Binutils

Vendor:

First CVE: Dec 31, 2005 · Active for 20 years

276
Total CVEs
More Total CVEs than 100% of tracked products
19.7
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Binutils over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2005
20 years ago
Most Recent CVE
Apr 22, 2026
93 days ago

CVE Severity & Scoring

Binutils276 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local205 (74.3%)
Network60 (21.7%)
Unknown11 (4.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low249 (90.2%)
High16 (5.8%)
Unknown11 (4.0%)
User Interaction
None64 (23.2%)
Unknown11 (4.0%)
Required201 (72.8%)
Privileges Required
Low23 (8.3%)
High0 (0.0%)
None242 (87.7%)
Unknown11 (4.0%)

Top CVEs

Signals from CVEs in this product scope (276 CVEs).

276 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecifie
Jun 19, 20177.841NOYES
opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (buffer overflow and application
Jun 19, 20177.840NOYES
The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspe
Jun 19, 20177.840NOYES
The aarch64_ext_ldst_reglist function in opcodes/aarch64-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or
Jun 19, 20177.839NOYES
The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a deni
Jun 19, 20177.839NOYES
The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigned integer overflow because bfd
Jan 26, 20187.838NOYES
The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly hav
Jun 19, 20177.838NOYES
The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a den
Jun 19, 20177.837NOYES
Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a deni
May 15, 20067.337NOYES
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute
Dec 31, 20057.535NOYES

Exploit Exposure

Signals from CVEs in this product scope (276 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
4.0% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (276 CVEs).

Media Mentions

Signals from CVEs in this product scope (276 CVEs).

Top CNAs Publishing CVEs For Binutils

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.45126.30.2%00
2.4465.20.4%00
2.43144.60.7%00
2.4035.50.4%00
2.3917.80.5%00
2.38.5025.50.4%00
2.3647.51.2%00
2.35.124.41.3%00
2.3545.51.0%00
2.3415.51.1%00
2.32136.21.8%00
2.31.185.92.1%00
2.31115.81.9%00
2.30226.32.6%00
2.29.1157.52.0%01
2.29316.12.0%01
2.28497.12.9%07
2.2666.70.3%00