Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.7% | — | Eclipse MosquittoCanonical Ubuntu LinuxOpensuse Backports SLEOpensuse Leap+2 | 19/9/2019 | 17/6/2026 | In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consists of approximately 65400 or more '/' characters, i.e. the topic hierarchy separator, then a stack overflow will occur. | |
| Modificada | Alta (7.5) | 3.2% | — | NIC BirdOpensuse Backports SLEFedoraproject FedoraDebian Linux | 9/9/2019 | 17/6/2026 | BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical expression when checking the validity of an input message. Sending a shutdown communication with a… | |
| Modificada | Alta (7.5) | 0.95% | — | Imapfilter Project ImapfilterDebian LinuxFedoraproject FedoraOpensuse Backports SLE+1 | 8/9/2019 | 17/6/2026 | IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate. | |
| Modificada | Alta (7.8) | 4.1% | — | KDE KconfigDebian LinuxFedoraproject FedoraOpensuse Backports SLE+4 | 7/8/2019 | 17/6/2026 | In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file. | |
| Modificada | Alta (8.8) | 4.0% | — | Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap | 31/7/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow in the colorhash function, allocating too small of a buffer. This buffer can then be written out of bounds, resulting in a heap overflow, ultimately… | |
| Modificada | Alta (8.8) | 3.5% | — | Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap | 31/7/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially crafted XPM image can cause an integer overflow, allocating too small of a buffer. This buffer can then be written out of bounds resulting in a heap overflow, ultimately ending in code… | |
| Modificada | Alta (8.8) | 3.6% | — | Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap | 31/7/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 3.6% | — | Libsdl Sdl2 ImageOpensuse Backports SLEOpensuse Leap | 31/7/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially crafted PCX image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability. | |
| Modificada | Alta (7.1) | 2.8% | — | Videolan VLC Media PlayerOpensuse Backports SLEOpensuse BackportsOpensuse Leap | 30/7/2019 | 17/6/2026 | An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read. | |
| Modificada | Media (5.5) | 1.6% | — | Mcpp Project McppOpensuse Backports SLEOpensuse Leap | 26/7/2019 | 17/6/2026 | MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c. | |
| Modificada | Crítica (9.8) | 3.7% | — | Videolan VLC Media PlayerOpensuse Backports SLEOpensuse LeapDebian Linux+1 | 18/7/2019 | 17/6/2026 | lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read because it does not properly validate the width and height. | |
| Modificada | Alta (8.1) | 3.7% | — | Libsdl Simple Directmedia LayerDebian LinuxOpensuse Backports SLEOpensuse Leap+9 | 16/7/2019 | 17/6/2026 | SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_blit_N.c when called from SDL_SoftBlit in video/SDL_blit.c. | |
| Modificada | Alta (7.8) | 2.1% | — | Videolan VLC Media PlayerDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+1 | 14/7/2019 | 17/6/2026 | An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and crash) or possibly have unspecified other impact via a crafted .mp4 file. | |
| Modificada | Alta (8.8) | 4.5% | — | Libsdl Sdl2 ImageDebian LinuxOpensuse Backports SLEOpensuse Leap+1 | 3/7/2019 | 17/6/2026 | An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cause an integer overflow, resulting in too little memory being allocated, which can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image… | |
| Modificada | Alta (8.8) | 4.0% | — | Libsdl Sdl2 ImageDebian LinuxOpensuse Backports SLEOpensuse Leap+1 | 3/7/2019 | 17/6/2026 | An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing error handler can lead to a buffer overflow and potential code execution. An attacker can provide a specially crafted image file to trigger this vulnerability. | |
| Modificada | Media (6.5) | 0.84% | — | Google ChromeOpensuse Backports SLEOpensuse Leap | 23/5/2019 | 17/6/2026 | Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. | |
| Modificada | Alta (7.5) | 4.6% | 💥 Exploit | Google ChromeOpensuse Backports SLEOpensuse Leap | 23/5/2019 | 17/6/2026 | Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 1.1% | — | Google ChromeOpensuse Backports SLEOpensuse Leap | 23/5/2019 | 17/6/2026 | Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform domain spoofing via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.0% | — | Libsdl Sdl2 ImageLibsdl Simple Directmedia LayerFedoraproject FedoraCanonical Ubuntu Linux+3 | 20/5/2019 | 17/6/2026 | An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There is a SEGV in the SDL function SDL_free_REAL at stdlib/SDL_malloc.c. | |
| Modificada | Alta (7.4) | 2.0% | — | Heimdal Project HeimdalFedoraproject FedoraOpensuse Backports SLEOpensuse Leap+1 | 15/5/2019 | 17/6/2026 | In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c. | |
| Modificada | Alta (8.8) | 2.6% | — | GraphicsmagickDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+1 | 24/4/2019 | 17/6/2026 | In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in… | |
| Modificada | Alta (8.8) | 2.9% | — | GraphicsmagickDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+1 | 24/4/2019 | 17/6/2026 | In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in… | |
| Modificada | Media (6.5) | 2.2% | — | GraphicsmagickFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+2 | 23/4/2019 | 17/6/2026 | coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Alta (8.1) | 2.2% | — | W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+5 | 17/4/2019 | 17/6/2026 | The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both… |