232017-02-17
CVE-2016-5036 [HIGH] CWE-125 CVE-2016-5036: The dump_block function in print_sections.c in libdwarf before 20160923 allows remote attackers to c The dump_block function in print_sections.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via crafted frame data.
nvd
CVE-2016-5042P3HIGHCVSS 7.5≥ 1999-12-14, < 2016-09-232017-02-17
CVE-2016-5042 [HIGH] CWE-835 CVE-2016-5042: The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause a d The dwarf_get_aranges_list function in libdwarf before 20160923 allows remote attackers to cause a denial of service (infinite loop and crash) via a crafted DWARF section.
nvd
CVE-2016-5043P3HIGHCVSS 7.5≥ 1999-12-14, < 2016-09-232017-02-17
CVE-2016-5043 [HIGH] CWE-125 CVE-2016-5043: The dwarf_dealloc function in libdwarf before 20160923 allows remote attackers to cause a denial of The dwarf_dealloc function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted DWARF section.
nvd
CVE-2016-5039P3HIGHCVSS 7.5≥ 1999-12-14, < 2016-09-232017-02-17
CVE-2016-5039 [HIGH] CWE-125 CVE-2016-5039: The get_attr_value function in libdwarf before 20160923 allows remote attackers to cause a denial of The get_attr_value function in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted object with all-bits on.
nvd
CVE-2016-5038P3HIGHCVSS 7.5≥ 1999-12-14, < 2016-09-232017-02-17
CVE-2016-5038 [HIGH] CWE-125 CVE-2016-5038: The dwarf_get_macro_startend_file function in dwarf_macro5.c in libdwarf before 20160923 allows remo The dwarf_get_macro_startend_file function in dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted string offset for .debug_str.
nvd
CVE-2016-9276P3HIGHCVSS 7.5≥ 1999-12-14, < 2016-11-242017-03-23
CVE-2016-9276 [HIGH] CWE-125 CVE-2016-9276: The dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before 20161124 allows remote att The dwarf_get_aranges_list function in dwarf_arrange.c in Libdwarf before 20161124 allows remote attackers to cause a denial of service (out-of-bounds read).
nvd
CVE-2022-34299P3HIGHCVSS 8.1v0.4.02022-06-23
CVE-2022-34299 [HIGH] CWE-125 CVE-2022-34299: There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_form There is a heap-based buffer over-read in libdwarf 0.4.0. This issue is related to dwarf_global_formref_b.
nvd
CVE-2024-2002P3HIGHCVSS 7.5≥ 0.1.0, < 0.9.22024-03-18
CVE-2024-2002 [HIGH] CWE-415 CVE-2024-2002: A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf ma A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results.
nvd
CVE-2016-5041P4HIGHCVSS 7.5≥ 1999-12-14, < 2016-09-232017-04-10
CVE-2016-5041 [HIGH] CWE-476 CVE-2016-5041: dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (NUL dwarf_macro5.c in libdwarf before 20160923 allows remote attackers to cause a denial of service (NULL pointer dereference) via a debugging information entry using DWARF5 and without a DW_AT_name.
nvd
CVE-2016-5040P4HIGHCVSS 7.5≥ 1999-12-14, < 2016-09-232017-02-17
CVE-2016-5040 [HIGH] CWE-125 CVE-2016-5040: libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read an libdwarf before 20160923 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a large length value in a compilation unit header.
nvd
CVE-2022-32200P4HIGHCVSS 7.8v0.4.02022-06-02
CVE-2022-32200 [HIGH] CWE-125 CVE-2022-32200: libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c. libdwarf 0.4.0 has a heap-based buffer over-read in _dwarf_check_string_valid in dwarf_util.c.
nvd