Uclibc-ng Project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    2
    Critical Level Threats
    4
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-29503

    A memory corruption vulnerability exists in the libpthread linuxthreads functionality of uClibC 0.9.33.2 and uClibC-ng 1.0.40. Thread allocation can lead to memory corruption. An attacker can create threads to trigger this vulnerability.

    Last Modified: Apr 15, 2025
    Published: Sep 29, 2022

    CVE-2022-30295

    uClibc-ng through 1.0.40 and uClibc through 0.9.33.2 use predictable DNS transaction IDs that may lead to DNS cache poisoning. This is related to a reset of a value to 0x2.

    Last Modified: Nov 21, 2024
    Published: May 06, 2022

    CVE-2021-27419

    uClibc-ng Integer Overflow or Wraparound

    Last Modified: Apr 16, 2025
    Published: May 03, 2022

    CVE-2021-43523

    In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.

    Last Modified: May 05, 2025
    Published: Nov 10, 2021

    CVE-2016-2225

    The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet.

    Last Modified: Apr 20, 2025
    Published: Mar 24, 2017
    Items Per Page
    Uclibc-Ng_Project Vulnerabilities & Security CVEs | CVE-DB