Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
292 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.2% | — | GNU Binutils | 21/3/2017 | 17/6/2026 | The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NULL pointer while reading section contents in a corrupt binary, leading to a program crash. | |
| Modificada | Crítica (9.8) | 2.3% | — | GNU Binutils | 21/3/2017 | 17/6/2026 | ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects. | |
| Modificada | Crítica (9.1) | 3.8% | — | GNU Binutils | 17/3/2017 | 17/6/2026 | readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well. | |
| Modificada | Media (5.5) | 1.1% | — | GNU Binutils | 17/3/2017 | 17/6/2026 | readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations. | |
| Modificada | Media (5.5) | 1.2% | — | GNU Binutils | 17/3/2017 | 17/6/2026 | readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow. | |
| Modificada | Media (5) | 5.2% | — | Fedoraproject FedoraDebian LinuxGNU BinutilsCanonical Ubuntu Linux | 15/1/2015 | 17/6/2026 | The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive. | |
| Modificada | Baja (3.6) | 1.0% | — | Canonical Ubuntu LinuxGNU BinutilsFedoraproject Fedora | 9/12/2014 | 17/6/2026 | Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar. | |
| Modificada | Alta (7.5) | 6.2% | — | Canonical Ubuntu LinuxGNU BinutilsFedoraproject Fedora | 9/12/2014 | 17/6/2026 | Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file. | |
| Modificada | Alta (7.5) | 6.2% | — | Fedoraproject FedoraGNU BinutilsCanonical Ubuntu Linux | 9/12/2014 | 17/6/2026 | Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file. | |
| Modificada | Alta (7.5) | 4.9% | — | Fedoraproject FedoraGNU BinutilsCanonical Ubuntu Linux | 9/12/2014 | 17/6/2026 | Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a truncated export table in a PE file. | |
| Modificada | Alta (7.5) | 5.2% | — | GNU BinutilsCanonical Ubuntu LinuxFedoraproject Fedora | 9/12/2014 | 17/6/2026 | The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable. | |
| Modificada | Alta (7.5) | 7.5% | — | Fedoraproject FedoraCanonical Ubuntu LinuxGNU Binutils | 9/12/2014 | 17/6/2026 | The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file. | |
| Modificada | Media (5) | 5.1% | — | GNU BinutilsFedoraproject FedoraCanonical Ubuntu Linux | 9/12/2014 | 17/6/2026 | The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record. | |
| Modificada | Media (5) | 3.6% | — | GNU BinutilsGNU LibibertyCanonical Ubuntu LinuxDebian Linux | 5/9/2012 | 16/6/2026 | Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which… | |
| Modificada | Alta (7.3) | 14% | 💥 Exploit | GNU Binutils | 15/5/2006 | 16/6/2026 | Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in… | |
| Modificada | Alta (7.6) | 2.3% | — | GNU BinutilsCanonical Ubuntu Linux | 31/12/2005 | 16/6/2026 | Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050714 allows user-assisted attackers to have an unknown impact via a crafted .s file. | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | GNU BinutilsCanonical Ubuntu Linux | 31/12/2005 | 16/6/2026 | Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code. |