Vulnerabilities
58 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-1372 | A vulnerability was found in GNU elfutils 0.192. A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf. The manipulation of the argument z/x leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 73db9d2021cab9e23fd734b0a76a612d52a6f1db. It is recommended to apply a patch to fix this issue. NVD description · AI analysis pending | 4.8 group max | <1% | PoC ×4 |
| — | |
| CVE-2025-1352 | A vulnerability has been found in GNU elfutils 0.192 and classified as critical. A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue. NVD description · AI analysis pending | 2.3 | <1% | PoC |
| — | |
| CVE-2024-25260 | elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c. elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c. NVD description · AI analysis pending | 4.0 | <1% | PoC ×2 |
| — | |
| CVE-2020-21047 | The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashe The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2021-33294 | In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) vi In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file. NVD description · AI analysis pending | 5.5 | <1% | PoC |
| — | |
| CVE-2023-33551 +1 in the same advisory: …33552 | Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted er Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2018-25068 | A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fileresources/src/main/java/com/anrisoftware/globalpom/fileresourcemanager/FileResourceManagerProvider.java. The manipulation leads to insecure temporary file. The attack can be initiated remotely. Upgrading to version 4.5.1 is able to address this issue. The patch is identified as 77a820bac2f68e662ce261ecb050c643bd7ee560. It is recommended to upgrade the affected component. VDB-217570 is the identifier assigned to this vulnerability. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2021-4238 | Randomly-generated alphanumeric strings contain significantly less entropy than expected. Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions. NVD description · AI analysis pending | 9.1 | 1% | PoC |
| — | |
| CVE-2020-36566 | Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. NVD description · AI analysis pending | 9.1 | 1% |
| — | ||
| CVE-2021-4277 | A vulnerability, which was classified as problematic, has been found in fredsmith utils. A vulnerability, which was classified as problematic, has been found in fredsmith utils. This issue affects some unknown processing of the file screenshot_sync of the component Filename Handler. The manipulation leads to predictable from observable state. The name of the patch is dbab1b66955eeb3d76b34612b358307f5c4e3944. It is recommended to apply a patch to fix this issue. The identifier VDB-216749 was assigned to this vulnerability. NVD description · AI analysis pending | 5.3 | <1% |
| — | ||
| CVE-2021-34080 | OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters prov OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters provided to the createCertRequest() and the createCert() functions. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2022-24884 | ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple signatures from different public keys does not mitigate the issue: `ecdsa_verify_list_legacy()` will accept an arbitrary number of such forged signatures. Both the `ecdsautil verify` CLI command and the libecdsautil library are affected. The issue has been fixed in ecdsautils 0.4.1. All older versions of ecdsautils (including versions before the split into a library and a CLI utility) are vulnerable. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2021-41269 | cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected. The issue was patched and a new version was released. Please upgrade to version 9.1.6. There are no known workarounds known. NVD description · AI analysis pending | 9.8 | 4% | PoC |
| — | |
| CVE-2021-23396 | All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function. All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-26954 | An issue was discovered in the qwutils crate before 0.3.1 for Rust. An issue was discovered in the qwutils crate before 0.3.1 for Rust. When a Clone panic occurs, insert_slice_clone can perform a double drop. NVD description · AI analysis pending | 5.3 | 1% | PoC |
| — | |
| CVE-2020-26238 | Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.3, a template Injection vulnerability is present. This enables attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Only projects using the @Cron annotation to validate untrusted Cron expressions are affected. This issue was patched in version 9.1.3. NVD description · AI analysis pending | 8.1 | 4% | PoC ×2 |
| — | |
| CVE-2020-7722 | All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function. All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2020-7718 | All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions. All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2020-7703 | All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function. All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2017-5333 | Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of se Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file. NVD description · AI analysis pending | 7.8 | 2% |
| — | ||
| CVE-2019-15657 | In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code. In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2019-7665 +1 in the same advisory: …7664 | In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes. NVD description · AI analysis pending | 5.5 | 1% | PoC ×2 |
| — | |
| CVE-2019-7149 | A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by eu-nm. NVD description · AI analysis pending | 6.5 group max | 2% | PoC |
| — | |
| CVE-2018-18520 +1 in the same advisory: …18521 | An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file before handling all inner entries. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file. NVD description · AI analysis pending | 6.5 group max | 3% | PoC |
| — | |
| CVE-2018-18310 | An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by consider_notes. NVD description · AI analysis pending | 5.5 | 1% | PoC |
| — | |
| CVE-2018-16402 +1 in the same advisory: …16403 | libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other i libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice. NVD description · AI analysis pending | 9.8 group max | 4% | PoC |
| — | |
| CVE-2018-16062 | dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file. NVD description · AI analysis pending | 5.5 | 2% |
| — | ||
| CVE-2018-10775 | NULL pointer dereference in the _fields_add function in fields.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (a NULL pointer dereference in the _fields_add function in fields.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by end2xml. NVD description · AI analysis pending | 6.5 | 2% | PoC |
| — | |
| CVE-2018-8769 | elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported. elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported. NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2017-17512 | sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable, which all sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --proxy-pac-file argument. NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2017-5208 | Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted execut Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code. NVD description · AI analysis pending | 8.8 | 4% |
| — | ||
| CVE-2017-7611 | The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. NVD description · AI analysis pending | 5.5 | 2% | PoC |
| — |