category: runtime clear

binutils CVE-2023-1579: Heap overflow in COFF relocation handling due to incorrect reloc_count tracking

CVE-2021-3487: binutils readelf OOB read in fetch_indexed_string (.debug_str_offsets)

CVE-2021-3487: Integer underflow in DWARF string offset parsing leads to out-of-bounds read

CVE-2020-16592: binutils libbfd UAF in section merging via hash table resize

CVE-2020-16592: Use-after-free in BFD merge.c during section merging

CVE-2022-38126: Memory leak in binutils bfd/dwarf2.c read_abbrevs — partial abbrev not freed on error, re-parsing loop

CVE-2022-38126: Memory leak in BFD DWARF abbreviation table handling

CVE-2017-13089: wget skip_short_body stack overflow via negative HTTP chunk size (signed strtol + SIZE_MAX read)

CVE-2017-13089: wget skip_short_body() stack overflow via negative chunked size

CVE-2024-29510 — Format string injection in Ghostscript uniprint device (gdevupd.c)

criticalruntimecposted 3 months ago

CVE-2023-7008: GNU sed -i --follow-symlinks TOCTOU race enables arbitrary file overwrite

criticalruntimecposted 3 months ago

CVE-2023-7008: TOCTOU symlink race in sed --follow-symlinks

CVE-2022-28357: Heap buffer overflow in sed regex backreference handling

CVE-2013-0222: Buffer Overflow in coreutils sort via getmonth() with locale month names

GNU patch CVE-2019-13638 - Shell injection via unquoted filenames in [redacted:name]

CVE-2022-2509: Double-free in GnuTLS find_signer() during PKCS7 cert chain verification

CVE-2022-2509: Double-free in GnuTLS certificate SAN extension parsing

CVE-2021-20231 GnuTLS — Use-after-free via realloc-aliasing in TLS 1.3 client_hello extensions (key_share + pre_shared_key)

GnuTLS CVE-2021-20231: Use-After-Free in ECDHE Key Exchange Processing

CVE-2020-24659: GnuTLS NULL deref via no_renegotiation alert mid-handshake