Skip to main content

CVE detail

CVE-2014-7187

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via deeply nested for loops, aka the "word_lineno" issue.

CVSS 10.0 · CriticalBuzz score 30.0

Buzz score

Why this CVE is surfacing

Buzz score total 30.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 22.0 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Mention score
22.0
8 evidence mentions in the snapshot
Diversity score
8.0
3 sources across 1 categories
KEV score
0.0
No KEV entry observed
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
8 source links · newest first
  • Top Cybersecurity Headlines of 2014SecurityWeek

    Data breaches, dangerous vulnerabilities and more dominated the headlines this year in cybersecurity.

    newswww.securityweek.comDec 30, 2014, 10:10 PM
  • It appears that 2014 will be remembered in the IT industry for several severe and wide-reaching server-side vulnerabilities. In April, a serious flaw ( CVE-2014-0160 ) in the widely-used OpenSSL encryption software that protects website traffic shook the industry (a.k.a. Heartbleed), leaving hundreds of thousands of systems open to attacks from cybercriminals. More than six months later, thousands of websites and devices still remain vulnerable . In September, multiple critical vulnerabilities ( CVE-2014-6271, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187, CVE-2014-6277 and CVE 2014-6278 ) were reported in the GNU Bourne-Again Shell (Bash), the common command-line shell used in many Linux / UNIX operating systems and Apple’s Mac OS X. The flaws could allow an attacker to remotely execute shell commands by attaching malicious code in environment variables used by the operating system. Similar to Heartbleed, these flaws affect a broad range of systems, including but not limited to Apache…

    newswww.securityweek.comNov 5, 2014, 3:18 PM
  • The GNU Bash vulnerability dubbed ShellShock affects a wide range of software solutions, including some industrial products developed by the German engineering and electronics giant Siemens.

    newswww.securityweek.comOct 8, 2014, 6:47 PM
  • The security researcher Michal Zalewski revealed the details of other two additional bugs he discovered in the Bourne Again Shell after the Bash Bug case. IT community worldwide has been shocked by the discovery of the Bash Bug flaw, a vulnerability that was present in the popular Bash component for more than two decades. While principal […]

    newssecurityaffairs.comOct 5, 2014, 1:28 PM
  • Joining several major tech companies, VMware has started rolling out software updates that address the recently discovered GNU Bash vulnerability dubbed ShellShock.

    newswww.securityweek.comOct 2, 2014, 1:41 PM
  • Ever since the existence of the GNU Bash flaw ( Shellshock ) came to light last week, threat actors have been searching for vulnerable machines that they can exploit for various purposes, Incapsula said on Monday.

    newswww.securityweek.comSep 30, 2014, 9:42 AM
  • The number of attempts by hackers to compromise computers through the Shellshock vulnerability is rising, but companies have options for defending against attackers. Shellshock is the name given to a set of at least six vulnerabilities in GNU Bash, the default command shell found in Linux, Unix and Mac OS X. The flaws in Bash, […]

    newswww.csoonline.comSep 30, 2014, 12:58 AM
  • From Thursday on, several security firms reported a drastic uptick in the number of attacks that leverage the recently disclosed vulnerability in GNU Bash (CVE-2014-6271), widely known as Shellshock. On Friday, AlienVault labs reported that the flaw was being used by two attackers to install two different pieces of malware on the victim system. One […]

    newswww.csoonline.comSep 29, 2014, 11:00 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence
  • CVE-2022-3715

    A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems.

    CVSS 7.8 · High
  • CVE-2012-6711

    A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through…

    CVSS 7.0 · High
  • CVE-2014-7186

    The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash…

    CVSS 10.0 · Critical
    9 mentions
  • CVE-2012-3410

    Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd,…

    CVSS 4.6 · Medium
  • CVE-2026-51251

    Schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::decode() function of the MP3 decoder due to missing size validation on untrusted mainDataB…

    CVSS 7.5 · High
    2 mentions
  • CVE-2026-64771

    A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A…

    CVSS 9.8 · Critical
    6 mentions