vciy

CVEs we hold for Gnu

Records whose assigning authority named Gnu as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9605GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflowGNU libredwg
CVE-2026-9530GNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-boundsGNU LibreDWG
CVE-2026-9529GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereferenceGNU LibreDWG
CVE-2026-9504GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-boundsGNU LibreDWG
CVE-2026-9503GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereferenceGNU LibreDWG
CVE-2026-9502GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based overflowGNU LibreDWG
CVE-2026-9501GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertionGNU LibreDWG
CVE-2026-9500GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflowGNU LibreDWG
CVE-2026-91782GNU Binutils Dynamic Relocation Allocation elfxx-x86.c elf_x86_allocate_dynrelocs null pointer dereferenceGNU Binutils
CVE-2026-91781GNU Binutils ELF Section elf64-x86-64.c elf_x86_64_common_section_index null pointer dereferenceGNU Binutils
CVE-2026-91780GNU Binutils elflink.c elf_link_add_object_symbols null pointer dereferenceGNU Binutils
CVE-2026-91779GNU Binutils Eh Frame elf-eh-frame.c _bfd_elf_eh_frame_section_offset null pointer dereferenceGNU Binutils
CVE-2026-91752GNU libextractor before 1.15 Stack Overflow via OLE2GNU libextractor
CVE-2026-90831GNU Binutils ELF String Table elf-strtab.c _bfd_elf_strtab_delref memory corruptionGNU Binutils
CVE-2026-90830GNU Binutils Section Merge merge.c _bfd_write_merged_section null pointer dereferenceGNU Binutils
CVE-2026-90829GNU Binutils SHT_GROUP Section elf.c bfd_elf_set_group_contents null pointer dereferenceGNU Binutils
CVE-2026-90828GNU Binutils ELF Orphan Section ldelf.c elf_orphan_compatible null pointer dereferenceGNU Binutils
CVE-2026-90804GNU Binutils Eh Frame Section elf-eh-frame.c _bfd_elf_write_section_eh_frame buffer overflowGNU Binutils
CVE-2026-90803GNU Binutils ld elf64-x86-64.c elf_x86_64_relocate_section buffer overflowGNU Binutils
CVE-2026-90802GNU Binutils ld libbfd.c bfd_putl64 null pointer dereferenceGNU Binutils
CVE-2026-90801GNU Binutils ld cache.c cache_bwrite buffer overflowGNU Binutils
CVE-2026-90622GNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereferenceGNU libredwg
CVE-2026-77219GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image LoaderGNU Emacs
CVE-2026-71394Heap Use of Uninitialized Memory in GNU Emacs for AndroidGNU Emacs
CVE-2026-71393Heap Buffer Overflow in GNU Emacs for AndroidGNU Emacs
CVE-2026-71392Integer Overflow in GNU Emacs for AndroidGNU Emacs
CVE-2026-71391Off-by-One Error in GNU Emacs for AndroidGNU Emacs
CVE-2026-66486Improper Output Encoding in GNU cpioGNU cpio
CVE-2026-66485Uncontrolled Memory Allocation in GNU cpioGNU cpio
CVE-2026-66484Path Traversal in GNU cpioGNU cpio
CVE-2026-5958Race Condition in GNU SedGNU Sed
CVE-2026-58472GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encodinggnuwget wget
CVE-2026-58471GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.cgnuwget wget
CVE-2026-58470GNU Wget 1.25.0 Integer Overflow via Content-Range Header Parsinggnuwget wget
CVE-2026-58469GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsinggnuwget wget
CVE-2026-57062no title heldGnuPG
CVE-2026-57053no title heldGNU libidn
CVE-2026-56968no title heldGNU SASL
CVE-2026-56392Heap-based Buffer Overflow in GNU coreutilsGNU coreutils
CVE-2026-56391Out‑of‑bounds Read in GNU coreutilsGNU coreutils
CVE-2026-56390Arbitrary Output Location Change in GNU BisonGNU Bison
CVE-2026-56389Arbitrary Command Execution in GNU BisonGNU Bison
CVE-2026-56355no title heldGNU Savane
CVE-2026-56289Loop with Unreachable Exit Condition in GNU patchGNU patch
CVE-2026-56288NULL Pointer Dereference in GNU patchGNU patch
CVE-2026-53910Heap-based Buffer Overflow in GNU diffutilsGNU diffutils
CVE-2026-48829no title heldGNU SASL
CVE-2026-41992Global Buffer Overflow in GNU gzipGNU gzip
CVE-2026-41991Predictable Temporary File in GNU gzipGNU gzip
CVE-2026-41990no title heldgnupg Libgcrypt
CVE-2026-41989no title heldgnupg Libgcrypt
CVE-2026-40553Stack-based buffer overflow in gawkGNU gawk
CVE-2026-40469Heap buffer overflow in gawkGNU gawk
