Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 1.6% | — | GNU GlibcRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little EndianRedhat Codeready Linux Builder EUS FOR Power Little Endian EUS+18 | 18/9/2023 | 14/7/2026 | A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the… | |
| Modificada | Media (6.5) | 1.7% | — | GNU GlibcRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder EUS FOR Power Little EndianRedhat Codeready Linux Builder EUS FOR Power Little Endian EUS+23 | 18/9/2023 | 17/6/2026 | A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a… | |
| Modificada | Media (5.5) | 0.38% | — | GNU Binutils | 14/9/2023 | 17/6/2026 | A flaw was found in Binutils. The field `the_bfd` of `asymbol`struct is uninitialized in the `bfd_mach_o_get_synthetic_symtab` function, which may lead to an application crash and local denial of service. | |
| Modificada | Media (5.5) | 0.35% | — | GNU Binutils | 14/9/2023 | 17/6/2026 | A flaw was found in Binutils. A logic fail in the bfd_init_section_decompress_status function may lead to the use of an uninitialized variable that can cause a crash and local denial of service. | |
| Modificada | Media (5.5) | 0.38% | — | GNU Binutils | 14/9/2023 | 17/6/2026 | A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service. | |
| Modificada | Alta (7.1) | 0.38% | — | GNU Binutils | 14/9/2023 | 17/6/2026 | An out-of-bounds read flaw was found in the parse_module function in bfd/vms-alpha.c in Binutils. | |
| Modificada | Media (4.8) | 0.76% | — | GNU GCC | 13/9/2023 | 23/6/2026 | **DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker to exploit an existing buffer overflow in dynamically-sized local variables in your application without this being detected. This stack-protector failure only applies to C99-style dynamically-sized… | |
| Modificada | Media (5.9) | 1.9% | 💥 PoC | GNU GlibcRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems EUS S390x+12 | 12/9/2023 | 17/6/2026 | A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or… | |
| Modificada | Media (5.5) | 0.64% | — | GNU BinutilsNetapp Ontap Select Deploy Administration UtilityFedoraproject Fedora | 22/8/2023 | 17/6/2026 | GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c. | |
| Modificada | Media (5.5) | 0.61% | — | GNU BinutilsFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 22/8/2023 | 17/6/2026 | GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. | |
| Modificada | Media (5.5) | 0.46% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function load_separate_debug_files at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack. | |
| Modificada | Alta (7.8) | 0.42% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function compare_symbols. | |
| Modificada | Alta (7.8) | 0.45% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | An issue was discovered Binutils objdump before 2.39.3 allows attackers to cause a denial of service or other unspecified impacts via function bfd_mach_o_get_synthetic_symtab in match-o.c. | |
| Modificada | Alta (7.8) | 0.43% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | An issue was discovered in Binutils addr2line before 2.39.3, function parse_module contains multiple out of bound reads which may cause a denial of service or other unspecified impacts. | |
| Modificada | Media (5.5) | 0.39% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | An issue was discovered function parse_stab_struct_fields in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks. | |
| Modificada | Media (5.5) | 0.39% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | An issue was discovered function pr_function_type in prdbg.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks. | |
| Modificada | Media (5.5) | 0.39% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | An issue was discovered function make_tempdir, and make_tempname in bucomm.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks. | |
| Modificada | Media (5.5) | 0.40% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | An issue was discovered function stab_demangle_v3_arg in stabs.c in Binutils 2.34 thru 2.38, allows attackers to cause a denial of service due to memory leaks. | |
| Modificada | Alta (7.8) | 0.51% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | Heap buffer overflow vulnerability in binutils readelf before 2.40 via function display_debug_section in file readelf.c. | |
| Modificada | Alta (7.8) | 0.49% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | Heap buffer overflow vulnerability in binutils readelf before 2.40 via function find_section_in_set in file readelf.c. | |
| Modificada | Media (5.5) | 0.34% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | Null pointer dereference vulnerability in Binutils readelf 2.38.50 via function read_and_display_attr_value in file dwarf.c. | |
| Modificada | Media (5.5) | 0.39% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | An issue was discovered in Binutils readelf 2.38.50, reachable assertion failure in function display_debug_names allows attackers to cause a denial of service. | |
| Modificada | Alta (7.5) | 0.82% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | Heap-based Buffer Overflow in function bfd_getl32 in Binutils objdump 3.37. | |
| Modificada | Media (6.5) | 0.97% | — | GNU Scientific LibraryDebian Linux | 22/8/2023 | 17/6/2026 | A buffer overflow can occur when calculating the quantile value using the Statistics Library of GSL (GNU Scientific Library), versions 2.5 and 2.6. Processing a maliciously crafted input data for gsl_stats_quantile_from_sorted_data of the library may lead to unexpected application termination or arbitrary code… | |
| Modificada | Alta (7.5) | 0.77% | — | GNU Binutils | 22/8/2023 | 17/6/2026 | GNU Binutils before 2.34 has an uninitialized-heap vulnerability in function tic4x_print_cond (file opcodes/tic4x-dis.c) which could allow attackers to make an information leak. |