Vendor
Multiple Vulnerabilities in GNU C Library
1 TTPMultiple vulnerabilities in the GNU C Library (glibc) allow a local attacker to perform privilege escalation or trigger a denial of service condition on affected Linux-based systems.
Multiple Vulnerabilities in GNU Binutils
1 TTPThe GNU binutils package contains multiple vulnerabilities that allow a local attacker to cause a Denial of Service condition or disclose sensitive information by processing malformed object files.
Stack-Based Buffer Overflow in GNU libextractor
1 TTP 1 CVEGNU libextractor versions prior to 1.15 contain a stack-based buffer overflow in the process_star_office function that can be triggered by malicious OLE2 stream data to cause application crashes.
Authentication Bypass in GNU Inetutils Telnet Daemon (CVE-2026-24061)
1 rule 2 TTPs 1 CVEAn authentication bypass vulnerability in GNU Inetutils telnetd (CVE-2026-24061) allows unauthenticated remote attackers to gain root access via a malicious USER parameter.
Denial of Service Vulnerability in libtasn1
1 CVEA vulnerability in the libtasn1 library tracked as CVE-2024-11111 allows a remote, anonymous attacker to cause a Denial of Service condition, potentially impacting applications that rely on the library for ASN.1 structure processing.
Remote Code Execution in GNU Debugger (GDB) via Malicious STABS Debug Data
1 TTP 1 CVEA memory corruption vulnerability in GDB's STABS parser allows an attacker to achieve arbitrary code execution by providing a crafted ELF binary containing malicious debug sections.
Privilege Escalation in Gnu C Library via CVE-2025-4802
1 TTP 1 CVEA local privilege escalation vulnerability (CVE-2025-4802) in Gnu C Library (glibc) versions 2.27-2.38 allows attackers to gain root access by exploiting unsanitized LD_LIBRARY_PATH in statically linked setuid binaries.
Multiple Vulnerabilities in GNU Screen
1 TTPGNU screen contains multiple vulnerabilities that enable a local attacker to perform privilege escalation, data manipulation, or unauthorized information disclosure.
Integer Overflow in GNU Emacs PBM/PPM/PGM Image Loader (CVE-2026-77219)
1 TTP 1 CVEGNU Emacs versions prior to 31.0.91 are susceptible to an integer overflow vulnerability in the PBM/PPM/PGM image loader, potentially leading to heap memory disclosure.
Denial of Service Vulnerability in GNU C Library
1 TTP 1 CVEA local attacker can exploit a vulnerability in the GNU C Library (glibc) to cause application crashes or service instability, resulting in a Denial of Service.
Multiple Vulnerabilities in GNU Emacs
1 TTPGNU Emacs is impacted by multiple vulnerabilities that can be leveraged by an attacker to facilitate information disclosure, arbitrary code execution, and denial-of-service.
Multiple Vulnerabilities in GNU cpio
1 TTP 1 CVEMultiple vulnerabilities in the GNU cpio utility allow unauthenticated remote attackers to bypass security controls, cause denial of service, or manipulate data during file extraction.
CVE-2026-18220: Out-of-Bounds Write in GNU Binutils BFD Library Leading to Arbitrary Code Execution
1 TTP 1 CVEAn out-of-bounds write vulnerability, CVE-2026-18220, exists in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils, allowing attackers to achieve arbitrary code execution via a specially crafted ELF/DLX object file processed by BFD-consuming tools.
binutils: Vulnerability Enables Denial of Service and Data Disclosure
2 TTPsA local attacker can exploit a vulnerability in binutils to cause a Denial of Service condition and disclose sensitive data.
CVE-2026-63825: gcov Utility Concurrent Access Crash Vulnerability
1 CVEA vulnerability, CVE-2026-63825, has been disclosed for the 'gcov' utility, which is part of the GNU Compiler Collection, involving concurrent access crashes fixed by using atomic counter updates to ensure thread-safe operations, potentially leading to system instability or denial of service due to race conditions during data access.
Qilin Ransomware Claims New Victim in Agriculture and Food Production Sector
2 rules 13 TTPs 5 CVEs 178 IOCsThe Qilin ransomware group, active since July 2022 and utilizing Golang, has claimed a new victim, Danone (International Delights) in the US Agriculture and Food Production sector, employing double extortion tactics involving data encryption and threatened data release.
CVE-2026-9605 Heap-Based Buffer Overflow in GNU libredwg
2 rules 1 CVEA heap-based buffer overflow vulnerability (CVE-2026-9605) exists in GNU libredwg up to version 0.13.4.8160 within the bit_read_RC function of the Dwgbmp Utility, potentially allowing a remote attacker to execute arbitrary code.
CVE-2026-5260: libgnutls Heap Overread via Short Premaster Secret
2 rules 1 CVEA remote attacker can trigger a heap overread in libgnutls by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, potentially leading to information disclosure.
GNU libc Vulnerabilities Allow DNS Response Manipulation
2 rules 1 TTPA remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to manipulate DNS responses, potentially leading to redirection to malicious sites.
GNU InetUtils Multiple Vulnerabilities Allow Code Execution and Information Disclosure
2 rules 2 TTPsMultiple vulnerabilities in GNU InetUtils allow a remote attacker to execute arbitrary code and disclose sensitive information.
GNU InetUtils Vulnerabilities Prior to 2.8
2 rulesGNU released a security advisory addressing critical vulnerabilities in GNU InetUtils versions prior to 2.8, prompting users to apply necessary updates.
Multiple Vulnerabilities in GNU libc
2 rules 3 TTPs 5 CVEsA remote, anonymous attacker can exploit multiple vulnerabilities in GNU libc to execute arbitrary program code, cause a denial-of-service condition, or disclose sensitive information.
GNU C Library iconv() Function Assertion Failure (CVE-2026-4046)
2 rules 1 TTP 3 CVEsA vulnerability in the iconv() function of the GNU C Library (versions 2.43 and earlier) can cause a crash due to an assertion failure when handling IBM1390 or IBM1399 character sets, potentially leading to remote application denial-of-service.
GNUTLS RSA-PSK Authentication Bypass Vulnerability (CVE-2026-42010)
2 rules 1 TTP 1 CVEA vulnerability in GNUTLS (CVE-2026-42010) allows a remote attacker to bypass authentication on servers configured with RSA-PSK by sending a specially crafted username containing a NUL character, leading to unauthorized access.
GNU telnetd Buffer Overflow Vulnerability (CVE-2026-32746)
3 rules 2 TTPs 1 CVEA critical buffer overflow vulnerability exists in GNU telnetd (CVE-2026-32746), potentially allowing remote code execution on affected Linux systems.