Tinycc is a minimalist C compiler with a focused scope, yet achieves prominence in embedded and educational deployment contexts where code-generation tools operate on untrusted or adversarially crafted input. The vulnerability profile concentrates on its core compilation engine, where memory-safety issues such as out-of-bounds write conditions represent the durable structural risk tied to code-generation and parsing complexity. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tinycc over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-12495MEDIUM An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to a one-byte out-of-bounds write in the gsym_addr function in x86_64-g | May 31, 2019 | 5.5 | 20 | NO | NO |
CVE-2019-9754MEDIUM An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 1 byte out of bounds write in the end_macro function in tccpp.c. | Mar 13, 2019 | 5.5 | 20 | NO | NO |
CVE-2018-20376MEDIUM An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the asm_parse_directive function in | Dec 23, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-20375MEDIUM An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the sym_pop function in tccgen.c. | Dec 23, 2018 | 5.5 | 20 | NO | NO |
CVE-2018-20374MEDIUM An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the use_section1 function in tccasm | Dec 23, 2018 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tinycc.
Media articles that mention a CVE ID that affects a product developed by Tinycc — matched by CVE ID, not by vendor name.