GNU / Patch
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-56289 | Loop with Unreachable Exit Condition in GNU patch | MEDIUM | 4.6 | Jul 9, 2026 |
| CVE-2026-56288 | NULL Pointer Dereference in GNU patch | MEDIUM | 4.6 | Jul 9, 2026 |
| CVE-2021-45261 | patch: Invalid Pointer via another_hunk function | MEDIUM | 5.5 | Dec 22, 2021 |
| CVE-2019-20633 | patch: double free in another_hunk function in pch.c | MEDIUM | 5.5 | Mar 25, 2020 |
| CVE-2015-1396 | patch: directory traversal via symlinks (incomplete fix for CVE-2015-1196) | HIGH | 7.5 | Nov 25, 2019 |
| CVE-2018-20969 | patch: do_ed_script in pch.c does not block strings beginning with a ! character | HIGH | 7.8 | Aug 16, 2019 |
| CVE-2019-13638 | patch: OS shell command injection when processing crafted patch files | HIGH | 7.8 | Jul 26, 2019 |
| CVE-2019-13636 | patch: the following of symlinks in inp.c and util.c is mishandled in cases other than input files | MEDIUM | 5.9 | Jul 17, 2019 |
| CVE-2018-1000156 | patch: Malicious patch files cause ed to execute arbitrary commands | HIGH | 7.8 | Apr 6, 2018 |
| CVE-2018-6952 | patch: Double free of memory in pch.c:another_hunk() causes a crash | HIGH | 7.5 | Feb 13, 2018 |
| CVE-2018-6951 | patch: NULL pointer dereference in pch.c:intuit_diff_type() causes a crash | HIGH | 7.5 | Feb 13, 2018 |
| CVE-2016-10713 | patch: Out-of-bounds access in pch_write_line function in pch.c | MEDIUM | 5.5 | Feb 13, 2018 |
| CVE-2015-1395 | patch: directory traversal via file rename | HIGH | 7.5 | Aug 25, 2017 |
| CVE-2014-9637 | patch: local denial of service with a crafted patch | MEDIUM | 5.5 | Aug 25, 2017 |
| CVE-2015-1196 | patch: directory traversal via symlinks | MEDIUM | 4.3 | Jan 21, 2015 |
Showing 1 to 15 of 15 CVEs