Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.4% | — | Leptonica | 19/2/2018 | 17/6/2026 | An issue was discovered in pixHtmlViewer in prog/htmlviewer.c in Leptonica before 1.75.3. Unsanitized input (rootname) can overflow a buffer, leading potentially to arbitrary code execution or possibly unspecified other impact. | |
| Modificada | Crítica (9.8) | 3.4% | — | LeptonicaDebian Linux | 16/2/2018 | 17/6/2026 | Leptonica before 1.75.3 does not limit the number of characters in a %s format argument to fscanf or sscanf, which allows remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string, as demonstrated by the gplotRead and ptaReadStream functions. | |
| Modificada | Media (5.5) | 0.92% | — | Dropbox Lepton | 10/5/2017 | 17/6/2026 | Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads. | |
| Modificada | Media (5.5) | 1.2% | — | Dropbox Lepton | 5/4/2017 | 17/6/2026 | The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image. | |
| Modificada | Media (5.5) | 0.87% | — | Lepton Project Lepton | 2/2/2017 | 17/6/2026 | The write_ujpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds read) via a crafted jpeg file. | |
| Modificada | Media (5.5) | 0.87% | — | Lepton Project Lepton | 2/2/2017 | 17/6/2026 | The build_huffcodes function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause denial of service (out-of-bounds write) via a crafted jpeg file. | |
| Modificada | Media (5.5) | 0.87% | — | Lepton Project Lepton | 2/2/2017 | 17/6/2026 | The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted jpeg file. | |
| Modificada | Media (5.5) | 0.87% | — | Lepton Project Lepton | 2/2/2017 | 17/6/2026 | The setup_imginfo_jpg function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted jpeg file. | |
| Modificada | Media (5.5) | 0.87% | — | Lepton Project Lepton | 2/2/2017 | 17/6/2026 | The process_file function in lepton/jpgcoder.cc in Dropbox lepton 1.0 allows remote attackers to cause a denial of service (crash) via a crafted jpeg file. | |
| Modificada | Media (4.3) | 1.1% | — | Lepton-cms Lepton | 24/2/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to admins/login/forgot/index.php, or the (2) display_name or (3) email parameter to account/preferences.php. | |
| Modificada | Alta (7.5) | 1.2% | — | Lepton-cms Lepton | 24/2/2012 | 16/6/2026 | SQL injection vulnerability in modules/news/rss.php in LEPTON before 1.1.4 allows remote attackers to execute arbitrary SQL commands via the group_id parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Lepton-cms Lepton | 24/2/2012 | 16/6/2026 | Directory traversal vulnerability in account/preferences.php in LEPTON before 1.1.4 allows remote attackers to include and execute arbitrary files via a .. (dot dot) in the language parameter. | |
| Modificada | Media (4.3) | 0.84% | — | Lepton-cms LeptonWebsitebaker2 Websitebaker | 2/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in WebsiteBaker before 2.8, as used in LEPTON and possibly other products, allows remote attackers to inject arbitrary web script or HTML via unknown vectors, a different vulnerability than CVE-2006-2307. |