Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via bit_search_sentinel ../../src/bits.c:1985. | |
| Modificada | Media (6.5) | 0.92% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | An issue was discovered in GNU LibreDWG 0.10. Crafted input will lead to an memory leak in dwg_decode_eed ../../src/decode.c:3638. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_appinfo ../../src/decode.c:2842. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_section_preview ../../src/decode.c:3175. | |
| Modificada | Media (6.5) | 0.86% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337. | |
| Modificada | Media (6.5) | 0.86% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A null pointer deference issue exists in GNU LibreDWG 0.10 via get_bmp ../../programs/dwgbmp.c:164. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exits in GNU LibreDWG 0.10 via: read_2004_section_classes ../../src/decode.c:2440. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2417. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulneraibility exists in GNU LibreDWG 0.10 via bit_calc_CRC ../../src/bits.c:2213. | |
| Modificada | Alta (7.8) | 0.89% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2379. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641via htmlescape ../../programs/escape.c:51. | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow vulnerability exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:48. | |
| Modificada | Media (6.5) | 0.91% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A null pointer dereference issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:29. which causes a denial of service (application crash). | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heab based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlescape ../../programs/escape.c:46. | |
| Modificada | Media (6.5) | 0.91% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A null pointer deference issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114, which causes a denial of service (application crash). | |
| Modificada | Alta (8.8) | 1.1% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via htmlwescape ../../programs/escape.c:97. | |
| Modificada | Alta (7.8) | 0.81% | — | GNU Libredwg | 17/5/2021 | 9/7/2026 | A heap based buffer overflow issue exists in GNU LibreDWG 0.10.2641 via output_TEXT ../../programs/dwg2SVG.c:114. | |
| Modificada | Crítica (9.8) | 1.8% | — | Gnuplot Project Gnuplot | 3/5/2021 | 17/6/2026 | The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands. | |
| Modificada | Alta (7.8) | 3.3% | 💥 PoC | GNU Binutils | 29/4/2021 | 17/6/2026 | A flaw was found in binutils readelf 2.35 program. An attacker who is able to convince a victim using readelf to read a crafted file could trigger a stack buffer overflow, out-of-bounds write of arbitrary data supplied by the attacker. The highest impact of this flaw is to confidentiality, integrity, and availability. | |
| Modificada | Media (6.1) | 1.1% | — | GNU WgetBroadcom Brocade Fabric Operating System FirmwareNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+2 | 29/4/2021 | 17/6/2026 | GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007. | |
| Modificada | Media (5.5) | 0.33% | — | GNU Guix | 26/4/2021 | 17/6/2026 | A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having an unprivileged user spawn a build process, for instance with `guix build`, that makes its build directory… | |
| Rechazada | Sin puntuar | — | — | GNU BinutilsAI | 15/4/2021 | 20/11/2023 | Rejected reason: Non Security Issue. See the binutils security policy for more details, https://sourceware.org/cgit/binutils-gdb/tree/binutils/SECURITY.txt | |
| Modificada | Alta (7.8) | 1.8% | — | GNU ChessFedoraproject Fedora | 7/4/2021 | 17/6/2026 | GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) data. This is related to a buffer overflow in the use of a .tmp.epd temporary file in the cmd_pgnload and cmd_pgnreplay functions in frontend/cmd.cc. | |
| Modificada | Media (5.5) | 1.3% | — | GNU BinutilsNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility | 26/3/2021 | 17/6/2026 | A flaw was found in GNU Binutils 2.35.1, where there is a heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c due to the number of symbols not calculated correctly. The highest threat from this vulnerability is to system availability. | |
| Modificada | Media (6.3) | 0.30% | — | GNU BinutilsRedhat Enterprise LinuxNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+2 | 26/3/2021 | 17/6/2026 | There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities… |