Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.3) | 0.30% | — | GNU Mailman | 15/4/2023 | 17/6/2026 | An issue was discovered in Mailman Core before 3.3.5. An attacker with access to the REST API could use timing attacks to determine the value of the configured REST API password and then make arbitrary REST API calls. The REST API is bound to localhost by default, limiting the ability for attackers to exploit this,… | |
| Modificada | Alta (7.1) | 0.51% | — | Nongnu Dmidecode | 13/4/2023 | 17/6/2026 | Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents… | |
| Modificada | Media (6.5) | 0.54% | 💥 Exploit | GNU Screen | 8/4/2023 | 17/6/2026 | socket.c in GNU Screen through 4.9.0, when installed setuid or setgid (the default on platforms such as Arch Linux and FreeBSD), allows local users to send a privileged SIGHUP signal to any PID, causing a denial of service or disruption of the target process. | |
| Modificada | Alta (7.8) | 0.49% | — | GNU Binutils | 3/4/2023 | 17/6/2026 | Heap based buffer overflow in binutils-gdb/bfd/libbfd.c in bfd_getl64. | |
| Modificada | Alta (7.8) | 0.47% | — | GNU ORG Mode | 19/3/2023 | 17/6/2026 | org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters. | |
| Modificada | Crítica (9.8) | 1.1% | — | Stoqey Gnuplot | 10/3/2023 | 17/6/2026 | An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s). | |
| Modificada | Alta (7.8) | 0.48% | — | GNU Emacs | 9/3/2023 | 17/6/2026 | emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90. | |
| Modificada | Alta (7.8) | 1.1% | — | GNU Emacs | 9/3/2023 | 17/6/2026 | emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90 | |
| Modificada | Alta (8.8) | 0.81% | — | GNU Libredwg | 1/3/2023 | 17/6/2026 | A heap-based buffer overflow vulnerability exits in GNU LibreDWG v0.12.5 via the bit_read_RC function at bits.c. | |
| Modificada | Media (5.9) | 1.3% | — | GNU Libmicrohttpd | 28/2/2023 | 17/6/2026 | GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data… | |
| Modificada | Alta (7.5) | 1.1% | — | MOD Gnutls Project MOD Gnutls | 23/2/2023 | 17/6/2026 | Mod_gnutls is a TLS module for Apache HTTPD based on GnuTLS. Versions from 0.9.0 to 0.12.0 (including) did not properly fail blocking read operations on TLS connections when the transport hit timeouts. Instead it entered an endless loop retrying the read operation, consuming CPU resources. This could be exploited for… | |
| Modificada | Baja (3.3) | 0.29% | — | Gnupg | 23/2/2023 | 17/6/2026 | GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB. | |
| Modificada | Alta (7.8) | 1.1% | — | GNU Emacs | 20/2/2023 | 17/6/2026 | An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection vulnerability. In the hfy-istext-command function, the parameter file and parameter srcdir come from external input, and parameters are not escaped. If a file name or directory name contains shell metacharacters, code may be… | |
| Modificada | Alta (7.3) | 1.6% | — | GNU Emacs | 20/2/2023 | 17/6/2026 | An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local command injection vulnerability. The ruby-find-library-file function is an interactive function, and bound to C-c C-f. Inside the function, the external command gem is called through… | |
| Modificada | Crítica (9.8) | 1.6% | — | GNU EmacsDebian Linux | 20/2/2023 | 17/6/2026 | GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command (suggested in the etags documentation) in… | |
| Modificada | Alta (7.5) | 0.67% | — | SIR Gnuboard | 20/2/2023 | 17/6/2026 | Gnuboard 5.5.4 and 5.5.5 is vulnerable to Insecure Permissions. An attacker can change password of all users without knowing victim's original password. | |
| Modificada | Alta (7.4) | 1.4% | — | GnutlsRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora+3 | 15/2/2023 | 17/6/2026 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount… | |
| Modificada | Alta (7.5) | 1.4% | — | GNU LessFedoraproject Fedora | 7/2/2023 | 17/6/2026 | In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal. | |
| Modificada | Crítica (9.8) | 1.1% | — | GNU Glibc | 6/2/2023 | 17/6/2026 | A vulnerability was found in GNU C Library 2.38. It has been declared as critical. This vulnerability affects the function __monstartup of the file gmon.c of the component Call Graph Monitor. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. VDB-220246 is the identifier… | |
| Modificada | Crítica (9.8) | 1.4% | — | GNU Glibc | 3/2/2023 | 17/6/2026 | sprintf in the GNU C Library (glibc) 2.37 has a buffer overflow (out-of-bounds write) in some situations with a correct buffer size. This is unrelated to CWE-676. It may write beyond the bounds of the destination buffer when attempting to write a padded, thousands-separated string representation of a number, if the… | |
| Modificada | Media (5.5) | 1.5% | — | GNU TARFedoraproject Fedora | 30/1/2023 | 17/6/2026 | GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters. | |
| Modificada | Media (5.5) | 0.44% | — | GNU BinutilsFedoraproject FedoraRedhat Enterprise Linux | 27/1/2023 | 17/6/2026 | An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599. | |
| Modificada | Crítica (9.8) | 1.6% | — | Gnupg LibksbaGpg4winGnupg Vs-desktopGnupg | 12/1/2023 | 17/6/2026 | A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment. | |
| Modificada | Alta (7.8) | 0.36% | — | GNU BashRedhat Enterprise Linux | 5/1/2023 | 17/6/2026 | A flaw was found in the bash package, where a heap-buffer overflow can occur in valid parameter_transform. This issue may lead to memory problems. | |
| Modificada | Crítica (9.8) | 1.6% | — | Gnupg LibksbaDebian Linux | 20/12/2022 | 17/6/2026 | Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser. |