Home / CVEs we hold for Gnu CVEs we hold for Gnu Records whose assigning authority named Gnu as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9605 GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow GNU libredwg CVE-2026-9530 GNU LibreDWG Dwgbmp Utility decode.c read_2004_compressed_section out-of-bounds GNU LibreDWG CVE-2026-9529 GNU LibreDWG Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference GNU LibreDWG CVE-2026-9504 GNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-bounds GNU LibreDWG CVE-2026-9503 GNU LibreDWG DWG File decode.c dwg_next_entity null pointer dereference GNU LibreDWG CVE-2026-9502 GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section heap-based overflow GNU LibreDWG CVE-2026-9501 GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion GNU LibreDWG CVE-2026-9500 GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflow GNU LibreDWG CVE-2026-91782 GNU Binutils Dynamic Relocation Allocation elfxx-x86.c elf_x86_allocate_dynrelocs null pointer dereference GNU Binutils CVE-2026-91781 GNU Binutils ELF Section elf64-x86-64.c elf_x86_64_common_section_index null pointer dereference GNU Binutils CVE-2026-91780 GNU Binutils elflink.c elf_link_add_object_symbols null pointer dereference GNU Binutils CVE-2026-91779 GNU Binutils Eh Frame elf-eh-frame.c _bfd_elf_eh_frame_section_offset null pointer dereference GNU Binutils CVE-2026-91752 GNU libextractor before 1.15 Stack Overflow via OLE2 GNU libextractor CVE-2026-90831 GNU Binutils ELF String Table elf-strtab.c _bfd_elf_strtab_delref memory corruption GNU Binutils CVE-2026-90830 GNU Binutils Section Merge merge.c _bfd_write_merged_section null pointer dereference GNU Binutils CVE-2026-90829 GNU Binutils SHT_GROUP Section elf.c bfd_elf_set_group_contents null pointer dereference GNU Binutils CVE-2026-90828 GNU Binutils ELF Orphan Section ldelf.c elf_orphan_compatible null pointer dereference GNU Binutils CVE-2026-90804 GNU Binutils Eh Frame Section elf-eh-frame.c _bfd_elf_write_section_eh_frame buffer overflow GNU Binutils CVE-2026-90803 GNU Binutils ld elf64-x86-64.c elf_x86_64_relocate_section buffer overflow GNU Binutils CVE-2026-90802 GNU Binutils ld libbfd.c bfd_putl64 null pointer dereference GNU Binutils CVE-2026-90801 GNU Binutils ld cache.c cache_bwrite buffer overflow GNU Binutils CVE-2026-90622 GNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereference GNU libredwg CVE-2026-77219 GNU Emacs < 31.0.91 Heap Over-Read via PBM/PPM/PGM Image Loader GNU Emacs CVE-2026-71394 Heap Use of Uninitialized Memory in GNU Emacs for Android GNU Emacs CVE-2026-58472 GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding gnuwget wget CVE-2026-58471 GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c gnuwget wget CVE-2026-58470 GNU Wget 1.25.0 Integer Overflow via Content-Range Header Parsing gnuwget wget CVE-2026-58469 GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing gnuwget wget CVE-2026-56392 Heap-based Buffer Overflow in GNU coreutils GNU coreutils CVE-2026-56289 Loop with Unreachable Exit Condition in GNU patch GNU patch CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils GNU diffutils CVE-2026-15520 GNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflow GNU LibreDWG CVE-2026-15184 GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference GNU LibreDWG CVE-2026-15182 GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow GNU LibreDWG CVE-2025-8746 GNU libopts __strstr_sse2 memory corruption GNU libopts CVE-2025-8735 GNU cflow Lexer c.c yylex null pointer dereference GNU cflow CVE-2025-8225 GNU Binutils DWARF Section dwarf.c process_debug_info memory leak GNU Binutils CVE-2025-8224 GNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereference GNU Binutils CVE-2025-7786 Gnuboard g6 Post Reply qa cross site scripting Gnuboard g6 CVE-2025-7546 GNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds write GNU Binutils CVE-2025-7545 GNU Binutils objcopy.c copy_section heap-based overflow GNU Binutils CVE-2025-61664 Grub2: missing unregister call for normal_exit command may lead to use-after-free GNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise… CVE-2025-61663 Grub2: missing unregister call for normal commands may lead to use-after-free GNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise… CVE-2025-61662 Grub2: missing unregister call for gettext command may lead to use-after-free GNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise… CVE-2025-61661 Grub2: grub2: out-of-bounds write via malicious usb device GNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise… CVE-2025-6141 GNU