Show filters
1,191 Total Results
Displaying 381-390 of 1,191
Sort by:
Attacker Value
Unknown

CVE-2019-14250

Disclosure Date: July 24, 2019 (last updated November 27, 2024)
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.
Attacker Value
Unknown

CVE-2019-1010204

Disclosure Date: July 23, 2019 (last updated November 08, 2023)
GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header field must be opened.
Attacker Value
Unknown

CVE-2019-13636

Disclosure Date: July 17, 2019 (last updated November 08, 2023)
In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. This affects inp.c and util.c.
0
Attacker Value
Unknown

CVE-2019-1010023

Disclosure Date: July 15, 2019 (last updated November 08, 2023)
GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.
0
Attacker Value
Unknown

CVE-2019-1010022

Disclosure Date: July 15, 2019 (last updated November 08, 2023)
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.
0
Attacker Value
Unknown

CVE-2019-1010025

Disclosure Date: July 15, 2019 (last updated November 08, 2023)
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.
0
Attacker Value
Unknown

CVE-2019-1010024

Disclosure Date: July 15, 2019 (last updated November 08, 2023)
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.
0
Attacker Value
Unknown

CVE-2019-13050

Disclosure Date: June 29, 2019 (last updated November 08, 2023)
Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a Certificate Spamming Attack.
Attacker Value
Unknown

CVE-2019-12972

Disclosure Date: June 26, 2019 (last updated November 08, 2023)
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. There is a heap-based buffer over-read in _bfd_doprnt in bfd.c because elf_object_p in elfcode.h mishandles an e_shstrndx section of type SHT_GROUP by omitting a trailing '\0' character.
Attacker Value
Unknown

CVE-2019-12904

Disclosure Date: June 20, 2019 (last updated November 08, 2023)
In Libgcrypt 1.8.4, the C implementation of AES is vulnerable to a flush-and-reload side-channel attack because physical addresses are available to other processes. (The C implementation is used on platforms where an assembly-language implementation is unavailable.) NOTE: the vendor's position is that the issue report cannot be validated because there is no description of an attack