Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 29% | — | Canonical Ubuntu LinuxOpensuseGNU Libtasn1Fedoraproject Fedora | 5/5/2016 | 17/6/2026 | The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.8, when used without the ASN1_DECODE_FLAG_STRICT_DER flag, allows remote attackers to cause a denial of service (infinite recursion) via a crafted certificate. | |
| Modificada | Media (4.3) | 33% | — | OpensuseFedoraproject FedoraGNU Libtasn1 | 12/5/2015 | 17/6/2026 | The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate. | |
| Modificada | Alta (10) | 7.7% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraGNU Libtasn1 | 10/4/2015 | 17/6/2026 | Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors. | |
| Modificada | Media (5) | 3.8% | — | GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+10 | 5/6/2014 | 17/6/2026 | The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument. | |
| Modificada | Alta (7.5) | 3.8% | — | GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+11 | 5/6/2014 | 17/6/2026 | The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data. | |
| Modificada | Media (5) | 6.8% | — | GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+11 | 5/6/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data. | |
| Modificada | Media (5) | 4.4% | — | GnutlsGNU Libtasn1 | 26/3/2012 | 16/6/2026 | The asn1_get_length_der function in decoding.c in GNU Libtasn1 before 2.12, as used in GnuTLS before 3.0.16 and other products, does not properly handle certain large length values, which allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly have unspecified… | |
| Modificada | Alta (7.5) | 3.9% | — | Free Software Foundation Inc. Libtasn1 | 10/2/2006 | 16/6/2026 | Tiny ASN.1 Library (libtasn1) before 0.2.18, as used by (1) GnuTLS 1.2.x before 1.2.10 and 1.3.x before 1.3.4, and (2) GNU Shishi, allows attackers to crash the DER decoder and possibly execute arbitrary code via "out-of-bounds access" caused by invalid input, as demonstrated by the ProtoVer SSL test suite. | |
| Modificada | Alta (10) | 2.0% | — | Free Software Foundation Inc. Libtasn1 | 7/7/2004 | 16/6/2026 | Unknown vulnerability in libtasn1 0.1.x before 0.1.2, and 0.2.x before 0.2.7, related to the DER parsing functions. |