Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gnu

First CVE: Sep 13, 1996Active for: 30 yearsTotal CVEs: 1,200
62.6
VTI Score
TOP TARGET

GNU's vulnerability footprint spans a diverse portfolio of foundational infrastructure and system software, including programming tools, core libraries, cryptographic implementations, and bootloaders that are embedded across virtually every Linux distribution and Unix-like system in the landscape. Despite a moderate number of distinct products, the vendor commands exceptional prominence because each of its components reaches an enormous installed base; vulnerabilities in GNU libc, GNU binutils, GnuTLS, and GRUB2 potentially affect millions of systems. The exposure recurs through memory-safety and bounds-checking weakness classes—out-of-bounds reads and writes, buffer overflows, and NULL-pointer dereferences—that are characteristic of large C codebases and legacy infrastructure software where fixing unsafe code incurs broad compatibility costs. A meaningful share of GNU vulnerabilities acquire public exploit code, reflecting both the open-source nature of the codebase and the strategic value of flaws in widely trusted system components. Defenders should treat GNU advisory releases as high-priority and broadly applicable across their Linux and Unix infrastructure; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
1,200
Total CVEs
More Total CVEs than 100% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 3% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Gnu over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 13, 1996
29 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Products(124 total)

Top CVEs

Signals from CVEs in this vendor scope (1200 CVEs).

1,200 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-24061CRITICAL
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable.
Jan 21, 20269.899YESYES
CVE-2014-6271CRITICAL
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra
Sep 24, 20149.899YESYES
CVE-2023-4911HIGH
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to us
Oct 3, 20237.898YESYES
CVE-2014-6278HIGH
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via
Sep 30, 20148.898YESYES
CVE-2014-7169CRITICAL
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri
Sep 25, 20149.898YESYES
CVE-2015-0235HIGH
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code
Jan 28, 201510.092NOYES
CVE-2011-4862HIGH
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU
Dec 25, 201110.092NOYES
CVE-2024-2961HIGH
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT charac
Apr 17, 20247.387NOYES
CVE-2009-3555CRITICAL
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier,
Nov 9, 20099.885NOYES
CVE-2015-7547HIGH
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attac
Feb 18, 20168.183NOYES
View all 1,200 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,200 CVEs
44%
42%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local405 (33.8%)
Network420 (35.0%)
Unknown369 (30.8%)
Physical4 (0.3%)
Adjacent Network2 (0.2%)
Attack Complexity
Low737 (61.4%)
High94 (7.8%)
Unknown369 (30.8%)
User Interaction
None424 (35.3%)
Unknown369 (30.8%)
Required406 (33.8%)
Privileges Required
Low127 (10.6%)
High27 (2.3%)
None677 (56.4%)
Unknown369 (30.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (1200 CVEs).

CISA KEV
5 CVEs
0.4% of CVEs· 99th percentile
Metasploit
11 CVEs
0.9% of CVEs· 97th percentile
Nuclei
5 CVEs
0.4% of CVEs· 95th percentile
ExploitDB
94 CVEs
7.8% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gnu.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gnu — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gnu's Products

View all 23 CNAs →

Top CWEs