Gcc

Vendor:

First CVE: Nov 1, 2000 · Active for 25 years

14
Total CVEs
More Total CVEs than 91% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.2
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Gcc over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 1, 2000
25 years ago
Most Recent CVE
Sep 13, 2023
1,045 days ago

CVE Severity & Scoring

Gcc14 CVEs
All CVEs352,294 CVEs
LowMediumHigh
Attack Vector
Local5 (35.7%)
Network4 (28.6%)
Unknown5 (35.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (50.0%)
High2 (14.3%)
Unknown5 (35.7%)
User Interaction
None5 (35.7%)
Unknown5 (35.7%)
Required4 (28.6%)
Privileges Required
Low1 (7.1%)
High0 (0.0%)
None8 (57.1%)
Unknown5 (35.7%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction seq
May 22, 20198.128NONO
GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.
Nov 18, 20217.826NONO
The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of
Sep 2, 20197.526NONO
Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.
Oct 23, 20197.825NONO
Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a c
Sep 1, 20226.523NONO
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
Mar 26, 20225.522NONO
**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized
Sep 13, 20234.821NONO
GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by
Jan 14, 20225.520NONO
gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, which can prevent the direction fla
Mar 17, 20087.520NONO
The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to o
Nov 1, 20007.519NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Gcc

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.314.00.4%00
6.214.00.4%00
6.114.00.4%00
6.014.00.4%00
5.414.00.4%00
5.314.00.4%00
5.214.00.4%00
5.114.00.4%00
5.014.00.4%00
4.914.00.4%00
4.814.00.4%00
4.714.00.4%00
4.614.00.4%00
4.3.016.81.3%00
4.317.52.8%00
4.2.416.81.3%00
4.2.316.81.3%00
4.2.216.81.3%00
4.2.116.81.3%00
4.2.016.81.3%00