Vulnerabilidades em GNU

130 resultados
Análise Vexday

O ecossistema GNU apresenta 88 CVEs catalogadas, com uma taxa de exploração ativa 2,5 vezes acima da média geral do catálogo CISA KEV — sinal de que, apesar do volume relativamente contido, as vulnerabilidades que surgem tendem a atrair atenção de agentes maliciosos de forma desproporcional. O ponto de maior atenção imediata é CVE-2026-24061, atualmente em exploração ativa e com EPSS de 0,9887, indicando probabilidade extremamente elevada de exploração observada ou iminente. A falha mais recorrente é CWE-119 (escrita/leitura fora dos limites de buffer), padrão que historicamente facilita execução de código arbitrário e elevação de privilégios. Com 10 CVEs acompanhadas de PoC pública e 13 surgidas nos últimos 90 dias, equipes de segurança devem monitorar ativamente o pipeline de patches e priorizar a mitigação das falhas críticas e exploráveis antes de avançar para o restante do portfólio.

CVE-2025-5001MEDIUMGNU PSPP pspp-convert.c calloc integer overflowEPSS 0.3%CVE-2025-7545MEDIUMGNU Binutils objcopy.c copy_section heap-based overflowEPSS 0.3%CVE-2025-11083MEDIUMGNU Binutils Linker elfcode.h elf_swap_shdr heap-based overflowEPSS 0.3%CVE-2025-11082MEDIUMGNU Binutils Linker elf-eh-frame.c _bfd_elf_parse_eh_frame heap-based overflowEPSS 0.3%CVE-2025-11495MEDIUMGNU Binutils Linker elf64-x86-64.c elf_x86_64_relocate_section heap-based overflowEPSS 0.2%CVE-2025-1371MEDIUMGNU elfutils eu-read readelf.c handle_dynamic_symtab null pointer dereferenceEPSS 0.2%CVE-2025-8224MEDIUMGNU Binutils BFD Library elf.c bfd_elf_get_str_section null pointer dereferenceEPSS 0.2%CVE-2025-8225MEDIUMGNU Binutils DWARF Section dwarf.c process_debug_info memory leakEPSS 0.2%CVE-2025-11413MEDIUMGNU Binutils Linker elflink.c elf_link_add_object_symbols out-of-boundsEPSS 0.2%CVE-2025-8746MEDIUMGNU libopts __strstr_sse2 memory corruptionEPSS 0.2%CVE-2025-11494MEDIUMGNU Binutils Linker elfxx-x86.c _bfd_x86_elf_late_size_sections out-of-boundsEPSS 0.2%CVE-2026-40467MEDIUMUse after free in gawkEPSS 0.2%CVE-2025-11412MEDIUMGNU Binutils Linker elflink.c bfd_elf_gc_record_vtentry out-of-boundsEPSS 0.2%CVE-2025-11414MEDIUMGNU Binutils Linker elflink.c get_link_hash_entry out-of-boundsEPSS 0.2%CVE-2025-61662HIGHGrub2: missing unregister call for gettext command may lead to use-after-freeEPSS 0.2%CVE-2025-11081MEDIUMGNU Binutils objdump.c dump_dwarf_section out-of-boundsEPSS 0.2%CVE-2026-40468LOWHeap buffer overflow in gawkEPSS 0.2%CVE-2025-6141MEDIUMGNU ncurses parse_entry.c postprocess_termcap stack-based overflowEPSS 0.2%CVE-2025-61661MEDIUMGrub2: grub2: out-of-bounds write via malicious usb deviceEPSS 0.2%CVE-2026-32772LOWtelnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.EPSS 0.2%