Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.7% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c. | |
| Modificada | Alta (8.1) | 1.7% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c. | |
| Modificada | Alta (8.1) | 1.7% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c. | |
| Modificada | Media (6.5) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c. | |
| Modificada | Alta (8.8) | 1.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c. | |
| Modificada | Media (4.3) | 1.6% | — | OtrsDebian LinuxOpensuse Backports SLEOpensuse Leap | 6/1/2020 | 17/6/2026 | An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and 6.0.x through 6.0.23. An attacker who is logged into OTRS as an agent is able to list tickets assigned to other agents, even tickets in a queue where the attacker doesn't have permissions. | |
| Modificada | Media (6.5) | 1.4% | — | Google ChromeOpensuse Backports SLEOpensuse Leap | 3/1/2020 | 17/6/2026 | Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.4% | — | Google ChromeOpensuse Backports SLEOpensuse Leap | 3/1/2020 | 17/6/2026 | Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.4% | — | Google ChromeOpensuse Backports SLEOpensuse Leap | 3/1/2020 | 17/6/2026 | Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.9% | — | Redhat AnsibleRedhat Ansible TowerRedhat Ceph StorageRedhat Cloudforms Management Engine+4 | 2/1/2020 | 17/6/2026 | Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True when Sumologic and Splunk callback plugins are used send tasks results events to collectors. This would discloses and collects any sensitive data. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec. | |
| Modificada | Alta (8.8) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec. | |
| Modificada | Alta (8.8) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c. | |
| Modificada | Alta (8.8) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec. | |
| Modificada | Alta (7.5) | 6.8% | — | SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+7 | 24/12/2019 | 17/6/2026 | zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive. | |
| Modificada | Alta (7.5) | 6.8% | — | SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+7 | 24/12/2019 | 17/6/2026 | flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results). | |
| Modificada | Alta (7.5) | 7.0% | — | SqliteSiemens Sinec Infrastructure Network ServicesOracle Mysql WorkbenchDebian Linux+7 | 23/12/2019 | 17/6/2026 | multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRewrite() calls. NOTE: this vulnerability exists because of an incomplete fix for CVE-2019-19880. | |
| Modificada | Alta (7.8) | 1.6% | — | Lout Project LoutOpensuse Backports SLEFedoraproject FedoraOpensuse Leap | 20/12/2019 | 17/6/2026 | Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. | |
| Modificada | Alta (7.8) | 1.5% | — | Lout Project LoutOpensuse Backports SLEOpensuse LeapFedoraproject Fedora | 20/12/2019 | 17/6/2026 | Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. | |
| Modificada | Alta (7.5) | 6.9% | — | SqliteNetapp Cloud BackupDebian LinuxSuse Package HUB+7 | 18/12/2019 | 17/6/2026 | exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant integer values in ORDER BY clauses of window definitions are mishandled. | |
| Analizada | Media (5.9) | 1.4% | — | Excon Project ExconOpensuse Backports SLEOpensuse LeapDebian Linux | 16/12/2019 | 28/7/2026 | In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted (such as by a timeout) would leave data on the socket. Subsequent requests would then read this data, returning content from the previous response. The race condition window appears to be… | |
| Modificada | Alta (8.8) | 6.4% | 💥 PoC | Google ChromeDebian LinuxFedoraproject FedoraSuse Package HUB+4 | 10/12/2019 | 17/6/2026 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |