severity: critical clear

CVE-2023-6246: Heap overflow in glibc syslog due to incorrect buffer allocation size

CVE-2023-4911 Looney Tunables: Buffer Overflow in glibc parse_tunables() via name=name=val input

CVE-2023-4911 Looney Tunables: heap overflow in glibc parse_tunables (GLIBC_TUNABLES env var)

CVE-2023-4911 'Looney Tunables' Buffer Overflow in glibc tunable initialization

criticalcposted 1 day ago

CVE-2014-7169: Bash Shellshock incomplete fix – command injection via function import in non-POSIX mode

CVE-2014-7169: Shellshock bypass via unvalidated function names in non-POSIX mode

CVE-2019-18276: Bash restricted-bypass via enable -f loading shared objects

CVE-2014-6271: Shellshock Command Injection in Bash Function Import

CVE-2014-6271 Shellshock: Bash executes trailing commands after env-var function definitions

CVE-2014-6271 Shellshock: bash parses past function boundary in env var imports

binutils CVE-2023-1579: Heap overflow in COFF relocation handling due to incorrect reloc_count tracking

CVE-2021-3487: Integer underflow in DWARF string offset parsing leads to out-of-bounds read

CVE-2020-16592: use-after-free in bfd_hash_lookup (binutils 2.34 BFD library)

CVE-2020-16592: binutils libbfd UAF in section merging via hash table resize

CVE-2020-16592: Use-after-free in BFD merge.c during section merging

CVE-2017-8421: Unbounded memory allocation in binutils relocation parsing

CVE-2022-38533: Heap overflow in BFD compressed section decompression

CVE-2016-6321: GNU tar path traversal via --strip-components applied after safer_name_suffix

tar CVE-2016-6321: Path-traversal via unvalidated --strip-components

CVE-2022-48303: GNU tar 1.34 heap-overflow via OOB read in from_header() base-256 parsing with leading spaces