Glibc
Vendor:
First CVE: May 3, 2000 · Active for 26 years
168
Total CVEs
More Total CVEs than 99% of tracked products
7.6
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.6%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Glibc over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 3, 2000
26 years ago
Most Recent CVE
Apr 28, 2026
86 days ago
CVE Severity & Scoring
Glibc168 CVEs
43%
38%
13%
All CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local29 (17.3%)
Network76 (45.2%)
Unknown62 (36.9%)
Physical0 (0.0%)
Adjacent Network1 (0.6%)
Attack Complexity
Low79 (47.0%)
High27 (16.1%)
Unknown62 (36.9%)
User Interaction
None99 (58.9%)
Unknown62 (36.9%)
Required6 (3.6%)
Privileges Required
Low20 (11.9%)
High0 (0.0%)
None86 (51.2%)
Unknown62 (36.9%)
Top CVEs
Signals from CVEs in this product scope (168 CVEs).
168 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4911HIGH A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to us | Oct 3, 2023 | 7.8 | 98 | YES | YES |
CVE-2015-0235HIGH Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code | Jan 28, 2015 | 10.0 | 92 | NO | YES |
CVE-2024-2961HIGH The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT charac | Apr 17, 2024 | 7.3 | 87 | NO | YES |
CVE-2015-7547HIGH Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attac | Feb 18, 2016 | 8.1 | 83 | NO | YES |
CVE-2010-4052MEDIUM Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attacker | Jan 13, 2011 | 5.0 | 55 | NO | YES |
CVE-2018-1000001HIGH In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and poten | Jan 31, 2018 | 7.8 | 52 | NO | YES |
CVE-2010-4051MEDIUM The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (app | Jan 13, 2011 | 5.0 | 50 | NO | YES |
CVE-2010-3856HIGH ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic sh | Jan 7, 2011 | 7.2 | 48 | NO | YES |
CVE-2010-3847MEDIUM elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment | Jan 7, 2011 | 6.9 | 46 | NO | YES |
CVE-2014-5119HIGH Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or exec | Aug 29, 2014 | 7.5 | 45 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (168 CVEs).
CISA KEV
1 CVE
0.6% of CVEs· 96th percentile
Metasploit
6 CVEs
3.6% of CVEs· 96th percentile
Nuclei
3 CVEs
1.8% of CVEs· 96th percentile
ExploitDB
22 CVEs
13.1% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (168 CVEs).
Media Mentions
Signals from CVEs in this product scope (168 CVEs).
Top CNAs Publishing CVEs For Glibc
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.9 | 12 | 5.7 | 12.3% | 0 | 5 |
| 2.8 | 12 | 5.4 | 5.0% | 0 | 4 |
| 2.7 | 13 | 5.5 | 4.8% | 0 | 4 |
| 2.6.1 | 12 | 5.4 | 5.0% | 0 | 4 |
| 2.6 | 12 | 5.4 | 5.0% | 0 | 4 |
| 2.5-49.el5_5.6 | 1 | 6.9 | 0.8% | 0 | 1 |
| 2.5.1 | 12 | 5.4 | 5.0% | 0 | 4 |
| 2.5 | 14 | 5.6 | 4.6% | 0 | 5 |
| 2.4 | 13 | 5.4 | 5.5% | 0 | 5 |
| 2.37 | 1 | 9.8 | 1.4% | 0 | 0 |
| 2.3.6 | 12 | 5.4 | 5.0% | 0 | 4 |
| 2.36 | 1 | 5.3 | 1.6% | 0 | 0 |
| 2.3.5 | 12 | 5.4 | 5.0% | 0 | 4 |
| 2.3.4 | 15 | 4.7 | 4.0% | 0 | 4 |
| 2.34 | 1 | 7.5 | 3.1% | 0 | 0 |
| 2.3.3 | 15 | 4.7 | 4.0% | 0 | 4 |
| 2.33 | 2 | 7.8 | 2.2% | 0 | 0 |
| 2.3.2 | 17 | 4.9 | 4.5% | 0 | 4 |
| 2.32 | 1 | 9.8 | 2.9% | 0 | 0 |
| 2.3.10 | 13 | 4.9 | 4.3% | 0 | 4 |