Vulnerabilidades em GNU

106 resultados
Análise Vexday

O ecossistema GNU apresenta 88 CVEs catalogadas, com uma taxa de exploração ativa 2,5 vezes acima da média geral do catálogo CISA KEV — sinal de que, apesar do volume relativamente contido, as vulnerabilidades que surgem tendem a atrair atenção de agentes maliciosos de forma desproporcional. O ponto de maior atenção imediata é CVE-2026-24061, atualmente em exploração ativa e com EPSS de 0,9887, indicando probabilidade extremamente elevada de exploração observada ou iminente. A falha mais recorrente é CWE-119 (escrita/leitura fora dos limites de buffer), padrão que historicamente facilita execução de código arbitrário e elevação de privilégios. Com 10 CVEs acompanhadas de PoC pública e 13 surgidas nos últimos 90 dias, equipes de segurança devem monitorar ativamente o pipeline de patches e priorizar a mitigação das falhas críticas e exploráveis antes de avançar para o restante do portfólio.

CVE-2026-24061CRITICALtelnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.EPSS 97.9%KEVCVE-2026-32746CRITICALtelnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_EPSS 23.7%CVE-2019-1010180GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and PoEPSS 2.6%CVE-2015-0837The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timinEPSS 2.0%CVE-2022-2469LOWGNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API clientEPSS 1.4%CVE-2025-43919MEDIUMGNU Mailman 2.1.39, as bundled in cPanel (and WHM), allows unauthenticated attackers to read arbitrary files via ../ directory traversal at EPSS 1.3%CVE-2025-1153LOWGNU Binutils format.c bfd_set_format memory corruptionEPSS 1.3%CVE-2023-2789LOWGNU cflow parser.c parse_variable_declaration denial of serviceEPSS 1.2%CVE-2024-10524MEDIUMGNU Wget is vulnerable to an SSRF attack when accessing partially-user-controlled shorthand URLsEPSS 1.1%CVE-2023-0687MEDIUMA vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of tEPSS 1.1%CVE-2025-1178MEDIUMGNU Binutils ld libbfd.c bfd_putl64 memory corruptionEPSS 0.8%CVE-2023-4039MEDIUMGCC's-fstack-protector fails to guard dynamically-sized local variables on AArch64EPSS 0.8%CVE-2024-56737HIGHGNU GRUB (aka GRUB2) through 2.12 has a heap-based buffer overflow in fs/hfs.c via crafted sblock data in an HFS filesystem.EPSS 0.7%CVE-2025-0840MEDIUMGNU Binutils objdump.c disassemble_bytes stack-based overflowEPSS 0.7%CVE-2025-1181LOWGNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec memory corruptionEPSS 0.7%CVE-2025-1180LOWGNU Binutils ld elf-eh-frame.c _bfd_elf_write_section_eh_frame memory corruptionEPSS 0.7%CVE-2025-1176LOWGNU Binutils ld elflink.c _bfd_elf_gc_mark_rsec heap-based overflowEPSS 0.7%CVE-2025-1147LOWGNU Binutils nm nm.c internal_strlen buffer overflowEPSS 0.7%CVE-2025-1352LOWGNU elfutils eu-readelf libdw_alloc.c __libdw_thread_tail memory corruptionEPSS 0.7%CVE-2025-1148LOWGNU Binutils ld ldelfgen.c link_order_scan memory leakEPSS 0.6%