threat
engine
.sh
Back
·
··:··
Home
/
Product
/
elfutils project elfutils
Product
elfutils project elfutils
33 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2025-1377
all versions
A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_g
3.3
LOW
CVE-2025-1376
all versions
A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in t
2.5
LOW
CVE-2025-1372
all versions
A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function
5.3
MEDIUM
CVE-2025-1371
all versions
A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle
3.3
LOW
CVE-2025-1365
all versions
A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of th
5.3
MEDIUM
CVE-2025-1352
all versions
A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_t
5.0
MEDIUM
CVE-2024-25260
all versions
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
4.0
MEDIUM
CVE-2020-21047
all versions
The libcpu component which is used by libasm of elfutils version 0.177 (git 47780c9e), suffers from denial-of-service vulnerabilit
5.5
MEDIUM
CVE-2021-33294
all versions
In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a denial
5.5
MEDIUM
CVE-2019-7665
all versions
In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A cr
5.5
MEDIUM
CVE-2019-7664
all versions
In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow ch
5.5
MEDIUM
CVE-2019-7150
all versions
An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.
5.5
MEDIUM
CVE-2019-7149
all versions
A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A cr
6.5
MEDIUM
CVE-2019-7148
all versions
An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174
6.5
MEDIUM
CVE-2019-7146
all versions
In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl. Remote attackers could l
5.5
MEDIUM
CVE-2018-18521
all versions
Divide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a
5.5
MEDIUM
CVE-2018-18520
<= 0.174
An Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is int
6.5
MEDIUM
CVE-2018-18310
<= 0.174
An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vu
5.5
MEDIUM
CVE-2018-16403
all versions
libdw in elfutils 0.173 checks the end of the attributes list incorrectly in dwarf_getabbrev in dwarf_getabbrev.c and dwarf_hasatt
5.5
MEDIUM
CVE-2018-16402
all versions
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or pos
9.8
CRITICAL
CVE-2018-16062
< 0.174
dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service
5.5
MEDIUM
CVE-2018-8769
all versions
elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is u
7.8
HIGH
CVE-2017-7613
all versions
elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to
5.5
MEDIUM
CVE-2017-7612
all versions
The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffe
5.5
MEDIUM
CVE-2017-7611
all versions
The check_symtab_shndx function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based bu
5.5
MEDIUM
CVE-2017-7610
all versions
The check_group function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer ov
5.5
MEDIUM
CVE-2017-7609
all versions
elf_compress.c in elfutils 0.168 does not validate the zlib compression factor, which allows remote attackers to cause a denial of
5.5
MEDIUM
CVE-2017-7608
all versions
The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of serv
5.5
MEDIUM
CVE-2017-7607
all versions
The handle_gnu_hash function in readelf.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffe
5.5
MEDIUM
CVE-2016-10255
<= 0.167
The __libelf_set_rawdata_wrlock function in elf_getdata.c in elfutils before 0.168 allows remote attackers to cause a denial of se
5.5
MEDIUM
CVE-2016-10254
<= 0.167
The allocate_elf function in common.h in elfutils before 0.168 allows remote attackers to cause a denial of service (crash) via a
5.5
MEDIUM
CVE-2014-9447
all versions
Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote
CVE-2014-0172
all versions
Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly t
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin