Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

43 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)2.6%—Universityofcalifornia Boinc Client2/6/201416/6/2026
Multiple stack-based buffer overflows in the XML parser in BOINC 7.x allow attackers to have unspecified impact via a crafted XML file, related to the scheduler.
ModificadaAlta (9.3)2.3%—Universityofcalifornia Boinc Client2/6/201416/6/2026
Stack-based buffer overflow in BOINC 6.10.58 and 6.12.34 allows remote attackers to have unspecified impact via multiple file_signature elements.
ModificadaMedia (5)2.7%—Universityofcalifornia Boinc Client2/6/201416/6/2026
Multiple stack-based buffer overflows in BOINC 6.13.x allow remote attackers to cause a denial of service (crash) via a long trickle-up to (1) client/cs_trickle.cpp or (2) db/db_base.cpp.
ModificadaMedia (5.8)0.99%—Openstack Python GlanceclientOpensuse28/8/201316/6/2026
The Python client library for Glance (python-glanceclient) before 0.10.0 does not properly check the preverify_ok value, which prevents the server hostname from being verified with a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate and allows man-in-the-middle attackers to…
ModificadaAlta (9.3)42%—Scadaengine Bacnet OPC Client16/2/201116/6/2026
Stack-based buffer overflow in WTclient.dll in SCADA Engine BACnet OPC Client before 1.0.25 allows user-assisted remote attackers to execute arbitrary code via a crafted .csv file, related to a status log message.
ModificadaAlta (7.5)4.5%—Silcnet Silc ClientSilcnet Silc Toolkit10/9/200916/6/2026
Multiple format string vulnerabilities in lib/silcclient/command.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client 1.1.8 and earlier, allow remote attackers to execute arbitrary code via format string specifiers in a channel name, related to (1) silc_client_command_topic, (2)…
ModificadaAlta (7.5)4.8%—Silcnet Silc ClientSilcnet Silc Toolkit10/9/200916/6/2026
Multiple format string vulnerabilities in lib/silcclient/client_entry.c in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.10, and SILC Client before 1.1.8, allow remote attackers to execute arbitrary code via format string specifiers in a nickname field, related to the (1) silc_client_add_client, (2)…
RechazadaSin puntuar——University OF Washington C-clientAIUniversity OF Washington Imap ToolkitAI22/2/20097/11/2023
Rejected reason: Format string vulnerability in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit imap-2007d and other applications, allows remote attackers to execute arbitrary code via format string specifiers in the initial request to the IMAP port (143/tcp). NOTE: Red Hat has…
ModificadaMedia (5)2.4%—Berkeley Boinc Client15/1/200916/6/2026
The decrypt_public function in lib/crypt.cpp in the client in Berkeley Open Infrastructure for Network Computing (BOINC) 6.2.14 and 6.4.5 does not check the return value from the OpenSSL RSA_public_decrypt function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS…
ModificadaMedia (5)1.4%—Nortel SIP Multimedia PC Client11/7/200816/6/2026
Nortel SIP Multimedia PC Client 4.x MCS5100 and MCS5200 does not limit the number of concurrent sessions, which allows attackers to cause a denial of service (resource consumption) via a large number of sessions.
ModificadaAlta (7.5)5.0%—T0pp8uzz Dana IRC Client30/6/200816/6/2026
Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long IRC message.
ModificadaMedia (6.8)4.1%—Silc ClientSilc ServerSilc ToolkitSilc31/3/200816/6/2026
The silc_pkcs1_decode function in the silccrypt library (silcpkcs1.c) in Secure Internet Live Conferencing (SILC) Toolkit before 1.1.7, SILC Client before 1.1.4, and SILC Server before 1.1.2 allows remote attackers to execute arbitrary code via a crafted PKCS#1 message, which triggers an integer underflow, signedness…
ModificadaMedia (5)2.8%—Silc ClientSilc Toolkit12/7/200716/6/2026
Buffer overflow in lib/silcclient/client_notify.c of SILC Client and SILC Toolkit before 1.1.2 allows remote attackers to cause a denial of service via "NICK_CHANGE" notifications.
ModificadaAlta (9.3)3.2%—Kvirc IRC Client26/6/200716/6/2026
The parseIrcUrl function in src/kvirc/kernel/kvi_ircurl.cpp in KVIrc 3.2.0 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an (1) irc:// or (2) irc6:// URI.
ModificadaAlta (7.8)1.9%—Nortel PC Client Soft Phone SIP22/6/200716/6/2026
The Nortel PC Client SIP Soft Phone 4.1 3.5.208[20051015] allows remote attackers to cause a denial of service (device crash) via a SIP message with a malformed header.
ModificadaMedia (4.6)0.35%—Daiki Ueno Liece Emacs IRC Client18/8/200316/6/2026
The liece Emacs IRC client 2.0+0.20030527 and earlier creates temporary files insecurely, which could allow local users to overwrite arbitrary files as other users.
ModificadaAlta (7.5)2.7%—University OF Washington C-clientUniversity OF Washington Imap-2002bUniversity OF Washington Pine16/6/200316/6/2026
c-client IMAP Client, as used in imap-2002b and Pine 4.53, allows remote malicious IMAP servers to cause a denial of service (crash) and possibly execute arbitrary code via certain large (1) literal and (2) mailbox size values that cause either integer signedness errors or integer overflow errors.
ModificadaMedia (5)1.6%—Kvirc IRC Client24/9/199916/6/2026
Directory traversal vulnerability in KVIrc IRC client 0.9.0 with the "Listen to !nick <soundname> requests" option enabled allows remote attackers to read arbitrary files via a .. (dot dot) in a DCC GET request.