Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

30 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)0.95%—Tinc-vpn TincDebian LinuxStarwindsoftware Starwind Virtual SAN10/10/201817/6/2026
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
ModificadaBaja (3.7)1.4%—Tinc-vpn TincDebian LinuxStarwindsoftware Starwind Virtual SAN10/10/201817/6/2026
tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1.
ModificadaMedia (5.3)1.5%—Tinc-vpn TincStarwindsoftware Starwind Virtual SAN10/10/201817/6/2026
tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.
ModificadaAlta (8.8)2.6%—Libsdl SDL ImageDebian LinuxStarwindsoftware Starwind Virtual SAN10/4/201817/6/2026
An exploitable code execution vulnerability exists in the XCF image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted XCF image can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can display a specially crafted image to trigger this…
ModificadaMedia (5.5)1.2%—Libsdl SDL ImageDebian LinuxStarwindsoftware Starwind Virtual SAN10/4/201817/6/2026
An exploitable information disclosure vulnerability exists in the PCX image rendering functionality of Simple DirectMedia Layer SDL2_image-2.0.2. A specially crafted PCX image can cause an out-of-bounds read on the heap, resulting in information disclosure . An attacker can display a specially crafted image to trigger…