ZeroHour

Vulnerabilities

58 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-1372
+4 in the same advisory: …1365 …1377 …1371 …1376
A vulnerability was found in GNU elfutils 0.192.

A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf. The manipulation of the argument z/x leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 73db9d2021cab9e23fd734b0a76a612d52a6f1db. It is recommended to apply a patch to fix this issue.

NVD description · AI analysis pending
4.8
group max
<1% PoC ×4
  • elfutils project elfutils
CVE-2025-1352
A vulnerability has been found in GNU elfutils 0.192 and classified as critical.

A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.

NVD description · AI analysis pending
2.3<1% PoC
  • elfutils project elfutils
CVE-2024-25260
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.

elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.

NVD description · AI analysis pending
4.0<1% PoC ×2
  • elfutils project elfutils
CVE-2020-21047
The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashe

The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error (CWE-193) and reachable assertion (CWE-617); to exploit the vulnerability, the attackers need to craft certain ELF files which bypass the missing bound checks.

NVD description · AI analysis pending
5.5<1%
  • elfutils project elfutils
CVE-2021-33294
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) vi

In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.

NVD description · AI analysis pending
5.5<1% PoC
  • elfutils project elfutils
CVE-2023-33551
+1 in the same advisory: …33552
Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted er

Heap Buffer Overflow in the erofsfsck_dirent_iter function in fsck/main.c in erofs-utils v1.6 allows remote attackers to execute arbitrary code via a crafted erofs filesystem image.

NVD description · AI analysis pending
7.8<1% PoC
  • erofs-utils project erofs-utils
CVE-2018-25068
A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical.

A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fileresources/src/main/java/com/anrisoftware/globalpom/fileresourcemanager/FileResourceManagerProvider.java. The manipulation leads to insecure temporary file. The attack can be initiated remotely. Upgrading to version 4.5.1 is able to address this issue. The patch is identified as 77a820bac2f68e662ce261ecb050c643bd7ee560. It is recommended to upgrade the affected component. VDB-217570 is the identifier assigned to this vulnerability.

NVD description · AI analysis pending
9.8<1%
  • globalpom-utils project globalpom-utils
CVE-2021-4238
Randomly-generated alphanumeric strings contain significantly less entropy than expected.

Randomly-generated alphanumeric strings contain significantly less entropy than expected. The RandomAlphaNumeric and CryptoRandomAlphaNumeric functions always return strings containing at least one digit from 0 to 9. This significantly reduces the amount of entropy in short strings generated by these functions.

NVD description · AI analysis pending
9.11% PoC
  • goutils project goutils
CVE-2020-36566
Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

NVD description · AI analysis pending
9.11%
  • tar-utils project tar-utils
CVE-2021-4277
A vulnerability, which was classified as problematic, has been found in fredsmith utils.

A vulnerability, which was classified as problematic, has been found in fredsmith utils. This issue affects some unknown processing of the file screenshot_sync of the component Filename Handler. The manipulation leads to predictable from observable state. The name of the patch is dbab1b66955eeb3d76b34612b358307f5c4e3944. It is recommended to apply a patch to fix this issue. The identifier VDB-216749 was assigned to this vulnerability.

NVD description · AI analysis pending
5.3<1%
  • utils project utils
CVE-2021-34080
OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters prov

OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters provided to the createCertRequest() and the createCert() functions.

NVD description · AI analysis pending
9.83% PoC
  • ssl-utils project ssl-utils
CVE-2022-24884
ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify).

ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge signatures. Requiring multiple signatures from different public keys does not mitigate the issue: `ecdsa_verify_list_legacy()` will accept an arbitrary number of such forged signatures. Both the `ecdsautil verify` CLI command and the libecdsautil library are affected. The issue has been fixed in ecdsautils 0.4.1. All older versions of ecdsautils (including versions before the split into a library and a CLI utility) are vulnerable.

NVD description · AI analysis pending
7.51%
  • ecdsautils project ecdsautils
  • ecdsautils project fedora
  • ecdsautils project debian linux
CVE-2021-41269
cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them.

cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Versions up to 9.1.2 are susceptible to this vulnerability. Please note, that only projects using the @Cron annotation to validate untrusted Cron expressions are affected. The issue was patched and a new version was released. Please upgrade to version 9.1.6. There are no known workarounds known.

