Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gnu binutils vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2018-12698
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows malicious users to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during exec...
Gnu Binutils 2.30
Canonical Ubuntu Linux 16.04.4
9.8
CVSSv3
CVE-2018-12699
finish_stab in stabs.c in GNU Binutils 2.30 allows malicious users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
Gnu Binutils 2.30
Canonical Ubuntu Linux 16.04.4
2 Github repositories
7.5
CVSSv3
CVE-2018-12697
A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) exists in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.
Gnu Binutils 2.30
Canonical Ubuntu Linux 16.04.4
NA
CVE-2018-12700
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
5.5
CVSSv3
CVE-2018-12641
An issue exists in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_arm_hp_template, demangle_class_name, demangle_fund_type, ...
Gnu Binutils 2.30
6.5
CVSSv3
CVE-2018-10373
concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote malicious users to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by nm-...
Gnu Binutils 2.30
Redhat Enterprise Linux Server 7.0
Redhat Enterprise Linux Desktop 7.0
Redhat Enterprise Linux Workstation 7.0
5.5
CVSSv3
CVE-2018-10372
process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote malicious users to cause a denial of service (heap-based buffer over-read and application crash) via a crafted binary file, as demonstrated by readelf.
Gnu Binutils 2.30
Redhat Enterprise Linux Desktop 7.0
Redhat Enterprise Linux Server 7.0
Redhat Enterprise Linux Workstation 7.0
5.5
CVSSv3
CVE-2018-9996
An issue exists in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expressio...
Gnu Binutils 2.30
5.5
CVSSv3
CVE-2018-9138
An issue exists in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_nested_args, demangle_args, do_arg, and do_type.
Gnu Binutils 2.29
Gnu Binutils 2.30
5.5
CVSSv3
CVE-2018-8945
The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote malicious users to cause a denial of service (segmentation fault) via a large attribute section.
Gnu Binutils 2.30
Redhat Enterprise Linux Desktop 7.0
Redhat Enterprise Linux Workstation 7.0
Redhat Enterprise Linux Server 7.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »