Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
1560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.7) | 0.30% | — | GNU C LibraryAI | 14/9/2026 | 18/9/2026 | Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding. Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination… | |
| Analizada | Baja (0.9) | 0.20% | — | GNU Binutils | 14/9/2026 | 18/9/2026 | A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer… | |
| Analizada | Baja (1.9) | 0.20% | — | GNU Binutils | 14/9/2026 | 18/9/2026 | A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been… | |
| Analizada | Baja (1.9) | 0.18% | — | GNU Binutils | 14/9/2026 | 18/9/2026 | A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was… | |
| Analizada | Baja (1.9) | 0.21% | — | GNU Binutils | 14/9/2026 | 18/9/2026 | A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for… | |
| Aplazada | Baja (1.9) | 0.17% | — | GNU LibredwgAI | 14/9/2026 | 15/9/2026 | A security flaw has been discovered in GNU libredwg 0.13.4. This impacts the function DWG_TABLE of the file src/dwg.spec of the component Layer Encoding. Performing a manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public and may be used… | |
| Pendiente de análisis | Media (4.2) | 0.27% | — | GNU GlibcAI | 11/9/2026 | 11/9/2026 | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of this bug needs a system that has nscd enabled and using an untrusted DNS server for name… | |
| Pendiente de análisis | Alta (7) | 0.13% | — | GNU GDBAI | 31/8/2026 | 29/9/2026 | A flaw was found in GDB's STABS debug format parser. The read_member_functions() function in gdb/stabsread.c contains a linked list removal bug in the code that separates destructor and non-destructor member functions of C++ classes. The bug causes the destructor entries to remain in the main function list while the… | |
| Pendiente de análisis | Media (4.9) | 0.14% | — | GNU C LibraryAI | 27/8/2026 | 3/9/2026 | Passing an effectively empty string to the `,ccs=` syntax extension of the mode argument in the `fopen` function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled. This usage pattern is not seen in applications in common… | |
| Pendiente de análisis | Alta (7.8) | 0.14% | — | GNU EmacsAI | 25/8/2026 | 28/8/2026 | A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted filenames. This occurs because TRAMP concatenates login arguments without proper sanitization, which are then passed to a local shell. Successful exploitation could lead to arbitrary code execution. | |
| Aplazada | Media (5.1) | 0.38% | — | GNU WgetAI | 25/8/2026 | 28/8/2026 | GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to… | |
| Aplazada | Media (6.9) | 0.13% | — | GNU EmacsAI | 21/8/2026 | 24/9/2026 | GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplying a crafted image with large dimensions and an elevated max color index. The image loader multiplies image dimensions and channel count using signed integer arithmetic;… | |
| Aplazada | Media (5.3) | 0.36% | — | GNU RushAI | 21/8/2026 | 27/8/2026 | Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: through 21082026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Aplazada | Alta (8.8) | 0.66% | — | TermixAIGNU TARAI | 19/8/2026 | 9/9/2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the archive creation endpoint in src/backend/ssh/file-manager.ts passes selected file basenames to tar without an end-of-options marker and without making the operands unambiguously relative. A… | |
| Pendiente de análisis | Baja (2.1) | 0.15% | — | GNU C LibraryAI | 10/8/2026 | 3/9/2026 | Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process. | |
| Aplazada | Media (5.3) | 0.45% | — | GNU EmacsAI | 10/8/2026 | 28/8/2026 | GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to an incorrect comparison variable in the read-length check, a crafted font file that claims to contain more table directory entries than actually present causes the parser to return a struct with… | |
| Aplazada | Media (5.3) | 0.67% | — | GNU EmacsAI | 10/8/2026 | 28/8/2026 | GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a 32-bit length value from a TrueType font file without overflow checking. On 32-bit targets, a crafted font causes the calculation to wrap, resulting in an undersized heap… | |
| Aplazada | Media (5.3) | 0.67% | — | GNU EmacsAI | 10/8/2026 | 28/8/2026 | GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueType font file, an unguarded addition in the xmalloc allocation call wraps around on 32-bit builds, causing a heap buffer overflow write. An attacker can deliver a… | |
| Aplazada | Media (5.3) | 0.54% | — | GNU EmacsAI | 10/8/2026 | 28/8/2026 | GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_simple_glyph() and sfnt_vary_compound_glyph() uses a strict greater-than comparison instead of greater-than-or-equal, allowing a crafted TrueType variable font to bypass… | |
| Aplazada | Media (4.6) | 0.18% | — | GNU CpioAI | 10/8/2026 | 28/8/2026 | GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline… | |
| Aplazada | Media (4.6) | 0.18% | — | GNU CpioAI | 10/8/2026 | 28/8/2026 | GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname during extraction. A malicious cpio archive containing a sufficiently long… | |
| Aplazada | Media (4.6) | 0.20% | — | GNU CpioAI | 10/8/2026 | 28/8/2026 | GNU cpio contains a Path Traversal vulnerability in its tar archive extraction functionality. When extracting a tar archive in copy-in mode with the --no-absolute-filenames option, the extracted file name is normalized but the tar hard-link target is passed to the link_to_name function without equivalent sanitization… | |
| Modificada | Media (4.4) | 0.08% | — | GNU TARRedhat Openshift Container PlatformRedhat Enterprise Linux | 3/8/2026 | 22/9/2026 | A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or… | |
| Modificada | Media (4.4) | 0.14% | — | GNU TARRedhat Openshift Container PlatformRedhat Enterprise Linux | 3/8/2026 | 22/9/2026 | A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with… | |
| Analizada | Media (4.6) | 0.18% | — | GNU Bison | 29/7/2026 | 24/8/2026 | GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this behavior allows directing generated files to… |