GNU's vulnerability footprint spans a diverse portfolio of foundational infrastructure and system software, including programming tools, core libraries, cryptographic implementations, and bootloaders that are embedded across virtually every Linux distribution and Unix-like system in the landscape. Despite a moderate number of distinct products, the vendor commands exceptional prominence because each of its components reaches an enormous installed base; vulnerabilities in GNU libc, GNU binutils, GnuTLS, and GRUB2 potentially affect millions of systems. The exposure recurs through memory-safety and bounds-checking weakness classes—out-of-bounds reads and writes, buffer overflows, and NULL-pointer dereferences—that are characteristic of large C codebases and legacy infrastructure software where fixing unsafe code incurs broad compatibility costs. A meaningful share of GNU vulnerabilities acquire public exploit code, reflecting both the open-source nature of the codebase and the strategic value of flaws in widely trusted system components. Defenders should treat GNU advisory releases as high-priority and broadly applicable across their Linux and Unix infrastructure; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gnu over time
Signals from CVEs in this vendor scope (1200 CVEs).
1,200 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24061CRITICAL telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. | Jan 21, 2026 | 9.8 | 99 | YES | YES |
CVE-2014-6271CRITICAL GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a cra | Sep 24, 2014 | 9.8 | 99 | YES | YES |
CVE-2023-4911HIGH A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to us | Oct 3, 2023 | 7.8 | 98 | YES | YES |
CVE-2014-6278HIGH GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via | Sep 30, 2014 | 8.8 | 98 | YES | YES |
CVE-2014-7169CRITICAL GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to wri | Sep 25, 2014 | 9.8 | 98 | YES | YES |
CVE-2015-0235HIGH Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code | Jan 28, 2015 | 10.0 | 92 | NO | YES |
CVE-2011-4862HIGH Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU | Dec 25, 2011 | 10.0 | 92 | NO | YES |
CVE-2024-2961HIGH The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT charac | Apr 17, 2024 | 7.3 | 87 | NO | YES |
CVE-2009-3555CRITICAL The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, | Nov 9, 2009 | 9.8 | 85 | NO | YES |
CVE-2015-7547HIGH Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attac | Feb 18, 2016 | 8.1 | 83 | NO | YES |
Signals from CVEs in this vendor scope (1200 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gnu.
Media articles that mention a CVE ID that affects a product developed by Gnu — matched by CVE ID, not by vendor name.