CVE-2025-62689High· 7.5▾ TwilightNULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted pack…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in commit ff13abc on the master branch of the libmicrohttpd Git repository, after the v1.0.2 tag. A specially crafted packet sent by an attacker could cause a denial-of-service (DoS) condition.
libmicrohttpd < 1.0.3Upgrade past the affected range:
libmicrohttpd 1.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59777High· 7.5NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier
CVE-2026-6846High· 7.8A flaw was found in binutils
CVE-2025-66862High· 7.5A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.
CVE-2026-75818Low· 1.8GNU Aspell prezip-bin contains a heap-based buffer overflow vulnerability in the decompressor in prog/prezip.c
CVE-2026-56392Medium· 6.1GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values
CVE-2025-11495Low· 3.3A vulnerability was determined in GNU Binutils 2.45