Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

292 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.2%—GNU Binutils21/3/201717/6/2026
The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NULL pointer while reading section contents in a corrupt binary, leading to a program crash.
ModificadaCrítica (9.8)2.3%—GNU Binutils21/3/201717/6/2026
ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects.
ModificadaCrítica (9.1)3.8%—GNU Binutils17/3/201717/6/2026
readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.
ModificadaMedia (5.5)1.1%—GNU Binutils17/3/201717/6/2026
readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations.
ModificadaMedia (5.5)1.2%—GNU Binutils17/3/201717/6/2026
readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow.
ModificadaMedia (5)5.2%—Fedoraproject FedoraDebian LinuxGNU BinutilsCanonical Ubuntu Linux15/1/201517/6/2026
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.
ModificadaBaja (3.6)1.0%—Canonical Ubuntu LinuxGNU BinutilsFedoraproject Fedora9/12/201417/6/2026
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
ModificadaAlta (7.5)6.2%—Canonical Ubuntu LinuxGNU BinutilsFedoraproject Fedora9/12/201417/6/2026
Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.
ModificadaAlta (7.5)6.2%—Fedoraproject FedoraGNU BinutilsCanonical Ubuntu Linux9/12/201417/6/2026
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.
ModificadaAlta (7.5)4.9%—Fedoraproject FedoraGNU BinutilsCanonical Ubuntu Linux9/12/201417/6/2026
Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a truncated export table in a PE file.
ModificadaAlta (7.5)5.2%—GNU BinutilsCanonical Ubuntu LinuxFedoraproject Fedora9/12/201417/6/2026
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
ModificadaAlta (7.5)7.5%—Fedoraproject FedoraCanonical Ubuntu LinuxGNU Binutils9/12/201417/6/2026
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
ModificadaMedia (5)5.1%—GNU BinutilsFedoraproject FedoraCanonical Ubuntu Linux9/12/201417/6/2026
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
ModificadaMedia (5)3.6%—GNU BinutilsGNU LibibertyCanonical Ubuntu LinuxDebian Linux5/9/201216/6/2026
Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which…
ModificadaAlta (7.3)14%💥 ExploitGNU Binutils15/5/200616/6/2026
Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in…
ModificadaAlta (7.6)2.3%—GNU BinutilsCanonical Ubuntu Linux31/12/200516/6/2026
Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050714 allows user-assisted attackers to have an unknown impact via a crafted .s file.
ModificadaAlta (7.5)12%💥 ExploitGNU BinutilsCanonical Ubuntu Linux31/12/200516/6/2026
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
Orbitaley — Vulnerabilidades