severity: significant clear

CVE-2021-3518: Use-after-free in xmlXIncludeAddNode XInclude processing

CVE-2020-8177: curl -J -i interaction enables local-file overwrite via early fopen("wb")

significantruntimecposted 1 day ago

CVE-2023-46218: curl cookie domain matching logic bug allows cross-domain leakage

CVE-2023-46218 curl cookie mixed-case PSL bypass in Curl_cookie_add

significantdatacposted 1 day ago

CVE-2023-27535: curl FTP connection reuse skips FTP_ACCOUNT / ALTERNATIVE_TO_USER / USE_SSL comparisons

CVE-2021-3487: binutils readelf OOB read in fetch_indexed_string (.debug_str_offsets)

CVE-2022-38126: Memory leak in binutils bfd/dwarf2.c read_abbrevs — partial abbrev not freed on error, re-parsing loop

CVE-2022-38126: Memory leak in BFD DWARF abbreviation table handling

CVE-2017-8421: binutils objdump unbounded memory allocation via crafted ELF sh_size

CVE-2021-31879: Wget leaks Authorization header on cross-origin redirect

CVE-2018-20483: wget leaks URL credentials into POSIX extended file attributes (xattrs)

CVE-2018-20483: wget --xattr leaks URL credentials into user.xdg.origin.url extended attribute

CVE-2024-38428: wget url_skip_credentials semicolon causes hostname confusion

CVE-2024-38428: GNU Wget url_skip_credentials mishandles ';' in userinfo, enabling hostname confusion

CVE-2024-38428: URL parser hostname confusion via multiple @ characters in userinfo

CVE-2024-33869: Ghostscript path traversal via unresolved symlinks in SAFER mode

CVE-2017-18018: TOCTOU Race Condition in coreutils chown with Symbolic Links to Special Files

CVE-2018-6952: GNU patch double-free in another_hunk via ptrn_missing+repl_missing

CVE-2022-2509: Double-free in GnuTLS certificate SAN extension parsing

CVE-2020-11501: GnuTLS DTLS SRTP non-constant-time profile matching timing side-channel