Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

551 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)9.3%💥 PoCRsyslog LibrelpDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+523/3/201817/6/2026
rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially…
ModificadaAlta (7.8)4.5%—Calibre-ebook Calibre8/3/201817/6/2026
gui2/viewer/bookmarkmanager.py in Calibre 3.18 calls cPickle.load on imported bookmark data, which allows remote attackers to execute arbitrary code via a crafted .pickle file, as demonstrated by Python code that contains an os.system call.
ModificadaCrítica (9.8)23%💥 ExploitLibreofficeDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+59/2/201817/6/2026
LibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which use the COM.MICROSOFT.WEBSERVICE function.
ModificadaMedia (5.9)2.2%—Librenms9/11/201717/6/2026
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.
ModificadaAlta (7.5)2.5%—LibreofficeLibwpd9/9/201717/6/2026
WP1StylesListener.cpp, WP5StylesListener.cpp, and WP42StylesListener.cpp in libwpd 0.10.1 mishandle iterators, which allows remote attackers to cause a denial of service (heap-based buffer over-read in the WPXTableList class in WPXTable.cpp). This vulnerability can be triggered in LibreOffice before 5.3.7. It may lead…
ModificadaAlta (7.5)3.5%—Gnome Librest18/8/201717/6/2026
The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object…
ModificadaAlta (7.5)3.0%—LibreswanFedoraproject Fedora13/6/201717/6/2026
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
ModificadaCrítica (9.8)2.2%—Libreoffice30/4/201717/6/2026
LibreOffice before 2017-03-17 has an out-of-bounds write caused by a heap-based buffer overflow related to the ReadJPEG function in vcl/source/filter/jpeg/jpegc.cxx.
ModificadaMedia (5.3)1.0%—Openbsd Libressl27/4/201717/6/2026
LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.
ModificadaCrítica (9.8)2.4%—Libreoffice15/4/201717/6/2026
LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.
ModificadaCrítica (9.8)3.9%—Libreoffice14/4/201717/6/2026
LibreOffice before 2017-01-02 has an out-of-bounds write caused by a heap-based buffer overflow related to the tools::Polygon::Insert function in tools/source/generic/poly.cxx.
ModificadaCrítica (9.8)3.5%—Libreoffice14/4/201717/6/2026
LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in vcl/source/gdi/svmconverter.cxx.
ModificadaCrítica (9.8)3.6%—Libreoffice14/4/201717/6/2026
LibreOffice before 2016-12-22 has an out-of-bounds write caused by a heap-based buffer overflow related to the EnhWMFReader::ReadEnhWMF function in vcl/source/filter/wmf/enhwmf.cxx.
ModificadaMedia (5.5)2.8%—Calibre-ebook Calibre16/3/201717/6/2026
The E-book viewer in calibre before 2.75 allows remote attackers to read arbitrary files via a crafted epub file with JavaScript.
ModificadaAlta (7.8)2.8%—Debian LinuxLibreofficeCanonical Ubuntu Linux8/7/201617/6/2026
Use-after-free vulnerability in LibreOffice before 5.1.4 allows remote attackers to execute arbitrary code via a crafted RTF file, related to stylesheet and superscript tokens.
ModificadaAlta (7.5)2.7%—Libreswan16/6/201617/6/2026
programs/pluto/ikev1.c in libreswan before 3.17 retransmits in initial-responder states, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed UDP packet. NOTE: the original behavior complies with the IKEv1 protocol, but has a required security update from the libreswan…
ModificadaAlta (7.5)2.6%—LibreswanFedoraproject Fedora18/4/201617/6/2026
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
ModificadaAlta (7.8)2.8%—LibreofficeCanonical Ubuntu Linux18/2/201617/6/2026
LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.
ModificadaAlta (7.8)2.8%—LibreofficeCanonical Ubuntu Linux18/2/201617/6/2026
The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.
ModificadaMedia (5)2.8%—Redhat Libreport7/12/201517/6/2026
libreport 2.0.7 before 2.6.3 only saves changes to the first file when editing a crash report, which allows remote attackers to obtain sensitive information via unspecified vectors related to the (1) backtrace, (2) cmdline, (3) environ, (4) open_fds, (5) maps, (6) smaps, (7) hostname, (8) remote, (9) ks.cfg, or (10)…
ModificadaMedia (6.8)9.6%—Canonical Ubuntu LinuxDebian LinuxLibreofficeApache Openoffice10/11/201517/6/2026
LibreOffice before 4.4.6 and 5.x before 5.0.1 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via an index to a non-existent bookmark in a DOC file.
ModificadaMedia (6.8)13%—Canonical Ubuntu LinuxDebian LinuxApache OpenofficeLibreoffice10/11/201517/6/2026
Integer overflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a long DOC file, which triggers a buffer overflow.
ModificadaMedia (6.8)8.7%—LibreofficeApache OpenofficeCanonical Ubuntu LinuxDebian Linux10/11/201517/6/2026
Integer underflow in LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2, when the configuration setting "Load printer settings with the document" is enabled, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via crafted…
ModificadaMedia (4.3)14%—LibreofficeCanonical Ubuntu LinuxDebian LinuxApache Openoffice10/11/201517/6/2026
LibreOffice before 4.4.5 and Apache OpenOffice before 4.1.2 uses the stored LinkUpdateMode configuration information in OpenDocument Format files and templates when handling links, which might allow remote attackers to obtain sensitive information via a crafted document, which embeds data from local files into (1)…
ModificadaMedia (4.3)2.8%—Libreswan9/11/201517/6/2026
The pluto IKE daemon in libreswan before 3.15 and Openswan before 2.6.45, when built with NSS, allows remote attackers to cause a denial of service (assertion failure and daemon restart) via a zero DH g^x value in a KE payload in a IKE packet.