CVE-2026-40468Heap buffer overflow in gawkGNU gawk
CVE-2026-40467Use after free in gawkGNU gawk
CVE-2026-32772no title heldGNU inetutils
CVE-2026-32746no title heldGNU inetutils
CVE-2026-28372no title heldGNU inetutils
CVE-2026-24883no title heldGnuPG
CVE-2026-24882no title heldGnuPG
CVE-2026-24881no title heldGnuPG
CVE-2026-24061no title heldGNU Inetutils
CVE-2026-1858wget2 Improper Certificate Validationgnu wget2
CVE-2026-16599Denial of Service in GNU wgetGNU wget
CVE-2026-15520GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflowGNU LibreDWG
CVE-2026-15184GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereferenceGNU LibreDWG
CVE-2026-15182GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflowGNU LibreDWG
CVE-2026-15146CVE-2026-15146GNU wget Wget
CVE-2025-8746GNU libopts __strstr_sse2 memory corruptionGNU libopts
CVE-2025-8736GNU cflow Lexer c.c yylex buffer overflowGNU cflow
CVE-2025-8735GNU cflow Lexer c.c yylex null pointer dereferenceGNU cflow
CVE-2025-8225GNU Binutils DWARF Section dwarf.c process_debug_info memory leakGNU Binutils
CVE-2025-8224GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereferenceGNU Binutils
CVE-2025-7786Gnuboard g6 Post Reply qa cross site scriptingGnuboard g6
CVE-2025-7546GNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds writeGNU Binutils
CVE-2025-7545GNU Binutils objcopy.c copy_section heap-based overflowGNU Binutils
CVE-2025-69720no title heldGNU ncurses
CVE-2025-68973no title heldGnuPG
CVE-2025-68972no title heldGnuPG
CVE-2025-62689no title heldGNU libbmicrohttpd
CVE-2025-61664Grub2: missing unregister call for normal_exit command may lead to use-after-freeGNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2025-61663Grub2: missing unregister call for normal commands may lead to use-after-freeGNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2025-61662Grub2: missing unregister call for gettext command may lead to use-after-freeGNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2025-61661Grub2: grub2: out-of-bounds write via malicious usb deviceGNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2025-6141GNU ncurses parse_entry.c postprocess_termcap stack-based overflowGNU ncurses
CVE-2025-59777no title heldGNU libbmicrohttpd
CVE-2025-59378no title heldGNU Guix
CVE-2025-5899GNU PSPP pspp-convert.c parse_variables_option free of memory not on the heapGNU PSPP
CVE-2025-5898GNU PSPP pspp-convert.c parse_variables_option out-of-bounds writeGNU PSPP
CVE-2025-54771Grub2: use-after-free in grub_file_close()GNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2025-54770Grub2: use-after-free in net_set_vlanGNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise…
CVE-2025-5245GNU Binutils objdump debug.c debug_type_samep memory corruptionGNU Binutils
CVE-2025-5244GNU Binutils ld elflink.c elf_gc_sweep memory corruptionGNU Binutils
CVE-2025-5001GNU PSPP pspp-convert.c calloc integer overflowGNU PSPP
CVE-2025-49431WordPress MF Plus WPML plugin <= 1.1 - Settings Change VulnerabilityGnuget MF Plus WPML
CVE-2025-48188no title heldGNU PSPP
CVE-2025-47816no title heldGNU PSPP
CVE-2025-47815no title heldGNU PSPP
CVE-2025-47814no title heldGNU PSPP
CVE-2025-47229no title heldGNU PSPP
CVE-2025-45582no title heldGNU Tar
CVE-2025-43921no title heldGNU Mailman
CVE-2025-43920no title heldGNU Mailman
CVE-2025-43919no title heldGNU Mailman
CVE-2025-3198GNU Binutils objdump bucomm.c display_info memory leakGNU Binutils
CVE-2025-30258no title heldGnuPG
CVE-2025-1377GNU elfutils eu-strip strip.c gelf_getsymshndx denial of serviceGNU elfutils
CVE-2025-1376GNU elfutils eu-strip elf_strptr.c elf_strptr denial of serviceGNU elfutils
CVE-2025-1372GNU elfutils eu-readelf readelf.c print_string_section buffer overflowGNU elfutils
CVE-2025-1371GNU elfutils eu-read readelf.c handle_dynamic_symtab null pointer dereferenceGNU elfutils
CVE-2025-1365GNU elfutils eu-readelf readelf.c process_symtab buffer overflowGNU elfutils
CVE-2025-1352GNU elfutils eu-readelf libdw_alloc.c __libdw_thread_tail memory corruptionGNU elfutils
CVE-2025-13151CVE-2025-13151GnuTLS libtasn1
CVE-2025-11840GNU Binutils ldmisc.c vfinfo out-of-boundsGNU Binutils
CVE-2025-11839GNU Binutils prdbg.c tg_tag_type return valueGNU Binutils
