Skip to main content

Vendor/product archive

gnu / bash CVEs

Beta · best-effort

17 CVEs tagged to gnu / bash5 Critical, 8 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2012-6711

Published Jun 18, 2019

A heap-based buffer overflow exists in GNU Bash before 4.3 when wide characters, not supported by the current locale set in the LC_CTYPE environment variable, are printed through…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2016-0634

Published Aug 28, 2017

The expansion of '\h' in the prompt string in bash 4.3 allows remote authenticated users to execute arbitrary code via shell metacharacters placed in 'hostname' of a machine.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5932

Published Mar 27, 2017

The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution meta…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7543

Published Jan 19, 2017

Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6278

Published Sep 30, 2014

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands vi…

CVSS 8.8 · High
evidence mentions
8
Buzz score
56.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2014-7187

Published Sep 28, 2014

Off-by-one error in the read_token_word function in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and…

CVSS 10.0 · Critical
evidence mentions
8
Buzz score
30.0
Vendor/product tagsBeta · best-effort

CVE-2014-7186

Published Sep 28, 2014

The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial of service (out-of-bounds array access and application crash…

CVSS 10.0 · Critical
evidence mentions
9
Buzz score
31.0
Vendor/product tagsBeta · best-effort

CVE-2014-6277

Published Sep 27, 2014

GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cau…

CVSS 10.0 · Critical
evidence mentions
9
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2012-3410

Published Aug 27, 2012

Stack-based buffer overflow in lib/sh/eaccess.c in GNU Bash before 4.2 patch 33 might allow local users to bypass intended restricted shell access via a long filename in /dev/fd,…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0002

Published Jan 14, 2010

The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIONS, which allows loc…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-1999-0491

Published Apr 20, 1999

The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1