CVEFinder.io

CVE-2025-15281

⚠️ high
🔍 Scan for this CVE
Summary

Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

CVSS Score
7.5
High
EPSS Score
0.1
Exploit Probability
Published Date
2026-01-20
First Seen: 2026-01-28
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 68.9% of all 329,456 vulnerabilities in our database.

#102,448
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Jan 22, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Partial
Limited system impact
🏆 Discovered By
Vitaly Simonovich
SSVC data provided by CISA
Last Modified 2026-02-05
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE IDs (Weakness Types)

📦 Affected Products 1

🔗 References 2

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-6238 🔶 medium 6.5 0.3 The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail t... 2026-04-28
CVE-2026-5435 ⚠️ high 7.3 0.1 The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforc... 2026-04-28
CVE-2026-4046 ⚠️ high 7.5 0.0 The iconv() function in the GNU C Library versions 2.43 and earlier may crash due to an assertion failure when convertin... 2026-03-30
CVE-2026-4437 ⚠️ high 7.5 0.1 Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the... 2026-03-20
CVE-2026-4438 🔶 medium 5.4 0.1 Calling gethostbyaddr or gethostbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend in the... 2026-03-20
CVE-2026-3904 🔶 medium 6.2 0.0 Calling NSS-backed functions that support caching via nscd may call the nscd client side code and in the GNU C Library ... 2026-03-11
These CVEs affect the same products