CVE Tools

Gcc

17 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Gcc, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Gcc CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Gcc CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-121
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 17 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High741%
  • Medium847%
  • Low212%

Latest CVEs

The 15 most recently published vulnerabilities affecting Gcc.

  1. CVE-2025-61729Excessive resource consumption when printing error string for host certificate validation in crypto/x5097.5
  2. CVE-2023-4039GCC's-fstack-protector fails to guard dynamically-sized local variables on AArch644.8
  3. CVE-2021-3826Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a crafted mangled sy...6.5
  4. CVE-2022-27943libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.5.5
  5. CVE-2021-46195GCC v12.0 was discovered to contain an uncontrolled recursion via the component libiberty/rust-demangle.c. This vulnerability allows attackers to cause a Denial of Service (DoS) by consuming excess...5.5
  6. CVE-2021-37322GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.7.8
  7. CVE-2002-2439Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.7.8
  8. CVE-2019-15847The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random numbe...7.5
  9. CVE-2018-12886stack_protect_prologue in cfgexpand.c and stack_protect_epilogue in function.c in GNU Compiler Collection (GCC) 4.1 through 8 (under certain circumstances) generate instruction sequences when targe...8.1
  10. CVE-2017-11671Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequenc...4.0
  11. CVE-2015-5276The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-depende...5.0
  12. CVE-2013-4598The Groups, Communities and Co (GCC) module 7.x-1.x before 7.x-1.1 for Drupal does not properly check permission, which allows remote attackers to access the configuration pages via unspecified vec...5.0
  13. CVE-2008-1685gcc 4.2.0 through 4.3.0 in GNU Compiler Collection, when casts are not used, considers the sum of a pointer and an int to be greater than or equal to the pointer, which might lead to removal of len...6.8
  14. CVE-2008-1367gcc 4.3.x does not generate a cld instruction while compiling functions used for string manipulation such as memcpy and memmove on x86 and i386, which can prevent the direction flag (DF) from being...7.5
  15. CVE-2006-1902fold_binary in fold-const.c in GNU Compiler Collection (gcc) 4.1 improperly handles pointer overflow when folding a certain expr comparison to a corresponding offset comparison in cases other than ...2.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store