Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

1563 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)1.0%—GNU Grub2Redhat Enterprise Linux19/12/202217/6/2026
When rendering certain unicode sequences, grub2's font code doesn't proper validate if the informed glyph's width and height is constrained within bitmap size. As consequence an attacker can craft an input which will lead to a out-of-bounds write into grub2's heap, leading to memory corruption and availability issues.…
ModificadaAlta (8.6)0.51%—GNU Grub2Fedoraproject FedoraRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Power Little Endian EUS+414/12/202217/6/2026
A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this further leads to a buffer overflow and a heap based out-of-bounds write. An attacker may use this…
ModificadaAlta (7.8)0.31%—GNU Libredwg30/11/202217/6/2026
LibreDWG v0.12.4.4643 was discovered to contain a heap buffer overflow via the function decode_preR13_section_hdr at decode_r11.c.
ModificadaAlta (7.8)0.66%—GNU EmacsDebian LinuxFedoraproject Fedora28/11/202217/6/2026
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a…
ModificadaMedia (5.4)0.42%—SIR Gnuboard12/11/202217/6/2026
A vulnerability was found in gnuboard5. It has been classified as problematic. Affected is an unknown function of the file bbs/faq.php of the component FAQ Key ID Handler. The manipulation of the argument fm_id leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 5.5.8.2.1…
ModificadaCrítica (9.1)2.2%—GNU Libtasn1Fedoraproject FedoraDebian Linux24/10/202217/6/2026
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
ModificadaMedia (6.5)0.58%—GNU Osip11/10/202217/6/2026
GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header.
ModificadaMedia (5.5)0.48%—GNU FribidiRedhat Enterprise Linux6/9/202217/6/2026
A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. This flaw allows an attacker to pass a specially crafted file to Fribidi, leading to a crash and causing a denial of service.
ModificadaMedia (5.5)0.50%—GNU FribidiRedhat Enterprise Linux6/9/202217/6/2026
A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option, leading to a crash and causing a denial…
ModificadaAlta (7.8)0.53%—GNU FribidiRedhat Enterprise Linux6/9/202217/6/2026
A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi application, which leads to a possible memory leak or a denial of service.
ModificadaAlta (7.8)0.51%—GNU PsppFedoraproject Fedora5/9/202217/6/2026
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
ModificadaAlta (7.8)0.52%—GNU PsppFedoraproject Fedora5/9/202217/6/2026
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. This issue is different from CVE-2018-20230.
ModificadaMedia (6.5)1.4%—GNU GCCFedoraproject Fedora1/9/202217/6/2026
Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a crafted mangled symbol.
ModificadaAlta (8.8)5.1%—GNU GzipRedhat Jboss Data GridDebian LinuxTukaani XZ31/8/202217/6/2026
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing…
ModificadaMedia (5.3)1.8%—GNU GlibcNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+331/8/202217/6/2026
An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap.
ModificadaAlta (7.5)2.1%—GNU InetutilsMIT Kerberos 5Debian LinuxNetkit-telnet Project Netkit-telnet30/8/202217/6/2026
telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many…
ModificadaMedia (5.5)0.33%—GNU BinutilsFedoraproject Fedora26/8/202217/6/2026
In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
ModificadaMedia (6.5)1.7%—GnutlsRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+124/8/202217/6/2026
A NULL pointer dereference flaw was found in GnuTLS. As Nettle's hash update functions internally call memcpy, providing zero-length input may cause undefined behavior. This flaw leads to a denial of service after authentication in rare circumstances.
ModificadaAlta (7.8)0.75%—GNU GlibcDebian LinuxNetapp E-series Performance AnalyzerNetapp NFS Plug-in+624/8/202217/6/2026
A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and…
ModificadaAlta (7.5)1.8%—GNU GlibcNetapp Ontap Select Deploy Administration UtilityNetapp H300s FirmwareNetapp H500s Firmware+324/8/202217/6/2026
A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data.
ModificadaCrítica (9.8)1.0%—GNU Libredwg18/8/202217/6/2026
LibreDWG v0.12.4.4608 & commit f2dea29 was discovered to contain a heap use-after-free via bit_copy_chain.
ModificadaAlta (8.8)0.38%—Mailerlite Signup Forms5/8/202217/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in MailerLite – Signup forms (official) plugin <= 1.5.7 at WordPress allows an attacker to change the API key.
ModificadaAlta (7.5)2.0%—GnutlsRedhat Enterprise LinuxFedoraproject FedoraDebian Linux1/8/202217/6/2026
A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.
ModificadaAlta (8.1)1.6%—GNU SaslDebian Linux19/7/202217/6/2026
GNU SASL libgsasl server-side read-out-of-bounds with malicious authenticated GSS-API client
ModificadaAlta (7)0.46%—GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+86/7/202217/6/2026
A crafted JPEG image may lead the JPEG reader to underflow its data pointer, allowing user-controlled data to be written in heap. To a successful to be performed the attacker needs to perform some triage over the heap layout and craft an image with a malicious format and payload. This vulnerability can lead to data…