Uclibc-ng Project
Uclibc-ng Project Uclibc-ng: vulnerabilidades y CVE
Uclibc-ng Project Uclibc-ng tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-29503 | Crítica (9.8) | 1.3% | — | 29 sept 2022 | A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger… |
| CVE-2022-30295 | Media (6.5) | 12% | — | 6 may 2022 | uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2. |
| CVE-2021-27419 | Crítica (9.8) | 1.7% | — | 3 may 2022 | uClibc-ng versions prior to 1.0.37 are vulnerable to integer wrap-around in functions malloc-simple. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a… |
| CVE-2021-43523 | Crítica (9.6) | 3.1% | — | 10 nov 2021 | In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong… |
| CVE-2016-2225 | Alta (7.5) | 2.5% | — | 24 mar 2017 | The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet. |
| CVE-2016-2224 | Alta (7.5) | 2.8% | — | 24 mar 2017 | The __decode_dotted function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via vectors involving compressed items in a reply. |
| CVE-2016-6264 | Alta (7.5) | 2.7% | — | 27 ene 2017 | Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the memset function. |