target entity

GNU

5 source-linked records in the current knowledge graph.

high

CVE-2026-24061: GNU InetUtils Argument Injection Vulnerability

GNU InetUtils contains an argument injection vulnerability in telnetd that could allow for remote authentication bypass via a "-f root" value for the USER environment variable. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-24061EPSS 98.9%GNUInetUtils
CISA KEV ↗ · unattributed attribution
high

CVE-2014-6278: GNU Bash OS Command Injection Vulnerability

GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2014-6278EPSS 99.6%GNUGNU Bash
CISA KEV ↗ · unattributed attribution
high

CVE-2023-4911: GNU C Library Buffer Overflow Vulnerability

GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-4911EPSS 81.4%GNUGNU C Library
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2014-7169: GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute code. This CVE correctly remediates the vulnerability in CVE-2014-6271. Required action: Apply updates per vendor instructions.

CVE-2014-6271CVE-2014-7169EPSS 100.0%Bourne-Again Shell (Bash)GNU
CISA KEV ↗ · unattributed attribution