Nongnu maintains a small portfolio of diverse open-source utilities and libraries spanning version control, system information, authentication, and notification components, many of which occupy specialized infrastructure and development roles. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, while the recurring weakness classes—memory-buffer issues, authentication flaws, and cross-site scripting in web-facing components—reflect the varied attack surfaces and legacy maturity of projects with different governance and update cadences. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nongnu over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-17455CRITICAL Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-bas | Oct 10, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-1000637HIGH zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack ap | Aug 20, 2018 | 7.8 | 25 | NO | NO |
CVE-2023-30630HIGH Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third pa | Apr 13, 2023 | 7.1 | 23 | NO | NO |
CVE-2010-3846MEDIUM Array index error in the apply_rcs_change function in rcs.c in CVS 1.11.23 allows local users to gain privileges via an RCS file containing crafted delta fragment changes that trig | Nov 5, 2010 | 6.9 | 22 | NO | NO |
CVE-2007-3209HIGH Mail Notification 4.0, when WITH_SSL is set to 0 at compile time, uses unencrypted connections for accounts configured with SSL/TLS, which allows remote attackers to obtain sensiti | Jun 14, 2007 | 7.8 | 20 | NO | NO |
CVE-2014-2886MEDIUM GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situation | Sep 18, 2014 | 6.8 | 18 | NO | NO |
CVE-2013-7322MEDIUM usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which caus | Mar 9, 2014 | 4.9 | 18 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in Samizdat before 0.6.2 allow remote authenticated users to inject arbitrary web script or HTML via the (1) message title or (2 | Feb 17, 2009 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nongnu.
Media articles that mention a CVE ID that affects a product developed by Nongnu — matched by CVE ID, not by vendor name.