gnu
40 known vulnerabilities affecting gnu products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-42009 | Medium | 1.3% | 7.5 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Data… | |
| CVE-2026-1584 | Medium | 1.3% | 7.5 | A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this … | |
| CVE-2026-42010 | Medium | 1.1% | 7.1 | A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adlem… | |
| CVE-2026-33845 | Medium | 0.8% | 7.5 | A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero len… | |
| CVE-2024-53920 | Medium | 0.6% | 7.8 | In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-co… | |
| CVE-2023-4692 | Medium | 0.5% | 7.5 | An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This is… | |
| CVE-2026-41992 | Medium | 0.4% | 7.5 | GNU gzip contains a global buffer overflow vulnerability in the LZH decompressio… | |
| CVE-2025-61662 | Medium | 0.2% | 7.8 | A Use-After-Free vulnerability has been discovered in GRUB's gettext module. Thi… | |
| CVE-2026-6846 | Medium | 0.2% | 7.8 | A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when p… | |
| CVE-2026-56389 | Medium | 0.2% | 8.6 | GNU Bison allows for an execution of an arbitrary program during HTML report gen… | |
| CVE-2025-32988 | Low | 1.3% | 6.5 | A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to … | |
| CVE-2025-32989 | Low | 1.3% | 5.3 | A heap-buffer-overread vulnerability was found in GnuTLS in how it handles the C… | |
| CVE-2025-32990 | Low | 0.8% | 6.5 | A heap-buffer-overflow (off-by-one) flaw was found in the GnuTLS software in the… | |
| CVE-2026-3832 | Low | 0.7% | 3.7 | A flaw was found in gnutls. A remote attacker could exploit this vulnerability b… | |
| CVE-2026-3833 | Low | 0.6% | 6.5 | A flaw was found in gnutls. This vulnerability occurs because gnutls performs ca… | |
| CVE-2023-4693 | Low | 0.5% | 5.3 | An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This iss… | |
| CVE-2026-5704 | Low | 0.4% | 5.0 | A flaw was found in tar. A remote attacker could exploit this vulnerability by c… | |
| CVE-2026-56968 | Low | 0.3% | 3.7 | GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_cli… | |
| CVE-2026-3442 | Low | 0.3% | 6.1 | A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overfl… | |
| CVE-2026-3441 | Low | 0.2% | 6.1 | A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability,… | |
| CVE-2026-4647 | Low | 0.2% | 6.1 | A flaw was found in the GNU Binutils BFD library, a widely used component for ha… | |
| CVE-2026-90829 | Low | 0.2% | 5.3 | A weakness has been identified in GNU Binutils 2.47. This issue affects the func… | |
| CVE-2026-90831 | Low | 0.2% | 5.3 | A vulnerability was detected in GNU Binutils 2.47. The affected element is the f… | |
| CVE-2026-90830 | Low | 0.2% | 5.3 | A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the… | |
| CVE-2026-6845 | Low | 0.1% | 5.0 | A flaw was found in binutils, specifically within the `readelf` utility. This vu… | |
| CVE-2026-56392 | Low | 0.1% | 6.1 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an i… | |
| CVE-2026-18508 | Low | 0.1% | 4.4 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level… | |
| CVE-2026-90801 | Low | 0.1% | 5.3 | A security flaw has been discovered in GNU Binutils 2.47. This impacts the funct… | |
| CVE-2026-56391 | Low | 0.1% | 6.1 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handl… | |
| CVE-2026-91782 | Low | 0.1% | 3.3 | A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerabilit… | |
| CVE-2026-91781 | Low | 0.1% | 3.3 | A security vulnerability has been detected in GNU Binutils 2.47. Affected is the… | |
| CVE-2026-56390 | Low | 0.1% | 6.3 | GNU Bison improperly handles grammar‑defined output paths. Grammar directives su… | |
| CVE-2026-90803 | Low | 0.1% | 5.3 | A security vulnerability has been detected in GNU Binutils 2.47. Affected by thi… | |
| CVE-2026-91779 | Low | 0.1% | 3.3 | A security flaw has been discovered in GNU Binutils 2.47. This affects the funct… | |
| CVE-2026-91780 | Low | 0.1% | 3.3 | A weakness has been identified in GNU Binutils 2.47. This impacts the function e… | |
| CVE-2026-90804 | Low | 0.1% | 4.8 | A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the… | |
| CVE-2026-90802 | Low | 0.1% | 4.4 | A weakness has been identified in GNU Binutils 2.47. Affected is the function bf… | |
| CVE-2026-6843 | Low | 0.1% | 5.5 | A flaw was found in nano. A local user could exploit a format string vulnerabili… | |
| CVE-2026-6844 | Low | 0.1% | 5.5 | A flaw was found in the `readelf` utility of the binutils package. A local attac… | |
| CVE-2026-18477 | Low | 0.1% | 4.4 | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dump… |