Skip to main content

Vendor/product archive

elfutils_project / elfutils CVEs

Beta · best-effort

33 CVEs tagged to elfutils_project / elfutils1 Critical, 1 High, 29 Medium, 2 Low, 0 Unrated.

CVE-2025-1377

Published Feb 17, 2025

A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component e…

CVSS 4.8 · Medium
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-1376

Published Feb 17, 2025

A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component…

CVSS 2.0 · Low
evidence mentions
9
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2025-1372

Published Feb 17, 2025

A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the fil…

CVSS 4.8 · Medium
evidence mentions
8
Buzz score
33.5
Vendor/product tagsBeta · best-effort

CVE-2025-1371

Published Feb 17, 2025

A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the comp…

CVSS 4.8 · Medium
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-1365

Published Feb 17, 2025

A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The…

CVSS 4.8 · Medium
evidence mentions
7
Buzz score
32.3
Vendor/product tagsBeta · best-effort

CVE-2025-1352

Published Feb 16, 2025

A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the co…

CVSS 2.3 · Low
evidence mentions
9
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2024-25260

Published Feb 20, 2024

elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-21047

Published Aug 22, 2023

The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerability caused by application crashes due to out-of-bou…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-33294

Published Jul 18, 2023

In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial of service (infinite loop) via crafted file.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7665

Published Feb 9, 2019

In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault le…

CVSS 5.5 · Medium

CVE-2019-7664

Published Feb 9, 2019

In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation faul…

CVSS 5.5 · Medium

CVE-2019-7150

Published Jan 29, 2019

An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking…

CVSS 5.5 · Medium

CVE-2019-7148

Published Jan 29, 2019

An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174. Remote attackers could leverage this vulnerabil…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7146

Published Jan 29, 2019

In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl. Remote attackers could leverage this vulnerability to cause a denial-of-s…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-16403

Published Sep 3, 2018

libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasattr in dwarf_hasattr.c, leading to a heap-based buf…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8769

Published Mar 18, 2018

elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2