Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.7% | — | Trusteddomain OpendmarcFedoraproject Fedora | 10/6/2021 | 17/6/2026 | OpenDMARC 1.4.1 and 1.4.1.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a multi-value From header field. | |
| Analizada | Media (5.5) | 3.1% | ⚠ Explotación activa | Trustedfirmware Trusted Firmware-m | 25/5/2021 | 17/6/2026 | In Arm Trusted Firmware M through 1.2, the NS world may trigger a system halt, an overwrite of secure data, or the printing out of secure data when calling secure functions under the NSPE handler mode. | |
| Analizada | Alta (7.5) | 1.8% | — | Trustedfirmware Trusted Firmware-m | 21/5/2021 | 17/6/2026 | In Trusted Firmware-M through 1.3.0, cleaning up the memory allocated for a multi-part cryptographic operation (in the event of a failure) can prevent the abort() operation in the associated cryptographic library from freeing internal resources, causing a memory leak. | |
| Modificada | Crítica (9.1) | 2.2% | — | Virustotal YaraFedoraproject Fedora | 14/5/2021 | 17/6/2026 | An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could allow an attacker to either cause denial of service or information disclosure via a malicious Mach-O file. Affects all versions before libyara 4.0.4 | |
| Modificada | Crítica (9.8) | 2.9% | — | Rust-lang RustFedoraproject Fedora | 14/4/2021 | 17/6/2026 | In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics. | |
| Modificada | Alta (8.2) | 2.0% | — | Rust-lang RustFedoraproject Fedora | 14/4/2021 | 17/6/2026 | In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to crash) if the borrowed string changes after its length is checked. | |
| Modificada | Media (5.9) | 1.1% | — | Rust-lang Rust | 14/4/2021 | 17/6/2026 | In the standard library in Rust before 1.29.0, there is weak synchronization in the Arc::get_mut method. This synchronization issue can be lead to memory safety issues through race conditions. | |
| Modificada | Media (5.9) | 0.80% | — | Rust-lang Rust | 14/4/2021 | 17/6/2026 | In the standard library in Rust before 1.19.0, there is a synchronization problem in the MutexGuard object. MutexGuards can be used across threads with any types, allowing for memory safety issues through race conditions. | |
| Modificada | Crítica (9.8) | 2.4% | — | Rust-lang RustFedoraproject Fedora | 11/4/2021 | 17/6/2026 | In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow. This bug can lead to a buffer overflow when a consumed Zip iterator is used again. | |
| Modificada | Alta (7.5) | 2.0% | — | Rust-lang RustFedoraproject Fedora | 11/4/2021 | 17/6/2026 | In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked() more than once for the same index (under certain conditions) when next_back() and next() are used together. This bug could lead to a memory safety violation due to an unmet safety requirement for the… | |
| Modificada | Alta (7.5) | 1.4% | — | Rust-lang Rust | 11/4/2021 | 17/6/2026 | In the standard library in Rust before 1.51.0, the Zip implementation calls __iterator_get_unchecked() for the same index more than once when nested. This bug can lead to a memory safety violation due to an unmet safety requirement for the TrustedRandomAccess trait. | |
| Modificada | Media (5.3) | 1.6% | — | Rust-lang RustFedoraproject Fedora | 11/4/2021 | 17/6/2026 | In the standard library in Rust before 1.52.0, the Zip implementation has a panic safety issue. It calls __iterator_get_unchecked() more than once for the same index when the underlying iterator panics (in certain conditions). This bug could lead to a memory safety violation due to an unmet safety requirement for the… | |
| Modificada | Alta (7.5) | 2.1% | — | Rust-lang Rust | 11/4/2021 | 17/6/2026 | In the standard library in Rust before 1.50.0, read_to_end() does not validate the return value from Read in an unsafe context. This bug could lead to a buffer overflow. | |
| Modificada | Crítica (9.8) | 1.7% | — | Rust-lang Rust | 11/4/2021 | 17/6/2026 | In the standard library in Rust before 1.49.0, VecDeque::make_contiguous has a bug that pops the same element more than once under certain condition. This bug could result in a use-after-free or double free. | |
| Modificada | Alta (7.5) | 1.5% | — | Rust-lang Rust | 11/4/2021 | 17/6/2026 | In the standard library in Rust before 1.49.0, String::retain() function has a panic safety problem. It allows creation of a non-UTF-8 Rust string when the provided closure panics. This bug could result in a memory safety violation when other string APIs assume that UTF-8 encoding is used on the same string. | |
| Modificada | Alta (7.5) | 1.3% | — | Rust-lang Rust | 11/4/2021 | 17/6/2026 | In the standard library in Rust before 1.2.0, BinaryHeap is not panic-safe. The binary heap is left in an inconsistent state when the comparison of generic elements inside sift_up or sift_down_range panics. This bug leads to a drop of zeroed memory as an arbitrary type, which can result in a memory safety violation. | |
| Analizada | Alta (7.8) | 100% | ⚠ Explotación activa💥 Exploit | Sudo Project SudoFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+20 | 26/1/2021 | 17/6/2026 | Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character. | |
| Modificada | Media (6.1) | 0.81% | — | Rust-lang Async-h1 | 26/1/2021 | 17/6/2026 | An issue was discovered in the async-h1 crate before 2.3.0 for Rust. Request smuggling can occur when used behind a reverse proxy. | |
| Modificada | Media (6.1) | 1.3% | — | Rust-lang Mdbook | 4/1/2021 | 17/6/2026 | mdBook is a utility to create modern online books from Markdown files and is written in Rust. In mdBook before version 0.4.5, there is a vulnerability affecting the search feature of mdBook, which could allow an attacker to execute arbitrary JavaScript code on the page. The search feature of mdBook (introduced in… | |
| Modificada | Alta (7.5) | 1.4% | — | Tokio-rustls | 31/12/2020 | 17/6/2026 | An issue was discovered in the tokio-rustls crate before 0.13.1 for Rust. Excessive memory usage may occur when data arrives quickly. | |
| Modificada | Alta (7.5) | 1.5% | — | Trust-dns-server Project Trust-dns-server | 31/12/2020 | 17/6/2026 | An issue was discovered in the trust-dns-server crate before 0.18.1 for Rust. DNS MX and SRV null targets are mishandled, causing stack consumption. | |
| Modificada | Media (5.5) | 0.40% | — | Rust-lang Socket2 | 31/12/2020 | 17/6/2026 | An issue was discovered in the socket2 crate before 0.3.16 for Rust. It has false expectations about the std::net::SocketAddr memory representation. | |
| Modificada | Media (5.5) | 0.34% | — | Rust-lang Future-utils | 31/12/2020 | 17/6/2026 | An issue was discovered in the futures-util crate before 0.3.2 for Rust. FuturesUnordered can lead to data corruption because Sync is mishandled. | |
| Modificada | Media (5.5) | 0.41% | — | Rust-lang Futures-task | 31/12/2020 | 17/6/2026 | An issue was discovered in the futures-task crate before 0.3.5 for Rust. futures_task::noop_waker_ref allows a NULL pointer dereference. | |
| Analizada | Alta (7.8) | 0.50% | — | Rust-lang Futures-task | 31/12/2020 | 17/6/2026 | An issue was discovered in the futures-task crate before 0.3.6 for Rust. futures_task::waker may cause a use-after-free in a non-static type situation. |