GNU / Bash
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-3715 | bash: a heap-buffer-overflow in valid_parameter_transform | HIGH | 7.8 | Jan 5, 2023 |
| CVE-2019-18276 | bash: when effective UID is not equal to its real UID the saved UID is not dropped | HIGH | 7.8 | Nov 28, 2019 |
| CVE-2012-6711 | bash: heap-based buffer overflow during echo of unsupported characters | HIGH | 7.8 | Jun 18, 2019 |
| CVE-2019-9924 | bash: BASH_CMD is writable in restricted bash shells | HIGH | 7.8 | Mar 22, 2019 |
| CVE-2016-0634 | bash: Arbitrary code execution via malicious hostname | HIGH | 7.5 | Aug 28, 2017 |
| CVE-2017-5932 | bash: Code execution in bash autocompletion | HIGH | 7.8 | Mar 27, 2017 |
| CVE-2016-9401 | bash: popd controlled free | MEDIUM | 6.2 | Jan 23, 2017 |
| CVE-2016-7543 | bash: Specially crafted SHELLOPTS+PS4 variables allows command substitution | HIGH | 8.4 | Jan 19, 2017 |
| CVE-2014-6278 KEV | bash: incorrect parsing of function definitions with nested command substitutions | HIGH | 8.8 | Sep 30, 2014 |
| CVE-2014-7187 | bash: off-by-one error in deeply nested flow control constructs | HIGH | 10.0 | Sep 28, 2014 |
| CVE-2014-7186 | bash: parser can allow out-of-bounds memory access while handling redir_stack | HIGH | 10.0 | Sep 28, 2014 |
| CVE-2014-6277 | bash: uninitialized here document closing delimiter pointer use | HIGH | 10.0 | Sep 27, 2014 |
| CVE-2014-7169 KEV | bash: code execution via specially-crafted environment (Incomplete fix for CVE-2014-6271) | CRITICAL | 9.8 | Sep 25, 2014 |
| CVE-2014-6271 KEV | bash: specially-crafted environment variables can be used to inject shell commands | CRITICAL | 9.8 | Sep 24, 2014 |
| CVE-2012-3410 | bash: Stack-based buffer overflow (crash) when expanding /dev/fd file names | MEDIUM | 4.6 | Aug 27, 2012 |
| CVE-2010-0002 | The /etc/profile.d/60alias.sh script in the Mandriva bash package for Bash 2.05b, 3.0, 3.2, 3.2.48, and 4.0 enables the --show-control-chars option in LS_OPTIO… | LOW | 2.1 | Jan 14, 2010 |
| CVE-1999-0491 | The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute. | MEDIUM | 4.6 | Jun 2, 2000 |
Showing 1 to 17 of 17 CVEs