Vulnerabilidades em GNU

130 resultados
Análise Vexday

O ecossistema GNU apresenta 88 CVEs catalogadas, com uma taxa de exploração ativa 2,5 vezes acima da média geral do catálogo CISA KEV — sinal de que, apesar do volume relativamente contido, as vulnerabilidades que surgem tendem a atrair atenção de agentes maliciosos de forma desproporcional. O ponto de maior atenção imediata é CVE-2026-24061, atualmente em exploração ativa e com EPSS de 0,9887, indicando probabilidade extremamente elevada de exploração observada ou iminente. A falha mais recorrente é CWE-119 (escrita/leitura fora dos limites de buffer), padrão que historicamente facilita execução de código arbitrário e elevação de privilégios. Com 10 CVEs acompanhadas de PoC pública e 13 surgidas nos últimos 90 dias, equipes de segurança devem monitorar ativamente o pipeline de patches e priorizar a mitigação das falhas críticas e exploráveis antes de avançar para o restante do portfólio.

CVE-2026-41991LOWPredictable Temporary File in GNU gzipEPSS 0.2%CVE-2026-15182MEDIUMGNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflowEPSS 0.2%CVE-2026-15520MEDIUMGNU LibreDWG R2004 Section Decompression decode.c decompress_R2004_section heap-based overflowEPSS 0.2%CVE-2025-7546MEDIUMGNU Binutils elf.c bfd_elf_set_group_contents out-of-bounds writeEPSS 0.2%CVE-2026-90828MEDIUMGNU Binutils ELF Orphan Section ldelf.c elf_orphan_compatible null pointer dereferenceEPSS 0.2%CVE-2025-47229LOWlibpspp-core.a in GNU PSPP through 2.0.1 allows attackers to cause a denial of service (var_set_leave_quiet assertion failure and applicatioEPSS 0.2%CVE-2026-9504MEDIUMGNU LibreDWG Dwggrep Utility dwggrep.c bit_convert_TU out-of-boundsEPSS 0.2%CVE-2026-15184MEDIUMGNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereferenceEPSS 0.2%CVE-2026-56288MEDIUMNULL Pointer Dereference in GNU patchEPSS 0.2%CVE-2026-56289MEDIUMLoop with Unreachable Exit Condition in GNU patchEPSS 0.2%CVE-2026-90829MEDIUMGNU Binutils SHT_GROUP Section elf.c bfd_elf_set_group_contents null pointer dereferenceEPSS 0.2%CVE-2025-5898MEDIUMGNU PSPP pspp-convert.c parse_variables_option out-of-bounds writeEPSS 0.2%CVE-2025-5899MEDIUMGNU PSPP pspp-convert.c parse_variables_option free of memory not on the heapEPSS 0.2%CVE-2025-8736MEDIUMGNU cflow Lexer c.c yylex buffer overflowEPSS 0.2%CVE-2025-48188LOWlibpspp-core.a in GNU PSPP through 2.0.1 has an incorrect call from fill_buffer (in data/encrypted-file.c) to the Gnulib rijndaelDecrypt funEPSS 0.2%CVE-2026-90831MEDIUMGNU Binutils ELF String Table elf-strtab.c _bfd_elf_strtab_delref memory corruptionEPSS 0.2%CVE-2026-90622MEDIUMGNU libredwg Layer Encoding dwg.spec DWG_TABLE null pointer dereferenceEPSS 0.2%CVE-2026-90830MEDIUMGNU Binutils Section Merge merge.c _bfd_write_merged_section null pointer dereferenceEPSS 0.2%CVE-2026-56389MEDIUMArbitrary Command Execution in GNU BisonEPSS 0.2%CVE-2026-66484MEDIUMPath Traversal in GNU cpioEPSS 0.2%