Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.32% | — | Opensuse Supportutils | 5/3/2019 | 17/6/2026 | Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides one at an arbitrary location it is executed with root privileges | |
| Modificada | Alta (7.8) | 2.0% | — | GNU BinutilsNetapp Element SoftwareCanonical Ubuntu LinuxF5 Traffix Signaling Delivery Controller | 24/2/2019 | 17/6/2026 | An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option section. | |
| Modificada | Media (5.5) | 1.2% | — | GNU BinutilsNetapp Element Software Management | 24/2/2019 | 17/6/2026 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in elf_read_notes in elf.c. | |
| Modificada | Alta (7.8) | 1.7% | — | GNU BinutilsNetapp HCI Management NodeNetapp SolidfireCanonical Ubuntu Linux+14 | 24/2/2019 | 17/6/2026 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is a heap-based buffer overflow in _bfd_archive_64_bit_slurp_armap in archive64.c. | |
| Modificada | Media (5.5) | 1.6% | — | GNU BinutilsNetapp HCI Management NodeNetapp SolidfireCanonical Ubuntu Linux | 24/2/2019 | 17/6/2026 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an out-of-bounds read leading to a SEGV in bfd_getl32 in libbfd.c, when called from pex64_get_runtime_function in pei-x86_64.c. | |
| Modificada | Media (5.5) | 1.1% | — | GNU BinutilsNetapp HCI Management NodeNetapp SolidfireCanonical Ubuntu Linux | 24/2/2019 | 17/6/2026 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in _bfd_elf_slurp_version_tables in elf.c. | |
| Modificada | Media (5.5) | 1.2% | — | GNU BinutilsNetapp HCI Management NodeNetapp Solidfire | 24/2/2019 | 17/6/2026 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an attempted excessive memory allocation in setup_group in elf.c. | |
| Modificada | Media (5.5) | 1.8% | — | GNU BinutilsNetapp HCI Management NodeNetapp SolidfireCanonical Ubuntu Linux | 24/2/2019 | 17/6/2026 | An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a stack consumption issue in d_count_templates_scopes in cp-demangle.c after many recursive calls. | |
| Modificada | Alta (7.8) | 1.6% | — | GNU BinutilsNetapp Element Software ManagementCanonical Ubuntu LinuxF5 Traffix Signaling Delivery Controller | 24/2/2019 | 17/6/2026 | An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_expression_1 in cp-demangle.c after many recursive calls. | |
| Modificada | Alta (8.8) | 3.3% | — | Fileutils Project Fileutils | 15/2/2019 | 16/6/2026 | Vulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variable that is passed to the shell. | |
| Modificada | Media (5.5) | 1.3% | — | Elfutils Project ElfutilsDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+7 | 9/2/2019 | 17/6/2026 | In elfutils 0.175, a heap-based buffer over-read was discovered in the function elf32_xlatetom in elf32_xlatetom.c in libelf. A crafted ELF input can cause a segmentation fault leading to denial of service (program crash) because ebl_core_note does not reject malformed core file notes. | |
| Modificada | Media (5.5) | 1.0% | — | Elfutils Project ElfutilsRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+4 | 9/2/2019 | 17/6/2026 | In elfutils 0.175, a negative-sized memcpy is attempted in elf_cvt_note in libelf/note_xlate.h because of an incorrect overflow check. Crafted elf input causes a segmentation fault, leading to denial of service (program crash). | |
| Modificada | Media (5.5) | 1.4% | — | Elfutils Project ElfutilsDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+7 | 29/1/2019 | 17/6/2026 | An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as… | |
| Modificada | Media (6.5) | 2.1% | — | Elfutils Project ElfutilsDebian Linux | 29/1/2019 | 17/6/2026 | A heap-based buffer over-read was discovered in the function read_srclines in dwarf_getsrclines.c in libdw in elfutils 0.175. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by eu-nm. | |
| Modificada | Media (6.5) | 1.6% | — | Elfutils Project Elfutils | 29/1/2019 | 17/6/2026 | An attempted excessive memory allocation was discovered in the function read_long_names in elf_begin.c in libelf in elfutils 0.174. Remote attackers could leverage this vulnerability to cause a denial-of-service via crafted elf input, which leads to an out-of-memory exception. NOTE: The maintainers believe this is not… | |
| Modificada | Media (5.5) | 1.5% | — | Elfutils Project Elfutils | 29/1/2019 | 17/6/2026 | In elfutils 0.175, there is a buffer over-read in the ebl_object_note function in eblobjnote.c in libebl. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted elf file, as demonstrated by eu-readelf. | |
| Modificada | Media (6.5) | 1.3% | — | GNU Recutils | 16/1/2019 | 17/6/2026 | An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_field_set_name() in the file rec-field.c in librec.a. | |
| Modificada | Media (6.5) | 1.3% | — | GNU Recutils | 16/1/2019 | 17/6/2026 | An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_extract_type in rec-utils.c in librec.a. | |
| Modificada | Media (6.5) | 1.3% | — | GNU Recutils | 16/1/2019 | 17/6/2026 | An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_buf_new in rec-buf.c when called from rec_parse_rset in rec-parser.c in librec.a. | |
| Modificada | Media (6.5) | 1.3% | — | GNU Recutils | 16/1/2019 | 17/6/2026 | An issue was discovered in GNU Recutils 1.8. There is a memory leak in rec_aggregate_reg_new in rec-aggregate.c in librec.a. | |
| Modificada | Media (6.5) | 1.3% | — | GNU Recutils | 16/1/2019 | 17/6/2026 | An issue was discovered in GNU Recutils 1.8. There is a NULL pointer dereference in the function rec_fex_size() in the file rec-fex.c of librec.a. | |
| Modificada | Media (6.5) | 1.3% | — | GNU Recutils | 16/1/2019 | 17/6/2026 | An issue was discovered in GNU Recutils 1.8. There is a double-free problem in the function rec_mset_elem_destroy() in the file rec-mset.c. | |
| Modificada | Media (6.5) | 2.7% | — | GNU Binutils | 15/1/2019 | 17/6/2026 | A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt. | |
| Modificada | Media (5.5) | 1.6% | — | GNU Binutils | 4/1/2019 | 17/6/2026 | The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm. | |
| Modificada | Media (5.5) | 2.0% | — | GNU Binutils | 4/1/2019 | 17/6/2026 | load_specific_debug_section in objdump.c in GNU Binutils through 2.31.1 contains an integer overflow vulnerability that can trigger a heap-based buffer overflow via a crafted section size. |