Gnu
63 known vulnerabilities
Top Products
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local a
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confin
GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifyi
GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of gram
GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation
GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--ch
GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff
GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Impro
GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string
GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() f
GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range(
GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_s
GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shar
GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp util
OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execut
Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write
Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read ar
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandl
GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could
A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) pac
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstra
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online
A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an i
wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromis
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail t
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforc
A flaw was found in GNU Emacs. This vulnerability, a memory corruption issue, occurs when Emacs processes specially craf
A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Ext
A flaw was found in binutils, specifically within the `readelf` utility. This vulnerability allows a local attacker to c
A flaw was found in the `readelf` utility of the binutils package. A local attacker could exploit two Denial of Service
A flaw was found in nano. A local user could exploit a format string vulnerability in the `statusline()` function. By cr
Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between
Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version
A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially cra
A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to
The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when convertin
A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the
Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the
A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read,
A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in t
telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
Heap buffer overflow vulnerability in LibreDWG versions v0.13.3.7571 up to v0.13.3.7835 allows a crafted DWG file to cau
Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malfor
GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malfor
GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF b
GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed
Frequently Asked Questions
How many CVEs affect Gnu?
Gnu has 63 CVE records in our database, including 3 critical and 23 high severity vulnerabilities. 1 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Gnu vulnerabilities?
Gnu has 3 critical severity (CVSS 9.0+) and 23 high severity (CVSS 7.0-8.9) vulnerabilities. 1 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Gnu vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Gnu products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Gnu Vulnerabilities
CyberStrike scans your infrastructure for Gnu vulnerabilities and provides real-time remediation guidance.
Get Started