Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 8.1% | 💥 Exploit | GNU Glibc | 2/5/2013 | 16/6/2026 | Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd. | |
| Modificada | Media (5) | 4.3% | — | Haxx CurlHaxx LibcurlCanonical Ubuntu Linux | 29/4/2013 | 16/6/2026 | The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL. | |
| Modificada | Media (5) | 4.1% | — | GNU Glibc | 29/4/2013 | 16/6/2026 | Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.17 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of domain conversion results. | |
| Modificada | Alta (7.5) | 22% | 💥 Exploit | Haxx CurlHaxx LibcurlCanonical Ubuntu Linux | 8/3/2013 | 16/6/2026 | Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the realm… | |
| Modificada | Media (5) | 2.9% | — | GNU Glibc | 8/2/2013 | 16/6/2026 | Buffer overflow in the extend_buffers function in the regular expression matcher (posix/regexec.c) in glibc, possibly 2.17 and earlier, allows context-dependent attackers to cause a denial of service (memory corruption and crash) via crafted multibyte characters. | |
| Modificada | Media (5.9) | 1.2% | — | Apache Libcloud | 4/11/2012 | 16/6/2026 | Apache Libcloud before 0.11.1 uses an incorrect regular expression during verification of whether the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate. | |
| Modificada | Media (4.6) | 0.99% | 💥 Exploit | GNU Glibc | 25/8/2012 | 16/6/2026 | Multiple integer overflows in the (1) strtod, (2) strtof, (3) strtold, (4) strtod_l, and other unspecified "related functions" in stdlib in GNU C Library (aka glibc or libc6) 2.16 allow local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string, which triggers a… | |
| Modificada | Alta (7.5) | 16% | — | CurlLibcurl | 13/4/2012 | 16/6/2026 | curl and libcurl 7.2x before 7.24.0 do not properly consider special characters during extraction of a pathname from a URL, which allows remote attackers to conduct data-injection attacks via a crafted URL, as demonstrated by a CRLF injection attack on the (1) IMAP, (2) POP3, or (3) SMTP protocol. | |
| Modificada | Media (4.3) | 1.4% | — | Apache Libcloud | 12/9/2011 | 16/6/2026 | libcloud before 0.4.1 does not verify SSL certificates for HTTPS connections, which allows remote attackers to spoof certificates and bypass intended access restrictions via a man-in-the-middle (MITM) attack. | |
| Modificada | Media (4.3) | 2.9% | — | Haxx LibcurlApple MAC OS XFedoraproject FedoraDebian Linux+1 | 7/7/2011 | 16/6/2026 | The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests. | |
| Modificada | Media (6.2) | 0.52% | — | GNU Glibc | 10/4/2011 | 16/6/2026 | locale/programs/locale.c in locale in the GNU C Library (aka glibc or libc6) before 2.13 does not quote its output, which might allow local users to gain privileges via a crafted localization environment variable, in conjunction with a program that executes a script that uses the eval function. | |
| Modificada | Baja (3.3) | 0.42% | — | GNU Glibc | 10/4/2011 | 16/6/2026 | The addmntent function in the GNU C Library (aka glibc or libc6) 2.13 and earlier does not report an error status for failed attempts to write to the /etc/mtab file, which makes it easier for local users to trigger corruption of this file, as demonstrated by writes from a process with a small RLIMIT_FSIZE value, a… | |
| Modificada | Media (5) | 2.9% | — | GNU Glibc | 8/4/2011 | 16/6/2026 | Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long UTF8 string that is used in an fnmatch call with a crafted pattern argument, a different vulnerability than CVE-2011-1071. | |
| Modificada | Baja (3.7) | 0.31% | — | GNU Glibc | 8/4/2011 | 16/6/2026 | ld.so in the GNU C Library (aka glibc or libc6) 2.13 and earlier expands the $ORIGIN dynamic string token when RPATH is composed entirely of this token, which might allow local users to gain privileges by creating a hard link in an arbitrary directory to a (1) setuid or (2) setgid program with this RPATH value, and… | |
| Modificada | Media (5.1) | 14% | 💥 Exploit | GNU EglibcGNU Glibc | 8/4/2011 | 16/6/2026 | The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898,… | |
| Modificada | Media (6.9) | 0.79% | 💥 Exploit | GNU GlibcRedhat Enterprise Linux | 8/4/2011 | 16/6/2026 | Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain privileges via a crafted dynamic shared object (DSO) in a… | |
| Modificada | Media (6.9) | 0.52% | — | GNU Glibc | 30/3/2011 | 16/6/2026 | ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states "This is just nonsense. There are a gazillion other ways to… | |
| Modificada | Baja (2.1) | 0.39% | — | Balbir Singh Libcgroup | 22/3/2011 | 16/6/2026 | The cgre_receive_netlink_msg function in daemon/cgrulesengd.c in cgrulesengd in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 does not verify that netlink messages originated in the kernel, which allows local users to bypass intended resource restrictions via a crafted message. | |
| Modificada | Alta (7.2) | 0.42% | — | Balbir Singh Libcgroup | 22/3/2011 | 16/6/2026 | Heap-based buffer overflow in the parse_cgroup_spec function in tools/tools-common.c in the Control Group Configuration Library (aka libcgroup or libcg) before 0.37.1 allows local users to gain privileges via a crafted controller list on the command line of an application. NOTE: it is not clear whether this issue… | |
| Modificada | Media (4) | 2.6% | — | GNU Glibc | 2/3/2011 | 16/6/2026 | The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability… | |
| Modificada | Media (5) | 51% | 💥 Exploit | GNU Glibc | 13/1/2011 | 16/6/2026 | Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by… | |
| Modificada | Media (5) | 40% | 💥 Exploit | GNU Glibc | 13/1/2011 | 16/6/2026 | The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (application crash) via a regular expression containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation, as… | |
| Modificada | Alta (7.2) | 11% | 💥 Exploit | GNU Glibc | 7/1/2011 | 16/6/2026 | ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library… | |
| Modificada | Media (6.9) | 9.5% | 💥 Exploit | GNU Glibc | 7/1/2011 | 16/6/2026 | elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory. | |
| Modificada | Media (5) | 1.6% | — | GNU Glibc | 14/10/2010 | 16/6/2026 | Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorrect program, as demonstrated by a setuid program that contains a… |