Gdb

Vendor:

First CVE: May 24, 2005 · Active for 21 years

9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Gdb over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 24, 2005
21 years ago
Most Recent CVE
Jul 25, 2023
1,097 days ago

CVE Severity & Scoring

Gdb9 CVEs
All CVEs352,713 CVEs
MediumHigh
Attack Vector
Local5 (55.6%)
Network0 (0.0%)
Unknown4 (44.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (55.6%)
High0 (0.0%)
Unknown4 (44.4%)
User Interaction
None0 (0.0%)
Unknown4 (44.4%)
Required5 (55.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (55.6%)
Unknown4 (44.4%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GNU gdb All versions is affected by: Buffer Overflow - Out of bound memory access. The impact is: Deny of Service, Memory Disclosure, and Possible Code Execution. The component is:
Jul 24, 20197.826NONO
GNU Debugger (GDB) 8.0 and earlier fails to detect a negative length field in a DWARF section. A malformed section in an ELF binary or a core file can cause GDB to repeatedly alloc
Jun 21, 20175.521NONO
GNU Project Debugger (GDB) before 7.5, when .debug_gdb_scripts is defined, automatically loads certain files from the current working directory, which allows local users to gain pr
Mar 5, 20136.921NONO
gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb.
May 24, 20057.218NONO
GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap buffer overflow via the function pe_as16() at /gdb/coff-pe-read.c.
Jul 25, 20235.517NONO
GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a heap use after free via the function add_pe_exported_sym() at /gdb/coff-pe-read.c.
Jul 25, 20235.517NONO
GNU gdb (GDB) 13.0.50.20220805-git was discovered to contain a stack overflow via the function ada_decode at /gdb/ada-lang.c.
Jul 25, 20235.517NONO
Buffer overflow in the (1) DWARF (dwarfread.c) and (2) DWARF2 (dwarf2read.c) debugging code in GNU Debugger (GDB) 6.5 allows user-assisted attackers, or restricted users, to execut
Aug 31, 20065.116NONO
Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrar
May 24, 20054.614NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Gdb

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.416.90.4%00
7.3.116.90.4%00
7.316.90.4%00
7.216.90.4%00
7.116.90.4%00
7.0.116.90.4%00
7.016.90.4%00
6.816.90.4%00
6.7.116.90.4%00
6.716.90.4%00
6.616.90.4%00
6.526.01.8%00
6.416.90.4%00
6.316.90.4%00
6.2.116.90.4%00
6.216.90.4%00
6.1.116.90.4%00
6.116.90.4%00
6.016.90.4%00
5.316.90.4%00