Binutils
Vendor:
First CVE: Dec 31, 2005 · Active for 20 years
276
Total CVEs
More Total CVEs than 100% of tracked products
19.7
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Binutils over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Apr 22, 2026
93 days ago
CVE Severity & Scoring
Binutils276 CVEs
51%
43%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local205 (74.3%)
Network60 (21.7%)
Unknown11 (4.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low249 (90.2%)
High16 (5.8%)
Unknown11 (4.0%)
User Interaction
None64 (23.2%)
Unknown11 (4.0%)
Required201 (72.8%)
Privileges Required
Low23 (8.3%)
High0 (0.0%)
None242 (87.7%)
Unknown11 (4.0%)
Top CVEs
Signals from CVEs in this product scope (276 CVEs).
276 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9749HIGH The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecifie | Jun 19, 2017 | 7.8 | 41 | NO | YES |
CVE-2017-9750HIGH opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (buffer overflow and application | Jun 19, 2017 | 7.8 | 40 | NO | YES |
CVE-2017-9746HIGH The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspe | Jun 19, 2017 | 7.8 | 40 | NO | YES |
CVE-2017-9756HIGH The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or | Jun 19, 2017 | 7.8 | 39 | NO | YES |
CVE-2017-9748HIGH The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a deni | Jun 19, 2017 | 7.8 | 39 | NO | YES |
CVE-2018-6323HIGH The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigned integer overflow because bfd | Jan 26, 2018 | 7.8 | 38 | NO | YES |
CVE-2017-9742HIGH The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly hav | Jun 19, 2017 | 7.8 | 38 | NO | YES |
CVE-2017-9747HIGH The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a den | Jun 19, 2017 | 7.8 | 37 | NO | YES |
CVE-2006-2362HIGH Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a deni | May 15, 2006 | 7.3 | 37 | NO | YES |
CVE-2005-4807HIGH Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute | Dec 31, 2005 | 7.5 | 35 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (276 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
4.0% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (276 CVEs).
Media Mentions
Signals from CVEs in this product scope (276 CVEs).
Top CNAs Publishing CVEs For Binutils
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.45 | 12 | 6.3 | 0.2% | 0 | 0 |
| 2.44 | 6 | 5.2 | 0.4% | 0 | 0 |
| 2.43 | 14 | 4.6 | 0.7% | 0 | 0 |
| 2.40 | 3 | 5.5 | 0.4% | 0 | 0 |
| 2.39 | 1 | 7.8 | 0.5% | 0 | 0 |
| 2.38.50 | 2 | 5.5 | 0.4% | 0 | 0 |
| 2.36 | 4 | 7.5 | 1.2% | 0 | 0 |
| 2.35.1 | 2 | 4.4 | 1.3% | 0 | 0 |
| 2.35 | 4 | 5.5 | 1.0% | 0 | 0 |
| 2.34 | 1 | 5.5 | 1.1% | 0 | 0 |
| 2.32 | 13 | 6.2 | 1.8% | 0 | 0 |
| 2.31.1 | 8 | 5.9 | 2.1% | 0 | 0 |
| 2.31 | 11 | 5.8 | 1.9% | 0 | 0 |
| 2.30 | 22 | 6.3 | 2.6% | 0 | 0 |
| 2.29.1 | 15 | 7.5 | 2.0% | 0 | 1 |
| 2.29 | 31 | 6.1 | 2.0% | 0 | 1 |
| 2.28 | 49 | 7.1 | 2.9% | 0 | 7 |
| 2.26 | 6 | 6.7 | 0.3% | 0 | 0 |