A vulnerability, which was classified as problematic, was found in GNU Binutils 2.43. Impacted is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation results in memory corruption.
This vulnerability is known as CVE-2025-1178. It is possible to launch the attack remotely. Furthermore, an exploit is available.
Applying a patch is advised to resolve this issue.
A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak.
This vulnerability is referenced as CVE-2025-1152. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
It is recommended to apply a patch to fix this issue.
The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."
A vulnerability was found in GNU Binutils 2.43/2.44. It has been declared as problematic. This vulnerability affects the function bfd_set_format of the file format.c. The manipulation results in memory corruption.
This vulnerability is identified as CVE-2025-1153. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability appears as CVE-2025-1176. The attack may be performed from remote. In addition, an exploit is available.
It is best practice to apply a patch to resolve this issue.
A vulnerability classified as critical has been found in GNU Binutils 2.43. This impacts an unknown function. Performing a manipulation results in improper access controls.
This vulnerability is identified as CVE-2024-57360. The attack can only be performed from the local network. There is not any exploit available.
A vulnerability labeled as problematic has been found in GNU Binutils up to 2.43. Affected is the function disassemble_bytes of the file binutils/objdump.c. Such manipulation of the argument buf leads to stack-based buffer overflow.
This vulnerability is documented as CVE-2025-0840. The attack can be executed remotely. Additionally, an exploit exists.
The affected component should be upgraded.
A vulnerability classified as problematic has been found in MIT Kerberos 5 1.21.2. The affected element is an unknown function of the file /krb5/src/kdc/ndr.c. Performing a manipulation results in memory leak.
This vulnerability is cataloged as CVE-2024-26462. The attack must originate from the local network. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in MIT Kerberos 5 1.21.2. This affects an unknown function in the library /krb5/src/lib/gssapi/krb5/k5sealv3.c. The manipulation leads to memory leak.
This vulnerability is documented as CVE-2024-26461. The attack requires being on the local network. There is not any exploit available.
A vulnerability was found in GNU objdump 2.43. It has been classified as critical. This affects an unknown part of the component BFD Library. This manipulation causes buffer overflow.
This vulnerability is tracked as CVE-2024-53589. The attack is only possible within the local network. No exploit exists.
A vulnerability labeled as problematic has been found in xkbcommon up to 0.8.1. This affects an unknown function of the file xkbcomp/compat.c of the component Parser. The manipulation results in null pointer dereference.
This vulnerability is reported as CVE-2018-15863. The attack requires a local approach. No exploit exists.
The affected component should be upgraded.
A vulnerability classified as problematic was found in MIT Kerberos 5 1.21.2. The impacted element is an unknown function in the library /krb5/src/lib/rpc/pmap_rmt.c. Executing a manipulation can lead to memory leak.
This vulnerability is registered as CVE-2024-26458. The attack requires access to the local network. No exploit is available.
A vulnerability has been found in wpengine Advanced Custom Fields Plugin up to 6.8.1 on WordPress and classified as critical. This impacts an unknown function of the component Form Submission Handler. The manipulation of the argument post_title leads to missing authorization.
This vulnerability is referenced as CVE-2026-8382. Remote exploitation of the attack is possible. No exploit is available.