NVD description · AI analysis pending
9.84% PoC
  • cron-utils project cron-utils
CVE-2021-23396
All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function.

All versions of package lutils are vulnerable to Prototype Pollution via the main (merge) function.

NVD description · AI analysis pending
9.81% PoC
  • lutils project lutils
CVE-2021-26954
An issue was discovered in the qwutils crate before 0.3.1 for Rust.

An issue was discovered in the qwutils crate before 0.3.1 for Rust. When a Clone panic occurs, insert_slice_clone can perform a double drop.

NVD description · AI analysis pending
5.31% PoC
  • qwutils project qwutils
CVE-2020-26238
Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them.

Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.3, a template Injection vulnerability is present. This enables attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE) vulnerability. Only projects using the @Cron annotation to validate untrusted Cron expressions are affected. This issue was patched in version 9.1.3.

NVD description · AI analysis pending
8.14% PoC ×2
  • cron-utils project cron-utils
CVE-2020-7722
All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.

All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function.

NVD description · AI analysis pending
9.82% PoC
  • nodee-utils project nodee-utils
CVE-2020-7718
All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.

All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.

NVD description · AI analysis pending
9.82% PoC
  • gammautils project gammautils
CVE-2020-7703
All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.

All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function.

NVD description · AI analysis pending
9.82% PoC
  • nis-utils project nis-utils
CVE-2017-5333
+2 in the same advisory: …5332 …5331
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of se

Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.

NVD description · AI analysis pending
7.82%
  • icoutils project icoutils
  • icoutils project enterprise linux
  • icoutils project enterprise linux desktop
  • +1 more
CVE-2019-15657
In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.

In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.

NVD description · AI analysis pending
9.82%
  • eslint-utils project eslint-utils
CVE-2019-7665
+1 in the same advisory: …7664
In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf.

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes.

NVD description · AI analysis pending
5.51% PoC ×2
  • elfutils project elfutils
  • elfutils project debian linux
  • elfutils project ubuntu linux
  • +1 more
CVE-2019-7149
+3 in the same advisory: …7148 …7146 …7150
A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175.

A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by eu-nm.

NVD description · AI analysis pending
6.5
group max
2% PoC
  • elfutils project elfutils
  • elfutils project debian linux
CVE-2018-18520
+1 in the same advisory: …18521
An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174.

An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file before handling all inner entries. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file.

NVD description · AI analysis pending
6.5
group max
3% PoC
  • elfutils project elfutils
  • elfutils project debian linux
  • elfutils project ubuntu linux
  • +1 more
CVE-2018-18310
An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174.

An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by consider_notes.

NVD description · AI analysis pending
5.51% PoC
  • elfutils project elfutils
  • elfutils project debian linux
  • elfutils project enterprise linux desktop
  • +1 more
CVE-2018-16402
+1 in the same advisory: …16403
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other i

libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.

NVD description · AI analysis pending
9.8
group max
4% PoC
  • elfutils project elfutils
  • elfutils project debian linux
  • elfutils project enterprise linux desktop
  • +1 more
CVE-2018-16062
dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read)

dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.

NVD description · AI analysis pending
5.52%
  • elfutils project elfutils
  • elfutils project debian linux
  • elfutils project leap
  • +1 more
CVE-2018-10775
+2 in the same advisory: …10774 …10773
NULL pointer dereference in the _fields_add function in fields.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (a

NULL pointer dereference in the _fields_add function in fields.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by end2xml.

NVD description · AI analysis pending
6.52% PoC
  • bibutils project bibutils
CVE-2018-8769
elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported.

elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported.

NVD description · AI analysis pending
7.8<1% PoC
  • elfutils project elfutils
CVE-2017-17512
sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable, which all

sensible-browser in sensible-utils before 0.0.11 does not validate strings before launching the program specified by the BROWSER environment variable, which allows remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by a --proxy-pac-file argument.

NVD description · AI analysis pending
8.82% PoC
  • sensible-utils project sensible-utils
CVE-2017-5208
Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted execut

Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code.

NVD description · AI analysis pending
8.84%
  • icoutils project icoutils
  • icoutils project debian linux
  • icoutils project enterprise linux desktop
  • +1 more
CVE-2017-7611
+3 in the same advisory: …7612 …7610 …7613
The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application

The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.

NVD description · AI analysis pending
5.52% PoC
  • elfutils project elfutils
  • elfutils project debian linux
  • elfutils project ubuntu linux