Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.7% | — | GNU Binutils | 19/6/2017 | 17/6/2026 | The process_otr function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not validate a certain offset, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via… | |
| Modificada | Alta (7.8) | 2.8% | — | GNU Binutils | 19/6/2017 | 17/6/2026 | The versados_mkobject function in bfd/versados.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, does not initialize a certain data structure, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified… | |
| Modificada | Alta (7.8) | 2.8% | — | GNU Binutils | 19/6/2017 | 17/6/2026 | bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file in… | |
| Modificada | Alta (7.8) | 3.0% | — | GNU Binutils | 19/6/2017 | 17/6/2026 | opcodes/rl78-decode.opc in GNU Binutils 2.28 has an unbounded GETBYTE macro, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. | |
| Modificada | Alta (7.8) | 8.1% | 💥 Exploit | GNU Binutils | 19/6/2017 | 17/6/2026 | opcodes/rx-decode.opc in GNU Binutils 2.28 lacks bounds checks for certain scale arrays, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump… | |
| Modificada | Alta (7.8) | 8.5% | 💥 Exploit | GNU Binutils | 19/6/2017 | 17/6/2026 | The *regs* macros in opcodes/bfin-dis.c in GNU Binutils 2.28 allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. | |
| Modificada | Alta (7.8) | 7.9% | 💥 Exploit | GNU Binutils | 19/6/2017 | 17/6/2026 | The ieee_object_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated… | |
| Modificada | Alta (7.8) | 7.9% | 💥 Exploit | GNU Binutils | 19/6/2017 | 17/6/2026 | The ieee_archive_p function in bfd/ieee.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, might allow remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated… | |
| Modificada | Alta (7.8) | 8.5% | 💥 Exploit | GNU Binutils | 19/6/2017 | 17/6/2026 | The disassemble_bytes function in objdump.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of rae insns printing for this file during "objdump -D"… | |
| Modificada | Alta (7.8) | 2.7% | — | GNU Binutils | 19/6/2017 | 17/6/2026 | The _bfd_vms_slurp_etir function in bfd/vms-alpha.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as… | |
| Modificada | Alta (7.8) | 2.8% | — | GNU Binutils | 19/6/2017 | 17/6/2026 | The sh_elf_set_mach_from_flags function in bfd/elf32-sh.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as… | |
| Modificada | Alta (7.8) | 2.8% | — | GNU Binutils | 19/6/2017 | 17/6/2026 | The print_insn_score32 function in opcodes/score7-dis.c:552 in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. | |
| Modificada | Alta (7.8) | 8.1% | 💥 Exploit | GNU Binutils | 19/6/2017 | 17/6/2026 | The score_opcodes function in opcodes/score7-dis.c in GNU Binutils 2.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, as demonstrated by mishandling of this file during "objdump -D" execution. | |
| Modificada | Media (5.5) | 1.6% | — | GNU Binutils | 18/5/2017 | 17/6/2026 | The print_symbol_for_build_attribute function in readelf.c in GNU Binutils 2017-04-12 allows remote attackers to cause a denial of service (invalid read and SEGV) via a crafted ELF file. | |
| Modificada | Alta (7.8) | 2.1% | — | GNU Binutils | 18/5/2017 | 17/6/2026 | readelf.c in GNU Binutils 2017-04-12 has a "shift exponent too large for type unsigned long" issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file. | |
| Modificada | Alta (7.8) | 2.1% | — | GNU Binutils | 18/5/2017 | 17/6/2026 | readelf.c in GNU Binutils 2017-04-12 has a "cannot be represented in type long" issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted ELF file. | |
| Modificada | Media (5.5) | 1.9% | — | GNU Binutils | 18/5/2017 | 17/6/2026 | GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to MIPS GOT mishandling in the process_mips_specific function in readelf.c. | |
| Modificada | Media (5.5) | 2.1% | — | GNU Binutils | 18/5/2017 | 17/6/2026 | GNU Binutils 2017-04-03 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash), related to the process_mips_specific function in readelf.c, via a crafted ELF file that triggers a large memory-allocation attempt. | |
| Modificada | Media (5.5) | 2.1% | — | GNU Binutils | 18/5/2017 | 17/6/2026 | GNU Binutils 2.28 allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file with many program headers, related to the get_program_headers function in readelf.c. | |
| Modificada | Media (5.5) | 2.1% | — | GNU Binutils | 18/5/2017 | 17/6/2026 | GNU Binutils 2.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file, related to the byte_get_little_endian function in elfcomm.c, the get_unwind_section_word function in readelf.c, and ARM unwind information that contains invalid word… | |
| Modificada | Crítica (9.8) | 2.5% | — | Keycloak-nodejs-auth-utils | 12/5/2017 | 17/6/2026 | It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks. | |
| Modificada | Media (5.5) | 0.96% | — | GNU Binutils | 2/5/2017 | 17/6/2026 | The function coff_set_alignment_hook in coffcode.h in Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a memory leak vulnerability which can cause memory exhaustion in objdump via a crafted PE file. Additional validation in dump_relocs_in_section in objdump.c can resolve this. | |
| Modificada | Alta (7.5) | 2.0% | — | GNU Binutils | 1/5/2017 | 17/6/2026 | dwarf.c in GNU Binutils 2.28 is vulnerable to an invalid read of size 1 during dumping of debug information from a corrupt binary. This vulnerability causes programs that conduct an analysis of binary programs, such as objdump and readelf, to crash. | |
| Modificada | Alta (7.5) | 1.9% | — | GNU Binutils | 1/5/2017 | 17/6/2026 | The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 and an invalid write of size 1 during processing of a corrupt binary containing reloc(s) with negative addresses. This vulnerability causes programs that conduct an analysis of binary… | |
| Modificada | Alta (7.5) | 1.8% | — | GNU Binutils | 1/5/2017 | 17/6/2026 | The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read of size 1 because the existing reloc offset range tests didn't catch small negative offsets less than the size of the reloc field. This vulnerability causes programs that conduct an analysis of… |