Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Elfutils Project Subscribe
Filtered by product Elfutils
Total 24 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10255 1 Elfutils Project 1 Elfutils 2018-06-06 4.3 MEDIUM 5.5 MEDIUM
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted (1) sh_off or (2) sh_size ELF header value, which triggers a memory allocation failure.
CVE-2016-10254 1 Elfutils Project 1 Elfutils 2018-06-06 4.3 MEDIUM 5.5 MEDIUM
The allocate_elf function in common.h in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a crafted ELF file, which triggers a memory allocation failure.
CVE-2014-0172 1 Elfutils Project 1 Elfutils 2017-06-30 6.8 MEDIUM N/A
Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed compressed debug section in an ELF file, which triggers a heap-based buffer overflow.
CVE-2014-9447 1 Elfutils Project 1 Elfutils 2015-04-17 6.4 MEDIUM N/A
Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program.