CVE-2025-1182GNU Binutils ld elflink.c bfd_elf_reloc_symbol_deleted_p memory corruptionGNU Binutils
CVE-2025-1181GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec memory corruptionGNU Binutils
CVE-2025-1180GNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruptionGNU Binutils
CVE-2025-1179GNU Binutils ld libbfd.c bfd_putl64 memory corruptionGNU Binutils
CVE-2025-1178GNU Binutils ld libbfd.c bfd_putl64 memory corruptionGNU Binutils
CVE-2025-1176GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflowGNU Binutils
CVE-2025-1153GNU Binutils format.c bfd_set_format memory corruptionGNU Binutils
CVE-2025-1152GNU Binutils ld xstrdup.c xstrdup memory leakGNU Binutils
CVE-2025-1151GNU Binutils ld xmemdup.c xmemdup memory leakGNU Binutils
CVE-2025-1150GNU Binutils ld libbfd.c bfd_malloc memory leakGNU Binutils
CVE-2025-11495GNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflowGNU Binutils
CVE-2025-11494GNU Binutils Linker elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-boundsGNU Binutils
CVE-2025-1149GNU Binutils ld xmalloc.c xstrdup memory leakGNU Binutils
CVE-2025-1148GNU Binutils ld ldelfgen.c link_order_scan memory leakGNU Binutils
CVE-2025-1147GNU Binutils nm nm.c internal_strlen buffer overflowGNU Binutils
CVE-2025-11414GNU Binutils Linker elflink.c get_link_hash_entry out-of-boundsGNU Binutils
CVE-2025-11413GNU Binutils Linker elflink.c elf_link_add_object_symbols out-of-boundsGNU Binutils
CVE-2025-11412GNU Binutils Linker elflink.c bfd_elf_gc_record_vtentry out-of-boundsGNU Binutils
CVE-2025-11083GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflowGNU Binutils
CVE-2025-11082GNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflowGNU Binutils
CVE-2025-11081GNU Binutils objdump.c dump_dwarf_section out-of-boundsGNU Binutils
CVE-2025-0840GNU Binutils objdump.c disassemble_bytes stack-based overflowGNU Binutils
CVE-2024-56738no title heldGNU GRUB2
CVE-2024-56737no title heldGNU GRUB2
CVE-2024-10524GNU Wget is vulnerable to an SSRF attack when accessing partially-user-controlled shorthand URLsgnu wget
CVE-2023-2789GNU cflow parser.c parse_variable_declaration denial of serviceGNU cflow
CVE-2023-0687no title heldGNU C Library
CVE-2023-0361no title heldn/a gnutls
CVE-2022-3219no title heldn/a gnupg
CVE-2022-28736There's a use-after-free vulnerability in grub_cmd_chainloader() functionGNU GRUB
CVE-2022-28735no title heldGNU GRUB
CVE-2022-28734Out-of-bounds write when handling split HTTP headersGNU GRUB
CVE-2022-28733Integer underflow in grub_net_recv_ip4_packetsGNU GRUB
CVE-2022-2509no title heldn/a GnuTLS
CVE-2022-2469no title heldGNU SASL
CVE-2022-1252Use of a Broken or Risky Cryptographic Algorithm in gnuboard/gnuboard5gnuboard/gnuboard5
CVE-2021-4293gnuboard youngcart5 menu_list_update.php cross site scriptinggnuboard youngcart5
CVE-2021-4209no title heldn/a GnuTLS
CVE-2021-38354GNU-Mailman Integration <= 1.0.6 Reflected Cross-Site ScriptingGNU-Mailman Integration
CVE-2021-3831Cross-site Scripting (XSS) - Reflected in gnuboard/gnuboard5gnuboard/gnuboard5
CVE-2021-27851Local privilege escalation in GNU Guix via guix-daemon and '--keep-failed'GNU Guix guix-daemon
CVE-2021-20232no title heldn/a gnutls
CVE-2021-20231no title heldn/a gnutls
CVE-2020-6096no title heldn/a GNU glibc
CVE-2020-1752no title heldGNU Libc glibc
CVE-2019-3836no title heldgnutls
CVE-2019-3829no title heldgnutls
CVE-2019-1010204no title heldGNU binutils gold
CVE-2019-1010180no title heldGNU gdb
CVE-2019-1010025no title heldGNU Libc glibc
CVE-2019-1010024no title heldGNU Libc glibc
CVE-2019-1010023no title heldGNU Libc glibc
CVE-2019-1010022no title heldGNU C Library glibc
CVE-2018-0618no title heldGNU Mailman Mailman
CVE-2017-7526no title heldGnuPG libgcrypt
CVE-2017-7507no title heldgnutls
CVE-2017-7476no title heldn/a Gnulib before 2017-04-26
CVE-2017-13090GNU Wget: heap overflow in HTTP protocol handlingGNU Project Wget
CVE-2017-13089GNU Wget: stack overflow in HTTP protocol handlingGNU Project Wget
CVE-2015-0837no title heldGNU GnuPG
CVE-2015-0294no title heldGnuTLS
CVE-2014-3591no title heldGNU GnuPG
CVE-2012-0824no title heldgnusound
CVE-2002-2439no title heldGNU gcc

179 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.