Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.3% | — | Libsndfile Project LibsndfileDebian Linux | 30/4/2017 | 17/6/2026 | The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file. | |
| Modificada | Media (6.5) | 3.4% | — | Libsndfile Project LibsndfileDebian Linux | 30/4/2017 | 17/6/2026 | The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file. | |
| Modificada | Alta (8.8) | 3.9% | — | Libsndfile Project LibsndfileDebian Linux | 30/4/2017 | 17/6/2026 | The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file. | |
| Modificada | Media (5.5) | 1.4% | — | Libsndfile Project Libsndfile | 12/4/2017 | 17/6/2026 | In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with read memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585. | |
| Modificada | Media (5.5) | 1.3% | — | Libsndfile Project Libsndfile | 12/4/2017 | 17/6/2026 | In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585. | |
| Modificada | Media (5.5) | 1.2% | — | Libsndfile Project Libsndfile | 7/4/2017 | 17/6/2026 | In libsndfile before 1.0.28, an error in the "header_read()" function (common.c) when handling ID3 tags can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file. | |
| Modificada | Media (5.5) | 1.4% | — | Libsndfile Project Libsndfile | 7/4/2017 | 17/6/2026 | In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file. | |
| Modificada | Media (5) | 2.8% | — | Libsndfile Project LibsndfileCanonical Ubuntu LinuxOpensuse LeapOpensuse | 19/11/2015 | 17/6/2026 | The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable. | |
| Modificada | Alta (9.3) | 13% | — | OpensuseMega-nerd Libsndfile | 17/11/2015 | 17/6/2026 | Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file. | |
| Modificada | Baja (2.1) | 0.58% | — | Libsndfile Project LibsndfileOpensuseDebian LinuxCanonical Ubuntu Linux+1 | 16/1/2015 | 17/6/2026 | The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read. | |
| Modificada | Media (6.8) | 4.6% | — | Mega-nerd Libsndfile | 27/7/2011 | 16/6/2026 | Integer overflow in libsndfile before 1.0.25 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PARIS Audio Format (PAF) file that triggers a heap-based buffer overflow. | |
| Modificada | Media (4.3) | 1.4% | — | Mega-nerd Libsndfile | 6/5/2010 | 16/6/2026 | The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, (5) float32_init, and (6) sds_read_header functions in libsndfile 1.0.20 allow context-dependent attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted audio file. | |
| Modificada | Alta (9.3) | 6.5% | — | Mega-nerd LibsndfileNullsoft Winamp | 26/5/2009 | 16/6/2026 | Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value. | |
| Modificada | Alta (9.3) | 8.2% | — | Mega-nerd LibsndfileNullsoft Winamp | 26/5/2009 | 16/6/2026 | Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value. | |
| Modificada | Alta (9.3) | 3.6% | — | Nullsoft WinampMega-nerd Libsndfile | 5/3/2009 | 16/6/2026 | Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 4.5% | — | Mega-nerd Libsndfile | 19/9/2007 | 16/6/2026 | Heap-based buffer overflow in the flac_buffer_copy function in libsndfile 1.0.17 and earlier might allow remote attackers to execute arbitrary code via a FLAC file with crafted PCM data containing a block with a size that exceeds the previous block size. |