Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.7% | — | Elfutils Project ElfutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 3/9/2018 | 17/6/2026 | libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice. | |
| Modificada | Media (5.5) | 1.6% | — | Elfutils Project ElfutilsDebian LinuxOpensuse LeapCanonical Ubuntu Linux+3 | 29/8/2018 | 17/6/2026 | dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file. | |
| Modificada | Alta (7.8) | 1.7% | — | Nongnu ZutilsDebian Linux | 20/8/2018 | 17/6/2026 | zutils version prior to version 1.8-pre2 contains a Buffer Overflow vulnerability in zcat that can result in Potential denial of service or arbitrary code execution. This attack appear to be exploitable via the victim openning a crafted compressed file. This vulnerability appears to have been fixed in 1.8-pre2. | |
| Modificada | Alta (8.1) | 5.6% | — | RPM Yum-utilsRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 1/8/2018 | 17/6/2026 | A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted system via path traversal. If reposync is… | |
| Modificada | Media (5.5) | 3.1% | — | GNU BinutilsRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 1/7/2018 | 17/6/2026 | The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_attributes in elf-attrs.c and bfd_malloc in libbfd.c. This can… | |
| Modificada | Media (6.1) | 99% | 💥 Exploit | Zohocorp Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+1 | 29/6/2018 | 17/6/2026 | A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script… | |
| Modificada | Alta (7.5) | 6.6% | — | Zohocorp Firewall AnalyzerZohocorp Manageengine Netflow AnalyzerZohocorp Manageengine Network Configuration ManagerZohocorp Manageengine Opmanager+1 | 29/6/2018 | 17/6/2026 | Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers to read certain files on the web server… | |
| Modificada | Alta (7.5) | 3.3% | — | GNU Binutils | 28/6/2018 | 17/6/2026 | remember_Ktype in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM). This can occur during execution of cxxfilt. | |
| Modificada | Crítica (9.8) | 4.5% | — | GNU BinutilsCanonical Ubuntu Linux | 23/6/2018 | 17/6/2026 | finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump. | |
| Modificada | Alta (7.5) | 6.6% | — | GNU BinutilsCanonical Ubuntu Linux | 23/6/2018 | 17/6/2026 | demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump. | |
| Modificada | Alta (7.5) | 5.0% | — | GNU BinutilsCanonical Ubuntu Linux | 23/6/2018 | 17/6/2026 | A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump. | |
| Modificada | Media (5.5) | 2.0% | — | GNU Binutils | 22/6/2018 | 17/6/2026 | An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_arm_hp_template, demangle_class_name, demangle_fund_type, do_type, do_arg, demangle_args,… | |
| Modificada | Alta (8.8) | 2.5% | — | Freedesktop Xdg-utilsDebian LinuxCanonical Ubuntu Linux | 10/5/2018 | 17/6/2026 | The open_envvar function in xdg-open in xdg-utils before 1.1.3 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, as demonstrated by %s in this environment variable. | |
| Modificada | Media (6.5) | 1.7% | — | Bibutils Project Bibutils | 7/5/2018 | 17/6/2026 | NULL pointer dereference in the _fields_add function in fields.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by end2xml. | |
| Modificada | Media (6.5) | 1.4% | — | Bibutils Project Bibutils | 7/5/2018 | 17/6/2026 | Read access violation in the isiin_keyword function in isiin.c in libbibutils.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by isi2xml. | |
| Modificada | Media (6.5) | 1.1% | — | Bibutils Project Bibutils | 7/5/2018 | 17/6/2026 | NULL pointer deference in the addsn function in serialno.c in libbibcore.a in bibutils through 6.2 allows remote attackers to cause a denial of service (application crash), as demonstrated by copac2xml. | |
| Modificada | Media (5.5) | 2.2% | — | GNU BinutilsRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 29/4/2018 | 17/6/2026 | The ignore_section_sym function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, does not validate the output_section pointer in the case of a symtab entry with a "SECTION" type that has a "0" value, which allows remote attackers to cause a denial of service (NULL… | |
| Modificada | Media (5.5) | 1.8% | — | GNU BinutilsRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 29/4/2018 | 17/6/2026 | The _bfd_XX_bfd_copy_private_bfd_data_common function in peXXigen.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, processes a negative Data Directory size with an unbounded loop that increases the value of (external_IMAGE_DEBUG_DIRECTORY) *edd so that the address… | |
| Modificada | Media (6.5) | 3.3% | — | GNU BinutilsRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 25/4/2018 | 17/6/2026 | concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by nm-new. | |
| Modificada | Media (5.5) | 2.3% | — | GNU BinutilsRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 25/4/2018 | 17/6/2026 | process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted binary file, as demonstrated by readelf. | |
| Modificada | Media (5.5) | 1.3% | — | GNU Binutils | 10/4/2018 | 17/6/2026 | An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression. | |
| Modificada | Media (5.5) | 1.0% | — | GNU Binutils | 30/3/2018 | 17/6/2026 | An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.29 and 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_nested_args, demangle_args, do_arg, and do_type. | |
| Modificada | Media (5.5) | 2.0% | — | GNU BinutilsRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 22/3/2018 | 17/6/2026 | The bfd_section_from_shdr function in elf.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (segmentation fault) via a large attribute section. | |
| Modificada | Alta (7.8) | 0.84% | — | Elfutils Project Elfutils | 18/3/2018 | 17/6/2026 | elfutils 0.170 has a buffer over-read in the ebl_dynamic_tag_name function of libebl/ebldynamictagname.c because SYMTAB_SHNDX is unsupported. | |
| Modificada | Alta (7.8) | 2.0% | — | Canonical Ubuntu LinuxDebian LinuxGNU Sharutils | 13/3/2018 | 17/6/2026 | Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, function looks_like_c_code. Failure to perform checking of the buffer containing input line. that can result in Could lead to code execution. This attack appear to be… |