Elfutils Project
Elfutils Project Elfutils: vulnerabilidades y CVE
Elfutils Project Elfutils tiene 33 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE33
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-1377 | Media (4.8) | 0.33% | — | 17 feb 2025 | A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to… |
| CVE-2025-1376 | Baja (2) | 0.31% | — | 17 feb 2025 | A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to… |
| CVE-2025-1372 | Media (4.8) | 0.35% | — | 17 feb 2025 | A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf.… |
| CVE-2025-1371 | Media (4.8) | 0.23% | — | 17 feb 2025 | A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to… |
| CVE-2025-1365 | Media (4.8) | 0.34% | — | 17 feb 2025 | A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The manipulation of the argument D/a leads… |
| CVE-2025-1352 | Baja (2.3) | 0.66% | — | 16 feb 2025 | A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of… |
| CVE-2024-25260 | Media (4) | 0.31% | — | 20 feb 2024 | elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c. |
| CVE-2020-21047 | Media (5.5) | 0.24% | — | 22 ago 2023 | The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bounds write (CWE-787), off-by-one error… |
| CVE-2021-33294 | Media (5.5) | 0.29% | — | 18 jul 2023 | In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file. |
| CVE-2019-7665 | Media (5.5) | 1.3% | — | 9 feb 2019 | In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program… |
| CVE-2019-7664 | Media (5.5) | 1.0% | — | 9 feb 2019 | In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program… |
| CVE-2019-7150 | Media (5.5) | 1.4% | — | 29 ene 2019 | An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core… |
| CVE-2019-7149 | Media (6.5) | 2.1% | — | 29 ene 2019 | A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated… |
| CVE-2019-7148 | Media (6.5) | 1.6% | — | 29 ene 2019 | An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174. Remote attackers could leverage this vulnerability to cause a denial-of-service via… |
| CVE-2019-7146 | Media (5.5) | 1.5% | — | 29 ene 2019 | In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted elf file, as… |
| CVE-2018-18521 | Media (5.5) | 1.8% | — | 19 oct 2018 | Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by… |
| CVE-2018-18520 | Media (6.5) | 2.8% | — | 19 oct 2018 | An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to support ar files inside ar files, handle_ar in size.c closes the outer ar file… |
| CVE-2018-18310 | Media (5.5) | 1.4% | — | 15 oct 2018 | An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a… |
| CVE-2018-16403 | Media (5.5) | 1.1% | — | 3 sept 2018 | libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf_hasattr.c, leading to a heap-based buffer over-read and an application crash. |
| CVE-2018-16402 | Crítica (9.8) | 3.7% | — | 3 sept 2018 | libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice. |
| CVE-2018-16062 | Media (5.5) | 1.6% | — | 29 ago 2018 | dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file. |
| CVE-2018-8769 | Alta (7.8) | 0.84% | — | 18 mar 2018 | elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported. |
| CVE-2017-7613 | Media (5.5) | 1.7% | — | 9 abr 2017 | elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file. |
| CVE-2017-7612 | Media (5.5) | 1.8% | — | 9 abr 2017 | The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
| CVE-2017-7611 | Media (5.5) | 1.8% | — | 9 abr 2017 | The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
| CVE-2017-7610 | Media (5.5) | 1.8% | — | 9 abr 2017 | The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
| CVE-2017-7609 | Media (5.5) | 1.6% | — | 9 abr 2017 | elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file. |
| CVE-2017-7608 | Media (5.5) | 2.1% | — | 9 abr 2017 | The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
| CVE-2017-7607 | Media (5.5) | 1.7% | — | 9 abr 2017 | The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file. |
| CVE-2016-10255 | Media (5.5) | 1.7% | — | 23 mar 2017 | The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a… |