Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 1.3% | — | Google ProtobufAI | 5/3/2024 | 23/9/2026 | The protojson.Unmarshal function can enter an infinite loop when unmarshaling certain forms of invalid JSON. This condition can occur when unmarshaling into a message which contains a google.protobuf.Any value, or when the UnmarshalOptions.DiscardUnknown option is set. | |
| Modificada | Crítica (9.8) | 1.7% | — | Protobufjs Project Protobufjs | 5/7/2023 | 17/6/2026 | "protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-2022-25878. A user-controlled protobuf message can be used by an attacker to pollute the prototype of Object.prototype by adding and overwriting its data and functions. Exploitation can involve:… | |
| Modificada | Alta (7.5) | 1.1% | — | Protobuf | 8/6/2023 | 17/6/2026 | Parsing invalid messages can panic. Parsing a text-format message which contains a potential number consisting of a minus sign, one or more characters of whitespace, and no further input will cause a panic. | |
| Modificada | Media (5.5) | 0.37% | — | Protobuf-c Project Protobuf-c | 13/4/2023 | 17/6/2026 | protobuf-c before 1.4.1 has an unsigned integer overflow in parse_required_member. | |
| Modificada | Alta (7.5) | 0.71% | — | Google Protobuf-javaGoogle Protobuf-javalite | 12/12/2022 | 17/6/2026 | A parsing issue similar to CVE-2022-3171, but with Message-Type Extensions in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to… | |
| Modificada | Alta (7.5) | 0.95% | — | Google Protobuf-javaGoogle Protobuf-javalite | 12/12/2022 | 17/6/2026 | A parsing issue similar to CVE-2022-3171, but with textformat in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted… | |
| Modificada | Alta (7.5) | 1.1% | — | Google-protobufGoogle Protobuf-javaGoogle Protobuf-javaliteGoogle Protobuf-kotlin+2 | 12/10/2022 | 17/6/2026 | A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable… | |
| Modificada | Alta (7.5) | 1.5% | — | Google Protobuf-cppGoogle Protobuf-pythonFedoraproject FedoraDebian Linux | 22/9/2022 | 17/6/2026 | A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A… | |
| Modificada | Media (5.5) | 1.1% | — | Protobuf-c Project Protobuf-cFedoraproject Fedora | 23/6/2022 | 17/6/2026 | Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.4% | — | Protobufjs Project Protobufjs | 27/5/2022 | 17/6/2026 | The package protobufjs before 6.11.3 are vulnerable to Prototype Pollution which can allow an attacker to add/modify properties of the Object.prototype. This vulnerability can occur in multiple ways: 1. by providing untrusted user input to util.setProperty or to ReflectionObject.setParsedOption functions 2. by… | |
| Modificada | Media (5.5) | 2.7% | — | Google ProtobufDebian LinuxFedoraproject FedoraOracle Mysql+4 | 26/1/2022 | 17/6/2026 | Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater. | |
| Modificada | Media (5.5) | 1.7% | — | Google-protobufGoogle Protobuf-javaGoogle Protobuf-kotlinOracle Communications Cloud Native Core Console+3 | 10/1/2022 | 17/6/2026 | An issue in protobuf-java allowed the interleaving of com.google.protobuf.UnknownFieldSet fields in such a way that would be processed out of order. A small malicious payload can occupy the parser for several minutes by creating large numbers of short-lived objects that cause frequent, repeated pauses. We recommend… | |
| Modificada | Alta (8.6) | 3.4% | — | Golang ProtobufHashicorp Consul | 11/1/2021 | 17/6/2026 | An issue was discovered in GoGo Protobuf before 1.3.2. plugin/unmarshal/unmarshal.go lacks certain index validation, aka the "skippy peanut butter" issue. | |
| Modificada | Alta (7.5) | 3.8% | — | Rust-protobuf Project Rust-protobufApache Hbase | 26/8/2019 | 17/6/2026 | An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls. | |
| Modificada | Media (5.5) | 0.96% | — | Protobufjs Project Protobufjs | 7/6/2018 | 17/6/2026 | protobufjs is vulnerable to ReDoS when parsing crafted invalid .proto files. | |
| Modificada | Alta (8.8) | 5.0% | — | Google Protobuf | 25/9/2017 | 17/6/2026 | protobuf allows remote authenticated attackers to cause a heap-based buffer overflow. |