ncurses parse_entry.c postprocess_termcap stack-based overflow GNU ncurses CVE-2025-5899 GNU PSPP pspp-convert.c parse_variables_option free of memory not on the heap GNU PSPP CVE-2025-5898 GNU PSPP pspp-convert.c parse_variables_option out-of-bounds write GNU PSPP CVE-2025-54771 Grub2: use-after-free in grub_file_close() GNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise… CVE-2025-54770 Grub2: use-after-free in net_set_vlan GNU grub2; Red Hat Enterprise Linux 10; Red Hat Enterprise… CVE-2025-5245 GNU Binutils objdump debug.c debug_type_samep memory corruption GNU Binutils CVE-2025-5244 GNU Binutils ld elflink.c elf_gc_sweep memory corruption GNU Binutils CVE-2025-5001 GNU PSPP pspp-convert.c calloc integer overflow GNU PSPP CVE-2025-49431 WordPress MF Plus WPML plugin <= 1.1 - Settings Change Vulnerability Gnuget MF Plus WPML CVE-2025-3198 GNU Binutils objdump bucomm.c display_info memory leak GNU Binutils CVE-2025-1377 GNU elfutils eu-strip strip.c gelf_getsymshndx denial of service GNU elfutils CVE-2025-1376 GNU elfutils eu-strip elf_strptr.c elf_strptr denial of service GNU elfutils CVE-2025-1372 GNU elfutils eu-readelf readelf.c print_string_section buffer overflow GNU elfutils CVE-2025-1371 GNU elfutils eu-read readelf.c handle_dynamic_symtab null pointer dereference GNU elfutils CVE-2025-1365 GNU elfutils eu-readelf readelf.c process_symtab buffer overflow GNU elfutils CVE-2025-1352 GNU elfutils eu-readelf libdw_alloc.c __libdw_thread_tail memory corruption GNU elfutils CVE-2025-11839 GNU Binutils prdbg.c tg_tag_type return value GNU Binutils CVE-2025-1182 GNU Binutils ld elflink.c bfd_elf_reloc_symbol_deleted_p memory corruption GNU Binutils CVE-2025-1181 GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec memory corruption GNU Binutils CVE-2025-1180 GNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruption GNU Binutils CVE-2025-1179 GNU Binutils ld libbfd.c bfd_putl64 memory corruption GNU Binutils CVE-2025-1178 GNU Binutils ld libbfd.c bfd_putl64 memory corruption GNU Binutils CVE-2025-1176 GNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflow GNU Binutils CVE-2025-1153 GNU Binutils format.c bfd_set_format memory corruption GNU Binutils CVE-2025-1152 GNU Binutils ld xstrdup.c xstrdup memory leak GNU Binutils CVE-2025-1151 GNU Binutils ld xmemdup.c xmemdup memory leak GNU Binutils CVE-2025-1150 GNU Binutils ld libbfd.c bfd_malloc memory leak GNU Binutils CVE-2025-11495 GNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflow GNU Binutils CVE-2025-11494 GNU Binutils Linker elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-bounds GNU Binutils CVE-2025-1149 GNU Binutils ld xmalloc.c xstrdup memory leak GNU Binutils CVE-2025-1148 GNU Binutils ld ldelfgen.c link_order_scan memory leak GNU Binutils CVE-2025-1147 GNU Binutils nm nm.c internal_strlen buffer overflow GNU Binutils CVE-2025-11414 GNU Binutils Linker elflink.c get_link_hash_entry out-of-bounds GNU Binutils CVE-2025-11413 GNU Binutils Linker elflink.c elf_link_add_object_symbols out-of-bounds GNU Binutils CVE-2025-11412 GNU Binutils Linker elflink.c bfd_elf_gc_record_vtentry out-of-bounds GNU Binutils CVE-2025-11083 GNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflow GNU Binutils CVE-2025-11082 GNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflow GNU Binutils CVE-2025-11081 GNU Binutils objdump.c dump_dwarf_section out-of-bounds GNU Binutils CVE-2025-0840 GNU Binutils objdump.c disassemble_bytes stack-based overflow GNU Binutils CVE-2024-10524 GNU Wget is vulnerable to an SSRF attack when accessing partially-user-controlled shorthand URLs gnu wget CVE-2023-2789 GNU cflow parser.c parse_variable_declaration denial of service GNU cflow CVE-2022-28736 There's a use-after-free vulnerability in grub_cmd_chainloader() function GNU GRUB CVE-2022-28734 Out-of-bounds write when handling split HTTP headers GNU GRUB CVE-2022-1252 Use of a Broken or Risky Cryptographic Algorithm in gnuboard/gnuboard5 gnuboard/gnuboard5 CVE-2021-4293 gnuboard youngcart5 menu_list_update.php cross site scripting gnuboard youngcart5 CVE-2021-38354 GNU-Mailman Integration <= 1.0.6 Reflected Cross-Site Scripting GNU-Mailman Integration CVE-2021-3831 Cross-site Scripting (XSS) - Reflected in gnuboard/gnuboard5 gnuboard/gnuboard5 CVE-2021-27851 Local privilege escalation in GNU Guix via guix-daemon and '--keep-failed' GNU Guix guix-daemon CVE-2017-13090 GNU Wget: heap overflow in HTTP protocol handling GNU Project Wget CVE-2017-13089 GNU Wget: stack overflow in HTTP protocol handling GNU Project Wget 179 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.