Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.42%—Tuxera Ntfs-3gDebian LinuxRedhat Enterprise LinuxFedoraproject Fedora7/9/202117/6/2026
A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.
ModificadaAlta (7.8)0.49%—Tuxera Ntfs-3gDebian LinuxFedoraproject Fedora7/9/20219/7/2026
NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when setuid-root.
ModificadaAlta (7.8)0.49%—Tuxera Ntfs-3gDebian LinuxFedoraproject Fedora7/9/20219/7/2026
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution.
ModificadaAlta (7.8)0.41%—Tuxera Ntfs-3gDebian LinuxFedoraproject Fedora7/9/20219/7/2026
In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.
ModificadaAlta (7.8)0.46%—Tuxera Ntfs-3gDebian Linux7/9/20219/7/2026
In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.
ModificadaAlta (7.8)0.48%—Tuxera Ntfs-3gDebian LinuxFedoraproject Fedora7/9/20219/7/2026
NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
ModificadaAlta (7.8)0.47%—Tuxera Ntfs-3gDebian LinuxFedoraproject Fedora7/9/20219/7/2026
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
ModificadaAlta (7.8)0.49%—Tuxera Ntfs-3gDebian LinuxFedoraproject Fedora7/9/20219/7/2026
In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.
ModificadaAlta (7.8)0.41%—Tuxera Ntfs-3gRedhat Enterprise LinuxFedoraproject FedoraDebian Linux7/9/202117/6/2026
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted…
ModificadaAlta (7)0.53%—Tuxera Ntfs-3gRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+25/6/201917/6/2026
An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where…
ModificadaAlta (7.8)2.2%💥 ExploitTuxera Ntfs-3gDebian Linux13/4/201817/6/2026
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation.
ModificadaMedia (4.6)0.35%—Ntfs-3g1/10/200716/6/2026
The ntfs-3g package before 1.913-2.fc7 in Fedora 7, and an ntfs-3g package in Ubuntu 7.10/Gutsy, assign incorrect permissions (setuid root) to mount.ntfs-3g, which allows local users with fuse group membership to read from and write to arbitrary block devices, possibly involving a file descriptor leak.
Orbitaley — Vulnerabilidades