Vulnerabilidades em GNU

130 resultados
Análise Vexday

O ecossistema GNU apresenta 88 CVEs catalogadas, com uma taxa de exploração ativa 2,5 vezes acima da média geral do catálogo CISA KEV — sinal de que, apesar do volume relativamente contido, as vulnerabilidades que surgem tendem a atrair atenção de agentes maliciosos de forma desproporcional. O ponto de maior atenção imediata é CVE-2026-24061, atualmente em exploração ativa e com EPSS de 0,9887, indicando probabilidade extremamente elevada de exploração observada ou iminente. A falha mais recorrente é CWE-119 (escrita/leitura fora dos limites de buffer), padrão que historicamente facilita execução de código arbitrário e elevação de privilégios. Com 10 CVEs acompanhadas de PoC pública e 13 surgidas nos últimos 90 dias, equipes de segurança devem monitorar ativamente o pipeline de patches e priorizar a mitigação das falhas críticas e exploráveis antes de avançar para o restante do portfólio.

CVE-2026-28372HIGHtelnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added EPSS 0.4%CVE-2026-40469MEDIUMHeap buffer overflow in gawkEPSS 0.4%CVE-2025-1372MEDIUMGNU elfutils eu-readelf readelf.c print_string_section buffer overflowEPSS 0.3%CVE-2025-1365MEDIUMGNU elfutils eu-readelf readelf.c process_symtab buffer overflowEPSS 0.3%CVE-2026-9605MEDIUMGNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflowEPSS 0.3%CVE-2025-47816LOWlibpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause an spvxml-helpers.c spvxml_parse_attributes out-of-bounds read, related tEPSS 0.3%CVE-2026-53910LOWHeap-based Buffer Overflow in GNU diffutilsEPSS 0.3%CVE-2026-71391MEDIUMOff-by-One Error in GNU Emacs for AndroidEPSS 0.3%CVE-2025-1377MEDIUMGNU elfutils eu-strip strip.c gelf_getsymshndx denial of serviceEPSS 0.3%CVE-2025-1376LOWGNU elfutils eu-strip elf_strptr.c elf_strptr denial of serviceEPSS 0.3%CVE-2026-40553MEDIUMStack-based buffer overflow in gawkEPSS 0.3%CVE-2025-47814MEDIUMlibpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from spv_EPSS 0.3%CVE-2025-47815MEDIUMlibpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a heap-based buffer overflow in inflate_read (called indirectly from zip_EPSS 0.3%CVE-2026-56968LOWGNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory diEPSS 0.3%CVE-2025-3198MEDIUMGNU Binutils objdump bucomm.c display_info memory leakEPSS 0.3%CVE-2025-5244MEDIUMGNU Binutils ld elflink.c elf_gc_sweep memory corruptionEPSS 0.3%CVE-2026-71394MEDIUMHeap Use of Uninitialized Memory in GNU Emacs for AndroidEPSS 0.3%CVE-2025-5245MEDIUMGNU Binutils objdump debug.c debug_type_samep memory corruptionEPSS 0.3%CVE-2025-11840MEDIUMGNU Binutils ldmisc.c vfinfo out-of-boundsEPSS 0.3%CVE-2025-11839MEDIUMGNU Binutils prdbg.c tg_tag_type return valueEPSS 0.3%