Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (later than CVE-2019-9779). | |
| Modificada | Crítica (9.1) | 3.0% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_CONTROL at dwg.spec. | |
| Modificada | Crítica (9.1) | 3.0% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at bits.c. | |
| Modificada | Alta (7.5) | 2.9% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the z dimension. | |
| Modificada | Alta (7.5) | 2.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dwg.spec. | |
| Modificada | Alta (7.5) | 2.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bits.c. | |
| Modificada | Alta (7.5) | 2.9% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the y dimension. | |
| Modificada | Alta (8.8) | 3.1% | — | Librehealth EHR | 20/12/2018 | 17/6/2026 | LH-EHR version REL-2_0_0 contains a Arbitrary File Upload vulnerability in Profile picture upload that can result in Remote Code Execution. This attack appear to be exploitable via Uploading a PHP file with image MIME type. | |
| Modificada | Alta (7.8) | 1.5% | — | Librecad | 8/11/2018 | 17/6/2026 | LibreCAD 2.1.3 allows remote attackers to cause a denial of service (0x89C04589 write access violation and application crash) or possibly have unspecified other impact via a crafted file. | |
| Modificada | Media (6.1) | 1.6% | — | Librenms | 18/10/2018 | 17/6/2026 | Persistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the dashboard_name parameter in the /ajax_form.php resource, related to html/includes/forms/add-dashboard.inc.php, html/includes/forms/delete-dashboard.inc.php, and… | |
| Modificada | Alta (8.8) | 1.5% | — | Librehealth EHR | 20/8/2018 | 17/6/2026 | LibreHealthIO lh-ehr version REL-2.0.0 contains a SQL Injection vulnerability in Show Groups Popup SQL query functions that can result in Ability to perform malicious database queries. This attack appear to be exploitable via User controlled parameters. | |
| Modificada | Alta (8.8) | 2.8% | — | Librehealth EHR | 20/8/2018 | 17/6/2026 | LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write in letter.php (2) vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled input. | |
| Modificada | Alta (8.8) | 2.8% | — | Librehealth EHR | 20/8/2018 | 17/6/2026 | LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Write vulnerability in Patient file letter functions that can result in Write files with malicious content and may lead to remote code execution. This attack appear to be exploitable via User controlled parameters. | |
| Modificada | Alta (7.1) | 1.5% | — | Librehealth EHR | 20/8/2018 | 17/6/2026 | LibreHealthIO lh-ehr version REL-2.0.0 contains a Authenticated Unrestricted File Deletion vulnerability in Import template that can result in Denial of service. This attack appear to be exploitable via User controlled parameter. | |
| Modificada | Alta (8.8) | 3.3% | — | Librehealth EHR | 20/8/2018 | 17/6/2026 | LibreHealthIO LH-EHR version REL-2.0.0 contains an Authenticated Unrestricted File Write vulnerability in Import template that can result in write files with malicious content and may lead to remote code execution. | |
| Modificada | Media (6.5) | 1.4% | — | Librehealth EHR | 20/8/2018 | 17/6/2026 | LibreHealthIO lh-ehr version <REL-2.0.0 contains an Authenticated Local File Disclosure vulnerability in Importing of templates allows local file disclosure that can result in Disclosure of sensitive files on the server. This attack appear to be exploitable via User controlled variable in import templates function. | |
| Modificada | Crítica (9.8) | 2.2% | — | Libreoffice | 5/8/2018 | 17/6/2026 | The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environments such as FreeBSD libc, which might allow attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact if LibreOffice… | |
| Modificada | Media (6.5) | 1.1% | — | GNU Libredwg | 23/7/2018 | 17/6/2026 | dwg_decode_eed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwg_free_eed in free.c) because it does not properly manage the obj->eed value after a free occurs. | |
| Modificada | Media (6.5) | 1.4% | — | GNU Libredwg | 20/7/2018 | 17/6/2026 | dwg_obj_block_control_get_block_headers in dwg_api.c in GNU LibreDWG 0.5.1048 allows remote attackers to cause a denial of service (NULL pointer dereference and SEGV) via a crafted dwg file. | |
| Modificada | Media (6.5) | 1.1% | — | GNU Libredwg | 20/7/2018 | 17/6/2026 | get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV). | |
| Modificada | Media (4.7) | 0.32% | — | Openbsd Libressl | 15/6/2018 | 17/6/2026 | LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host. | |
| Modificada | Alta (7.5) | 78% | 💥 Exploit | LibreofficeApache OpenofficeDebian LinuxRedhat Enterprise Linux Desktop+3 | 1/5/2018 | 17/6/2026 | An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document. | |
| Modificada | Alta (7.8) | 2.1% | — | Debian LinuxLibreofficeRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 16/4/2018 | 17/6/2026 | The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to cause a denial of service (heap-based buffer overflow with write access) or possibly have unspecified other impact via a… | |
| Modificada | Alta (7.8) | 1.9% | — | LibreofficeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 16/4/2018 | 17/6/2026 | sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the… | |
| Modificada | Alta (7.4) | 1.0% | 💥 PoC | Openbsd Libressl | 24/3/2018 | 17/6/2026 | The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle attackers to spoof servers and obtain sensitive… |