Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.42% | — | Tuxera Ntfs-3gDebian LinuxRedhat Enterprise LinuxFedoraproject Fedora | 7/9/2021 | 17/6/2026 | A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22. | |
| Modificada | Alta (7.8) | 0.49% | — | Tuxera Ntfs-3gDebian LinuxFedoraproject Fedora | 7/9/2021 | 9/7/2026 | NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when setuid-root. | |
| Modificada | Alta (7.8) | 0.49% | — | Tuxera Ntfs-3gDebian LinuxFedoraproject Fedora | 7/9/2021 | 9/7/2026 | In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution. | |
| Modificada | Alta (7.8) | 0.41% | — | Tuxera Ntfs-3gDebian LinuxFedoraproject Fedora | 7/9/2021 | 9/7/2026 | In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application. | |
| Modificada | Alta (7.8) | 0.46% | — | Tuxera Ntfs-3gDebian Linux | 7/9/2021 | 9/7/2026 | In NTFS-3G versions < 2021.8.22, when a specially crafted unicode string is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution. | |
| Modificada | Alta (7.8) | 0.48% | — | Tuxera Ntfs-3gDebian LinuxFedoraproject Fedora | 7/9/2021 | 9/7/2026 | NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overflow can occur allowing for code execution and escalation of privileges. | |
| Modificada | Alta (7.8) | 0.47% | — | Tuxera Ntfs-3gDebian LinuxFedoraproject Fedora | 7/9/2021 | 9/7/2026 | In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges. | |
| Modificada | Alta (7.8) | 0.49% | — | Tuxera Ntfs-3gDebian LinuxFedoraproject Fedora | 7/9/2021 | 9/7/2026 | In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution. | |
| Modificada | Alta (7.8) | 0.41% | — | Tuxera Ntfs-3gRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 7/9/2021 | 17/6/2026 | In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted… | |
| Modificada | Alta (7) | 0.53% | — | Tuxera Ntfs-3gRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+2 | 5/6/2019 | 17/6/2026 | An integer underflow issue exists in ntfs-3g 2017.3.23. A local attacker could potentially exploit this by running /bin/ntfs-3g with specially crafted arguments from a specially crafted directory to cause a heap buffer overflow, resulting in a crash or the ability to execute arbitrary code. In installations where… | |
| Modificada | Alta (7.8) | 2.2% | 💥 Exploit | Tuxera Ntfs-3gDebian Linux | 13/4/2018 | 17/6/2026 | Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation. | |
| Modificada | Media (4.6) | 0.35% | — | Ntfs-3g | 1/10/2007 | 16/6/2026 | The ntfs-3g package before 1.913-2.fc7 in Fedora 7, and an ntfs-3g package in Ubuntu 7.10/Gutsy, assign incorrect permissions (setuid root) to mount.ntfs-3g, which allows local users with fuse group membership to read from and write to arbitrary block devices, possibly involving a file descriptor leak. |