Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.2% | — | GNU Binutils | 21/3/2017 | 17/6/2026 | objdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer over-reads (of size 1 and size 8) while handling corrupt STABS enum type strings in a crafted object file, leading to program crash. | |
| Modificada | Media (5.5) | 1.2% | — | GNU Binutils | 21/3/2017 | 17/6/2026 | The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NULL pointer while reading section contents in a corrupt binary, leading to a program crash. | |
| Modificada | Crítica (9.8) | 2.3% | — | GNU Binutils | 21/3/2017 | 17/6/2026 | ihex.c in GNU Binutils before 2.26 contains a stack buffer overflow when printing bad bytes in Intel Hex objects. | |
| Modificada | Crítica (9.1) | 3.8% | — | GNU Binutils | 17/3/2017 | 17/6/2026 | readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well. | |
| Modificada | Media (5.5) | 1.1% | — | GNU Binutils | 17/3/2017 | 17/6/2026 | readelf in GNU Binutils 2.28 has a use-after-free (specifically read-after-free) error while processing multiple, relocated sections in an MSP430 binary. This is caused by mishandling of an invalid symbol index, and mishandling of state across invocations. | |
| Modificada | Media (5.5) | 1.2% | — | GNU Binutils | 17/3/2017 | 17/6/2026 | readelf in GNU Binutils 2.28 writes to illegal addresses while processing corrupt input files containing symbol-difference relocations, leading to a heap-based buffer overflow. | |
| Modificada | Media (5.5) | 1.5% | — | Icoutils Project IcoutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 16/2/2017 | 17/6/2026 | An issue was discovered in icoutils 0.31.1. An out-of-bounds read leading to a buffer overflow was observed in the "simple_vec" function in the "extract.c" source file. This affects icotool. | |
| Modificada | Media (5.5) | 1.5% | — | Icoutils Project IcoutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 16/2/2017 | 17/6/2026 | An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "extract_icons" function in the "extract.c" source file. This issue can be triggered by processing a corrupted ico file and will result in an icotool crash. | |
| Modificada | Media (5.5) | 1.5% | — | Icoutils Project IcoutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 16/2/2017 | 17/6/2026 | An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. This is happening because the "len" parameter for memcpy is not checked for size and thus becomes a negative integer in the process, resulting in a failed memcpy. This… | |
| Modificada | Media (4.6) | 0.43% | — | GNU Coreutils | 7/2/2017 | 17/6/2026 | chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer. | |
| Modificada | Baja (3.3) | 0.37% | — | Ecryptfs-utilsCanonical Ubuntu Linux | 22/7/2016 | 17/6/2026 | ecryptfs-setup-swap in eCryptfs does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning on a (1) NVMe or (2) MMC drive, which allows local users to obtain sensitive information via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for… | |
| Modificada | Baja (3.3) | 0.35% | — | Canonical Ubuntu LinuxEcryptfs-utils | 22/7/2016 | 17/6/2026 | ecryptfs-setup-swap in eCryptfs before 111 does not prevent the unencrypted swap partition from activating during boot when using GPT partitioning and certain versions of systemd, which allows local users to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (8.4) | 0.37% | — | Ecryptfs-utilsCanonical Ubuntu LinuxOpensuse LeapOpensuse+2 | 22/1/2016 | 17/6/2026 | mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid. | |
| Modificada | Alta (7.5) | 6.9% | — | Canonical Ubuntu LinuxT1utils Project T1utils | 8/6/2015 | 17/6/2026 | Buffer overflow in the set_cs_start function in t1disasm.c in t1utils before 1.39 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted font file. | |
| Modificada | Alta (10) | 5.6% | — | Debian Cifs-utils | 31/3/2015 | 17/6/2026 | Stack-based buffer overflow in cifskey.c or cifscreds.c in cifs-utils before 6.4, as used in pam_cifscreds, allows remote attackers to have unspecified impact via unknown vectors. | |
| Modificada | Media (5) | 2.2% | — | Ecryptfs-utils | 16/3/2015 | 17/6/2026 | eCryptfs 104 and earlier uses a default salt to encrypt the mount passphrase, which makes it easier for attackers to obtain user passwords via a brute force attack. | |
| Modificada | Alta (10) | 2.8% | — | Powerpc-utils Project Powerpc-utils | 19/2/2015 | 17/6/2026 | scripts/amsvis/powerpcAMS/amsnet.py in powerpc-utils-python uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object. | |
| Modificada | Media (6.8) | 3.3% | — | Gentoo Xdg-utils | 21/1/2015 | 17/6/2026 | Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open. | |
| Modificada | Alta (7.5) | 7.1% | — | GNU CoreutilsCanonical Ubuntu Linux | 16/1/2015 | 17/6/2026 | The parse_datetime function in GNU coreutils allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted date string, as demonstrated by the "--date=TZ="123"345" @1" string to the touch or date command. | |
| Modificada | Media (5) | 5.2% | — | Fedoraproject FedoraDebian LinuxGNU BinutilsCanonical Ubuntu Linux | 15/1/2015 | 17/6/2026 | The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive. | |
| Modificada | Media (6.4) | 5.0% | — | Elfutils Project Elfutils | 2/1/2015 | 17/6/2026 | Directory traversal vulnerability in the read_long_names function in libelf/elf_begin.c in elfutils 0.152 and 0.161 allows remote attackers to write to arbitrary files to the root directory via a / (slash) in a crafted archive, as demonstrated using the ar program. | |
| Modificada | Baja (3.6) | 1.0% | — | Canonical Ubuntu LinuxGNU BinutilsFedoraproject Fedora | 9/12/2014 | 17/6/2026 | Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar. | |
| Modificada | Alta (7.5) | 6.2% | — | Canonical Ubuntu LinuxGNU BinutilsFedoraproject Fedora | 9/12/2014 | 17/6/2026 | Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file. | |
| Modificada | Alta (7.5) | 6.2% | — | Fedoraproject FedoraGNU BinutilsCanonical Ubuntu Linux | 9/12/2014 | 17/6/2026 | Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file. | |
| Modificada | Alta (7.5) | 4.9% | — | Fedoraproject FedoraGNU BinutilsCanonical Ubuntu Linux | 9/12/2014 | 17/6/2026 | Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a truncated export table in a PE file. |