Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

326 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.7%—Eclipse MosquittoCanonical Ubuntu LinuxOpensuse Backports SLEOpensuse Leap+219/9/201917/6/2026
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur.
ModificadaAlta (7.5)3.2%—NIC BirdOpensuse Backports SLEFedoraproject FedoraDebian Linux9/9/201917/6/2026
BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical expression when checking the validity of an input message. Sending a shutdown communication with a…
ModificadaAlta (7.5)0.95%—Imapfilter Project ImapfilterDebian LinuxFedoraproject FedoraOpensuse Backports SLE+18/9/201917/6/2026
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
ModificadaAlta (7.8)4.1%—KDE KconfigDebian LinuxFedoraproject FedoraOpensuse Backports SLE+47/8/201917/6/2026
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
ModificadaAlta (8.8)4.0%—Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap31/7/201917/6/2026
An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the colorhash function, allocating too small of a buffer. This buffer can then be written out of bounds, resulting in a heap overflow, ultimately…
ModificadaAlta (8.8)3.5%—Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap31/7/201917/6/2026
An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer can then be written out of bounds resulting in a heap overflow, ultimately ending in code…
ModificadaAlta (8.8)3.6%—Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap31/7/201917/6/2026
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
ModificadaAlta (8.8)3.6%—Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap31/7/201917/6/2026
An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.
ModificadaAlta (7.1)2.8%—Videolan VLC Media PlayerOpensuse Backports SLEOpensuse BackportsOpensuse Leap30/7/201917/6/2026
An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
ModificadaMedia (5.5)1.6%—Mcpp Project McppOpensuse Backports SLEOpensuse Leap26/7/201917/6/2026
MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c.
ModificadaCrítica (9.8)3.7%—Videolan VLC Media PlayerOpensuse Backports SLEOpensuse LeapDebian Linux+118/7/201917/6/2026
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height.
ModificadaAlta (8.1)3.7%—Libsdl Simple Directmedia LayerDebian LinuxOpensuse Backports SLEOpensuse Leap+916/7/201917/6/2026
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c.
ModificadaAlta (7.8)2.1%—Videolan VLC Media PlayerDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+114/7/201917/6/2026
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file.
ModificadaAlta (8.8)4.5%—Libsdl Sdl2 ImageDebian LinuxOpensuse Backports SLEOpensuse Leap+13/7/201917/6/2026
An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image…
ModificadaAlta (8.8)4.0%—Libsdl Sdl2 ImageDebian LinuxOpensuse Backports SLEOpensuse Leap+13/7/201917/6/2026
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability.
ModificadaMedia (6.5)0.84%—Google ChromeOpensuse Backports SLEOpensuse Leap23/5/201917/6/2026
Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
ModificadaAlta (7.5)4.6%💥 ExploitGoogle ChromeOpensuse Backports SLEOpensuse Leap23/5/201917/6/2026
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)1.1%—Google ChromeOpensuse Backports SLEOpensuse Leap23/5/201917/6/2026
Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
ModificadaMedia (6.5)2.0%—Libsdl Sdl2 ImageLibsdl Simple Directmedia LayerFedoraproject FedoraCanonical Ubuntu Linux+320/5/201917/6/2026
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c.
ModificadaAlta (7.4)2.0%—Heimdal Project HeimdalFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+115/5/201917/6/2026
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
ModificadaAlta (8.8)2.6%—GraphicsmagickDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+124/4/201917/6/2026
In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in…
ModificadaAlta (8.8)2.9%—GraphicsmagickDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+124/4/201917/6/2026
In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in…
ModificadaMedia (6.5)2.2%—GraphicsmagickFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+223/4/201917/6/2026
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaAlta (8.1)2.2%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+517/4/201917/6/2026
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both…