Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.9% | — | Canonical Ubuntu LinuxGnome Evolution | 20/7/2018 | 17/6/2026 | camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive information by… | |
| Modificada | Crítica (9.8) | 4.2% | — | Gnome LibsoupCanonical Ubuntu LinuxDebian LinuxRedhat Ansible Tower+5 | 5/7/2018 | 17/6/2026 | The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname. | |
| Modificada | Crítica (9.8) | 1.8% | — | Gnome Evolution | 15/6/2018 | 17/6/2026 | addressbook/backends/ldap/e-book-backend-ldap.c in Evolution-Data-Server in GNOME Evolution through 3.29.2 might allow attackers to trigger a Buffer Overflow via a long query that is processed by the strcat function. NOTE: the software maintainer disputes this because "the code had computed the required string length… | |
| Modificada | Alta (7.5) | 1.9% | — | Gnome Epiphany | 7/6/2018 | 17/6/2026 | libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via certain window.open and document.write calls. | |
| Modificada | Media (6.5) | 1.6% | — | Webkitgtk+Gnome Libsoup | 4/6/2018 | 17/6/2026 | WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to use system proxy settings for WebSocket connections. As a result, users could be deanonymized by crafted web sites via a… | |
| Modificada | Alta (7.5) | 1.5% | — | Gnome Epiphany | 23/5/2018 | 17/6/2026 | ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call. | |
| Modificada | Media (5.9) | 4.1% | — | 9folders NineApple MailBloop AirmailEmclient+13 | 16/5/2018 | 17/6/2026 | The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. | |
| Modificada | Media (6.5) | 2.2% | — | Gnome LibgxpsRedhat Ansible TowerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 6/5/2018 | 17/6/2026 | There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Media (6.5) | 2.2% | — | Gnome LibgxpsRedhat Ansible TowerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 4/5/2018 | 17/6/2026 | There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Crítica (9.8) | 23% | — | Gnome LibsoupDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 24/4/2018 | 17/6/2026 | An exploitable stack based buffer overflow vulnerability exists in the GNOME libsoup 2.58. A specially crafted HTTP request can cause a stack overflow resulting in remote code execution. An attacker can send a special HTTP request to the vulnerable server to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 2.0% | — | Gnome NetworkmanagerCanonical Ubuntu Linux | 20/3/2018 | 17/6/2026 | GNOME NetworkManager version 1.10.2 and earlier contains a Information Exposure (CWE-200) vulnerability in DNS resolver that can result in Private DNS queries leaked to local network's DNS servers, while on VPN. This vulnerability appears to have been fixed in Some Ubuntu 16.04 packages were fixed, but later updates… | |
| Modificada | Alta (8.8) | 2.2% | — | Gnome LibrsvgDebian Linux | 9/2/2018 | 17/6/2026 | GNOME librsvg version before commit c6ddf2ed4d768fd88adbea2b63f575cd523022ea contains a Improper input validation vulnerability in rsvg-io.c that can result in the victim's Windows username and NTLM password hash being leaked to remote attackers through SMB. This attack appear to be exploitable via The victim must… | |
| Modificada | Alta (7.8) | 2.2% | — | Fedoraproject FedoraGnome GcabCanonical Ubuntu LinuxDebian Linux+6 | 12/1/2018 | 17/6/2026 | A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file. | |
| Modificada | Alta (8.8) | 2.0% | — | Gnome Gdk-pixbufDebian LinuxCanonical Ubuntu Linux | 2/1/2018 | 17/6/2026 | Gnome gdk-pixbuf 2.36.8 and older is vulnerable to several integer overflow in the gif_get_lzw function resulting in memory corruption and potential code execution | |
| Modificada | Alta (7.8) | 1.4% | — | Gnome Evince | 27/11/2017 | 17/6/2026 | Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91. | |
| Modificada | Media (6.5) | 2.5% | — | Gnome NautilusDebian Linux | 20/9/2017 | 17/6/2026 | GNOME Nautilus before 3.23.90 allows attackers to spoof a file type by using the .desktop file extension, as demonstrated by an attack in which a .desktop file's Name field ends in .pdf but this file's Exec field launches a malicious "sh -c" command. In other words, Nautilus provides no UI indication that a file… | |
| Modificada | Alta (7.8) | 2.6% | — | Gnome Gdk-pixbufDebian Linux | 5/9/2017 | 17/6/2026 | An exploitable integer overflow vulnerability exists in the tiff_image_parse functionality of Gdk-Pixbuf 2.36.6 when compiled with Clang. A specially crafted tiff file can cause a heap-overflow resulting in remote code execution. An attacker can send a file or a URL to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 4.6% | — | Gnome Gdk-pixbufDebian Linux | 5/9/2017 | 17/6/2026 | An exploitable heap overflow vulnerability exists in the gdk_pixbuf__jpeg_image_load_increment functionality of Gdk-Pixbuf 2.36.6. A specially crafted jpeg file can cause a heap overflow resulting in remote code execution. An attacker can send a file or url to trigger this vulnerability. | |
| Modificada | Media (5.5) | 2.3% | — | Gnome Gedit | 5/9/2017 | 17/6/2026 | libgedit.a in GNOME gedit through 3.22.1 allows remote attackers to cause a denial of service (CPU consumption) via a file that begins with many '\0' characters. | |
| Modificada | Alta (7.8) | 51% | 💥 Exploit | Gnome EvinceDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 5/9/2017 | 17/6/2026 | backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the… | |
| Modificada | Alta (7.5) | 3.5% | — | Gnome Librest | 18/8/2017 | 17/6/2026 | The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object… | |
| Modificada | Alta (7.5) | 1.5% | — | Gnome Libgxps | 24/7/2017 | 17/6/2026 | There is a NULL pointer dereference in the caseless_hash function in gxps-archive.c in libgxps 0.2.5. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Alta (7.8) | 1.3% | — | Gnome Librsvg | 19/7/2017 | 17/6/2026 | A SIGFPE is raised in the function box_blur_line of rsvg-filter.c in GNOME librsvg 2.40.17 during an attempted parse of a crafted SVG file, because of incorrect protection against division by zero. | |
| Modificada | Alta (7.8) | 0.63% | — | Gnome-exe-thumbnailer Project Gnome-exe-thumbnailer | 18/7/2017 | 17/6/2026 | gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript code in its filename. | |
| Modificada | Crítica (9.8) | 1.6% | — | Gnome Gtk-vnc | 17/7/2017 | 17/6/2026 | gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering |