Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
467 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.1% | — | LibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+2 | 20/9/2016 | 17/6/2026 | Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtree file, which triggers undefined behavior. | |
| Modificada | Alta (7.5) | 4.3% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITLibarchive+1 | 20/9/2016 | 17/6/2026 | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself. | |
| Modificada | Media (5.5) | 1.5% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITLibarchive | 20/9/2016 | 17/6/2026 | Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file. | |
| Modificada | Media (5.5) | 2.1% | — | Canonical Ubuntu LinuxLibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 20/9/2016 | 17/6/2026 | The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. | |
| Modificada | Media (5.5) | 1.5% | — | Libarchive | 20/9/2016 | 17/6/2026 | The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password. | |
| Modificada | Media (5.5) | 2.0% | — | Canonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+1 | 20/9/2016 | 17/6/2026 | The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted rar archive. | |
| Modificada | Media (5.5) | 2.1% | — | Canonical Ubuntu LinuxLibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 20/9/2016 | 17/6/2026 | The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newline parsing. | |
| Modificada | Media (5.5) | 5.4% | — | LibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+1 | 20/9/2016 | 17/6/2026 | The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file. | |
| Modificada | Media (6.5) | 2.9% | — | LibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+1 | 20/9/2016 | 17/6/2026 | The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file. | |
| Modificada | Media (5.5) | 2.1% | — | LibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+2 | 20/9/2016 | 17/6/2026 | The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct. | |
| Modificada | Alta (7.5) | 12% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerLibarchive+1 | 20/9/2016 | 17/6/2026 | The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. | |
| Modificada | Media (5.5) | 1.9% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerCanonical Ubuntu Linux+1 | 20/9/2016 | 17/6/2026 | The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file. | |
| Modificada | Alta (7.5) | 4.5% | — | Canonical Ubuntu LinuxLibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Desktop+1 | 20/9/2016 | 17/6/2026 | The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file. | |
| Modificada | Alta (7.5) | 3.8% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerLibarchive | 20/9/2016 | 17/6/2026 | The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy." | |
| Modificada | Alta (7.5) | 4.3% | — | Debian LinuxLibarchiveCanonical Ubuntu Linux | 20/9/2016 | 17/6/2026 | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file. | |
| Modificada | Media (6.5) | 3.2% | — | Canonical Ubuntu LinuxDebian LinuxLibarchive | 20/9/2016 | 17/6/2026 | bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar file. | |
| Modificada | Media (5.5) | 1.8% | — | Libarchive | 20/9/2016 | 17/6/2026 | bsdcpio in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read and crash) via crafted cpio file. | |
| Modificada | Media (5.8) | 1.0% | 💥 Exploit | Sapcar Archive Tool | 13/8/2016 | 17/6/2026 | SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security Note 2327384. | |
| Modificada | Alta (7.5) | 4.4% | — | Canonical Ubuntu LinuxKDE Karchives | 2/8/2016 | 17/6/2026 | Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads. | |
| Modificada | Alta (8.8) | 10% | — | Libarchive | 7/5/2016 | 17/6/2026 | Heap-based buffer overflow in the zip_read_mac_metadata function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to execute arbitrary code via crafted entry-size values in a ZIP archive. | |
| Modificada | Alta (8.3) | 6.1% | — | Apache Hive | 29/1/2016 | 17/6/2026 | The authorization framework in Apache Hive 1.0.0, 1.0.1, 1.1.0, 1.1.1, 1.2.0 and 1.2.1, on clusters protected by Ranger and SqlStdHiveAuthorization, allows attackers to bypass intended parent table access restrictions via unspecified partition-level operations. | |
| Modificada | Alta (7.3) | 6.8% | — | IBM Infosphere BiginsightsApache Hive | 21/12/2015 | 17/6/2026 | The LDAP implementation in HiveServer2 in Apache Hive before 1.0.1 and 1.1.x before 1.1.1, as used in IBM InfoSphere BigInsights 3.0, 3.0.0.1, and 3.0.0.2 and other products, mishandles simple unauthenticated and anonymous bind configurations, which allows remote attackers to bypass authentication via a crafted LDAP… | |
| Modificada | Alta (10) | 1.6% | — | Gehealthcare Centricity Clinical Archive Audit Trail Repository | 4/8/2015 | 17/6/2026 | GE Healthcare Centricity Clinical Archive Audit Trail Repository has a default password of initinit for the (1) SSL key manager and (2) server keystore; (3) keystore_password for the server truststore; and atna for the (4) primary storage database and (5) archive storage database, which has unspecified impact and… | |
| Modificada | Alta (7.5) | 5.8% | — | Debian LinuxFedoraproject FedoraARJ Software ARJ Archiver | 8/4/2015 | 17/6/2026 | Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive. | |
| Modificada | Media (5.8) | 3.3% | — | ARJ Software ARJ ArchiverFedoraproject Fedora | 8/4/2015 | 17/6/2026 | Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive. |