Newlib
Vendor:
First CVE: Mar 18, 2020 · Active for 6 years
10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Newlib over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 18, 2020
6 years ago
Most Recent CVE
Aug 20, 2024
703 days ago
CVE Severity & Scoring
Newlib10 CVEs
80%
20%
All CVEs352,231 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low8 (80.0%)
High0 (0.0%)
None2 (20.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3420CRITICAL A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc c | Mar 5, 2021 | 9.8 | 31 | NO | NO |
CVE-2024-30949CRITICAL An issue in newlib v.4.3.0 allows an attacker to execute arbitrary code via the time unit scaling in the _gettimeofday function. | Aug 20, 2024 | 9.8 | 25 | NO | NO |
CVE-2019-14878MEDIUM In the __d2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is perfor | Mar 19, 2020 | 6.5 | 22 | NO | NO |
CVE-2019-14875MEDIUM In the __multiply function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is p | Mar 19, 2020 | 6.5 | 22 | NO | NO |
CVE-2019-14874MEDIUM In the __i2b function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is perfor | Mar 19, 2020 | 6.5 | 22 | NO | NO |
CVE-2019-14872MEDIUM The _dtoa_r function of the newlib libc library, prior to version 3.3.0, performs multiple memory allocations without checking their return value. This could result in NULL pointer | Mar 19, 2020 | 6.5 | 22 | NO | NO |
CVE-2019-14877MEDIUM In the __mdiff function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate big integers, however no check is perfo | Mar 19, 2020 | 6.5 | 21 | NO | NO |
CVE-2019-14876MEDIUM In the __lshift function of the newlib libc library, all versions prior to 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is per | Mar 19, 2020 | 6.5 | 21 | NO | NO |
CVE-2019-14873MEDIUM In the __multadd function of the newlib libc library, prior to versions 3.3.0 (see newlib/libc/stdlib/mprec.c), Balloc is used to allocate a big integer, however no check is perfor | Mar 19, 2020 | 6.5 | 21 | NO | NO |
CVE-2019-14871MEDIUM The REENT_CHECK macro (see newlib/libc/include/sys/reent.h) as used by REENT_CHECK_TM, REENT_CHECK_MISC, REENT_CHECK_MP and other newlib macros in versions prior to 3.3.0, does not | Mar 18, 2020 | 6.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Newlib
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.3.0 | 1 | 9.8 | 0.8% | 0 | 0 |