Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.0% | — | Miniupnp Project Ngiflib | 3/5/2018 | 17/6/2026 | The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 does not consider the bounds of the pixels data structure, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file, a… | |
| Modificada | Alta (8.8) | 1.5% | — | Miniupnp Project Ngiflib | 2/5/2018 | 17/6/2026 | The DecodeGifImg function in ngiflib.c in MiniUPnP ngiflib 0.4 lacks certain checks against width and height, which allows remote attackers to cause a denial of service (WritePixels heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted GIF file. | |
| Modificada | Alta (7.8) | 0.47% | — | Miniupnp Project Miniupnpd | 3/1/2018 | 17/6/2026 | Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact | |
| Modificada | Crítica (9.8) | 24% | 💥 Exploit | Miniupnp Project Miniupnpd | 11/5/2017 | 17/6/2026 | Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact. | |
| Modificada | Media (5.5) | 0.32% | — | Miniupnp Project Minissdpd | 24/3/2017 | 17/6/2026 | The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (invalid free and daemon crash) via vectors related to error handling. | |
| Modificada | Media (5.5) | 0.32% | — | Miniupnp Project Minissdpd | 24/3/2017 | 17/6/2026 | The processRequest function in minissdpd.c in MiniSSDPd 1.2.20130907-3 allows local users to cause a denial of service (out-of-bounds memory access and daemon crash) via vectors involving a negative length value. | |
| Modificada | Media (6.8) | 4.8% | — | Miniupnp Project MiniupnpcDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+1 | 2/11/2015 | 17/6/2026 | Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers to cause a denial of service (application crash) and possibly execute arbitrary code via an "oversized" XML element name. | |
| Modificada | Media (5) | 3.3% | — | Miniupnp Project MiniupnpOpensuse | 11/9/2014 | 17/6/2026 | The getHTTPResponse function in miniwget.c in MiniUPnP 1.9 allows remote attackers to cause a denial of service (crash) via crafted headers that trigger an out-of-bounds read. | |
| Modificada | Alta (7.8) | 1.8% | — | Miniupnp Project Miniupnpd | 31/1/2013 | 16/6/2026 | Integer signedness error in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (incorrect memory copy) via a SOAPAction header that lacks a " (double quote) character, a different vulnerability than CVE-2013-0230. | |
| Modificada | Alta (7.8) | 2.8% | — | Miniupnp Project Miniupnpd | 31/1/2013 | 16/6/2026 | The ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and service crash) via a SOAPAction header that lacks a # (pound sign) character, a different vulnerability than CVE-2013-0230. | |
| Modificada | Alta (10) | 69% | 💥 Exploit | Miniupnp Project Miniupnpd | 31/1/2013 | 16/6/2026 | Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method. | |
| Modificada | Alta (7.8) | 76% | 💥 Exploit | Miniupnp Project Miniupnpd | 31/1/2013 | 16/6/2026 | The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read. |