Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.4% | — | Qwutils Project Qwutils | 9/2/2021 | 17/6/2026 | An issue was discovered in the qwutils crate before 0.3.1 for Rust. When a Clone panic occurs, insert_slice_clone can perform a double drop. | |
| Modificada | Media (5.5) | 1.3% | — | GNU BinutilsRedhat Enterprise LinuxNetapp HCI Compute Node FirmwareNetapp Cloud Backup+4 | 4/1/2021 | 17/6/2026 | There's a flaw in bfd_pef_parse_function_stubs of bfd/pef.c in binutils in versions prior to 2.34 which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. | |
| Modificada | Media (5.5) | 1.2% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Media (5.5) | 1.2% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Media (6.1) | 1.1% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Media (5.5) | 1.1% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Media (5.5) | 0.34% | — | Rust-lang Future-utils | 31/12/2020 | 17/6/2026 | An issue was discovered in the futures-util crate before 0.3.2 for Rust. FuturesUnordered can lead to data corruption because Sync is mishandled. | |
| Modificada | Media (4.7) | 0.26% | — | Rust-lang Future-utils | 31/12/2020 | 17/6/2026 | An issue was discovered in the futures-util crate before 0.3.7 for Rust. MutexGuard::map can cause a data race for certain closure situations (in safe code). | |
| Modificada | Crítica (9.1) | 1.4% | — | Actix-utils | 31/12/2020 | 17/6/2026 | An issue was discovered in the actix-utils crate before 2.0.0 for Rust. The Cell implementation allows obtaining more than one mutable reference to the same data. | |
| Modificada | Baja (3.3) | 1.2% | — | GNU BinutilsNetapp Ontap Select Deploy Administration Utility | 27/12/2020 | 17/6/2026 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35.1. A heap-based buffer over-read can occur in bfd_getl_signed_32 in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section in elf.c. | |
| Modificada | Media (5.5) | 1.1% | — | GNU BinutilsNetapp Cloud BackupNetapp HCI Management NodeNetapp Ontap Select Deploy Administration Utility+1 | 9/12/2020 | 17/6/2026 | A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file. | |
| Modificada | Media (5.5) | 1.2% | — | GNU BinutilsNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Solidfire & HCI Management Node | 9/12/2020 | 17/6/2026 | A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in scan_unit_for_symbols, as demonstrated in addr2line, that can cause a denial of service via a crafted file. | |
| Modificada | Media (5.5) | 1.1% | — | GNU BinutilsNetapp Ontap Select Deploy Administration UtilityFedoraproject Fedora | 9/12/2020 | 17/6/2026 | A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file. | |
| Modificada | Media (5.5) | 0.89% | — | GNU BinutilsNetapp Ontap Select Deploy Administration Utility | 9/12/2020 | 17/6/2026 | A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read in process_symbol_table, as demonstrated in readeif. | |
| Modificada | Media (5.5) | 0.95% | — | GNU BinutilsNetapp Ontap Select Deploy Administration Utility | 9/12/2020 | 17/6/2026 | A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated in readelf, via a crafted file. | |
| Modificada | Alta (8.1) | 4.2% | — | Cron-utils Project Cron-utils | 25/11/2020 | 17/6/2026 | Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.3, a template Injection vulnerability is present. This enables attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE)… | |
| Modificada | Alta (7) | 0.65% | — | Samba Cifs-utilsFedoraproject FedoraOpensuse Leap | 9/9/2020 | 17/6/2026 | It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges. | |
| Modificada | Crítica (9.8) | 1.9% | — | Nodee-utils Project Nodee-utils | 1/9/2020 | 17/6/2026 | All versions of package nodee-utils are vulnerable to Prototype Pollution via the deepSet function. | |
| Modificada | Crítica (9.8) | 1.9% | — | Gammautils Project Gammautils | 1/9/2020 | 17/6/2026 | All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions. | |
| Modificada | Crítica (9.8) | 1.9% | — | Nis-utils Project Nis-utils | 17/8/2020 | 17/6/2026 | All versions of package nis-utils are vulnerable to Prototype Pollution via the setValue function. | |
| Modificada | Crítica (9.8) | 2.1% | — | Springtree Madlib-object-utils | 14/8/2020 | 17/6/2026 | madlib-object-utils before 0.1.7 is vulnerable to Prototype Pollution via setValue. | |
| Modificada | Alta (7.5) | 1.6% | — | SAS GO RPM Utils | 24/6/2020 | 17/6/2026 | In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-leading ".." which leads in file extraction outside of the current directory. Note: the fixing commit was applied to all affected versions… | |
| Modificada | Crítica (9.8) | 3.1% | — | Utils-extend Project Utils-extend | 3/4/2020 | 17/6/2026 | Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend. | |
| Modificada | Crítica (9.8) | 2.3% | — | GNU Coreutils | 24/1/2020 | 17/6/2026 | Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings. | |
| Modificada | Alta (7.8) | 0.52% | — | GNU Coreutils | 24/1/2020 | 17/6/2026 | The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have… |