category: runtime clear

CVE-2022-0778: Infinite loop in BN_mod_sqrt Tonelli-Shanks algorithm

CVE-2014-0160 Heartbleed: missing bounds check in tls1_process_heartbeat enables OOB heap read

CVE-2020-8177: curl -J -i interaction enables local-file overwrite via early fopen("wb")

significantruntimecposted 3 months ago

CVE-2023-27534: curl SFTP path traversal via weak tilde-prefix check in Curl_getworkingpath

CVE-2023-38545: Heap Buffer Overflow in SOCKS5 Hostname Handling

glibc CVE-2022-23218: Stack Buffer Overflow in clnt_create() with UNIX socket paths

CVE-2021-35942: Integer overflow in glibc wordexp() w_addword leads to heap overflow

CVE-2021-35942: Integer Overflow in glibc wordexp() w_addword Function

CVE-2024-2961: Buffer overflow in glibc ISO-2022-CN-EXT converter

CVE-2021-3999: 1-byte buffer underflow in glibc __getcwd_generic at root

CVE-2021-3999: Off-by-One Buffer Underflow in glibc getcwd()

CVE-2023-6779: heap-overflow in glibc __vsyslog_internal via uninitialized bufsize in secondary buffer path

CVE-2023-6779: glibc __vsyslog_internal heap overflow via secondary buffer expansion

CVE-2023-6246: Heap overflow in glibc __vsyslog_internal due to undersized malloc

CVE-2023-6246: Heap overflow in glibc syslog due to incorrect buffer allocation size

CVE-2023-4911 Looney Tunables: heap overflow in glibc parse_tunables (GLIBC_TUNABLES env var)

CVE-2014-7169: Bash Shellshock incomplete fix – command injection via function import in non-POSIX mode

CVE-2014-7169: Shellshock bypass via unvalidated function names in non-POSIX mode

CVE-2014-6271: Shellshock Command Injection in Bash Function Import

CVE-2014-6271 Shellshock: bash parses past function boundary in env var imports