Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.1) | 4.5% | — | GNU Glibc | 1/6/2010 | 16/6/2026 | Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through 2.11.1, when the --verify option is used, allows user-assisted remote attackers to execute arbitrary code via a crafted ELF program with a negative value for a certain… | |
| Modificada | Alta (7.2) | 0.57% | — | GNU Glibc | 1/6/2010 | 16/6/2026 | The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain… | |
| Modificada | Media (5) | 2.0% | — | GNU Glibc | 1/6/2010 | 16/6/2026 | Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n… | |
| Modificada | Media (5) | 11% | 💥 Exploit | GNU Glibc | 1/6/2010 | 16/6/2026 | Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format… | |
| Modificada | Media (6.8) | 3.6% | — | Libcurl | 19/3/2010 | 16/6/2026 | content_encoding.c in libcurl 7.10.5 through 7.19.7, when zlib is enabled, does not properly restrict the amount of callback data sent to an application that requests automatic decompression, which might allow remote attackers to cause a denial of service (application crash) or have unspecified other impact by sending… | |
| Modificada | Alta (7.5) | 3.1% | — | GNU Glibc | 14/1/2010 | 16/6/2026 | nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function. | |
| Modificada | Alta (7.5) | 3.5% | — | LibcurlLibcurl | 14/8/2009 | 16/6/2026 | lib/ssluse.c in cURL and libcurl 7.4 through 7.19.5, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate… | |
| Modificada | Media (6.8) | 9.0% | 💥 Exploit | CurlLibcurl | 5/3/2009 | 16/6/2026 | The redirect implementation in curl and libcurl 5.11 through 7.19.3, when CURLOPT_FOLLOWLOCATION is enabled, accepts arbitrary Location values, which might allow remote HTTP servers to (1) trigger arbitrary requests to intranet servers, (2) read or overwrite arbitrary files via a redirect to a file: URL, or (3)… | |
| Modificada | Media (5) | 1.1% | — | Perl-openssl Libcrypt-openssl-dsa-perl | 15/1/2009 | 16/6/2026 | libcrypt-openssl-dsa-perl does not properly check the return value from the OpenSSL DSA_verify and DSA_do_verify functions, which might allow remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature, a similar vulnerability to CVE-2008-5077. | |
| Modificada | Alta (10) | 4.9% | — | Libcaudio | 10/11/2008 | 16/6/2026 | Heap-based buffer overflow in the cddb_read_disc_data function in cddb.c in libcdaudio 0.99.12p2 allows remote CDDB servers to execute arbitrary code via long CDDB data. | |
| Modificada | Media (5) | 13% | 💥 Exploit | GNU Libcdio | 3/1/2008 | 16/6/2026 | Stack-based buffer overflow in the print_iso9660_recurse function in iso-info (src/iso-info.c) in GNU Compact Disc Input and Control Library (libcdio) 0.79 and earlier allows context-dependent attackers to cause a denial of service (core dump) and possibly execute arbitrary code via a disk or image that contains a… | |
| Modificada | Alta (7.5) | 2.3% | — | Libcurl | 18/7/2007 | 16/6/2026 | libcurl 7.14.0 through 7.16.3, when built with GnuTLS support, does not check SSL/TLS certificate expiration or activation dates, which allows remote attackers to bypass certain access restrictions. | |
| Modificada | Alta (7.2) | 0.45% | — | Gentoo Glibc | 3/7/2007 | 16/6/2026 | Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution | |
| Modificada | Alta (7.5) | 5.2% | — | CurlLibcurlWget | 13/10/2005 | 16/6/2026 | Stack-based buffer overflow in the ntlm_output function in http-ntlm.c for (1) wget 1.10, (2) curl 7.13.2, and (3) libcurl 7.13.2, and other products that use libcurl, when NTLM authentication is enabled, allows remote servers to execute arbitrary code via a long NTLM username. | |
| Modificada | Alta (8.8) | 5.7% | — | Haxx CurlHaxx Libcurl | 2/5/2005 | 16/6/2026 | Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded, which is not properly handled by (1) the Curl_input_ntlm function in http_ntlm.c… | |
| Modificada | Baja (2.1) | 0.39% | — | GNU GlibcRedhat Enterprise LinuxRedhat Enterprise Linux Desktop | 9/2/2005 | 16/6/2026 | The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Baja (2.1) | 0.36% | — | GNU Glibc | 31/12/2004 | 16/6/2026 | The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968. | |
| Modificada | Baja (2.1) | 0.36% | — | GNU Glibc | 31/12/2004 | 16/6/2026 | GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program. | |
| Modificada | Alta (7.2) | 0.34% | — | SGI IrixAILibcprAI | 18/8/2004 | 16/6/2026 | cpr (libcpr) in SGI IRIX before 6.5.25 allows local users to gain privileges by loading a user provided library while restarting the checkpointed process. | |
| Modificada | Media (4.9) | 0.38% | — | GNU GlibcGNU ZebraQuagga Routing Software SuiteSGI Propack+3 | 15/12/2003 | 16/6/2026 | The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface. | |
| Modificada | Alta (7.5) | 15% | — | GNU GlibcMIT Kerberos 5OpenafsSGI Irix+9 | 25/3/2003 | 16/6/2026 | Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability… | |
| Modificada | Alta (10) | 5.4% | — | Tuxbr Libcgi | 31/12/2002 | 16/6/2026 | Stack-based buffer overflow in the parse_field function in cgi_lib.c for LIBCGI 1.0.2 and 1.0.3 allows remote attackers to execute arbitrary code via a long argument. | |
| Modificada | Media (5) | 2.5% | — | GNU GlibcSGI IrixApple MAC OS XApple MAC OS X Server | 12/11/2002 | 16/6/2026 | The Sun RPC functionality in multiple libc implementations does not provide a time-out mechanism when reading data from TCP connections, which allows remote attackers to cause a denial of service (hang). | |
| Modificada | Media (5) | 3.3% | — | GNU Glibc | 11/10/2002 | 16/6/2026 | The BIND 4 and BIND 8.2.x stub resolver libraries, and other libraries such as glibc 2.2.5 and earlier, libc, and libresolv, use the maximum buffer size instead of the actual size when processing a DNS response, which causes the stub resolvers to read past the actual boundary ("read buffer overflow"), allowing remote… | |
| Modificada | Alta (7.5) | 5.9% | — | GNU GlibcISC Bind | 12/8/2002 | 16/6/2026 | Buffer overflow in DNS resolver functions that perform lookup of network names and addresses, as used in BIND 4.9.8 and ported to glibc 2.2.5 and earlier, allows remote malicious DNS servers to execute arbitrary code through a subroutine used by functions such as getnetbyname and getnetbyaddr. |