Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.1% | — | GNU BinutilsNetapp Cloud BackupNetapp HCI Management NodeNetapp Ontap Select Deploy Administration Utility+1 | 9/12/2020 | 17/6/2026 | A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file. | |
| Modificada | Media (5.5) | 1.2% | — | GNU BinutilsNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Solidfire & HCI Management Node | 9/12/2020 | 17/6/2026 | A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in scan_unit_for_symbols, as demonstrated in addr2line, that can cause a denial of service via a crafted file. | |
| Modificada | Media (5.5) | 1.1% | — | GNU BinutilsNetapp Ontap Select Deploy Administration UtilityFedoraproject Fedora | 9/12/2020 | 17/6/2026 | A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file. | |
| Modificada | Media (5.5) | 0.89% | — | GNU BinutilsNetapp Ontap Select Deploy Administration Utility | 9/12/2020 | 17/6/2026 | A Denial of Service vulnerability exists in the Binary File Descriptor (BFD) in GNU Binutils 2.35 due to an invalid read in process_symbol_table, as demonstrated in readeif. | |
| Modificada | Media (5.5) | 0.95% | — | GNU BinutilsNetapp Ontap Select Deploy Administration Utility | 9/12/2020 | 17/6/2026 | A double free vulnerability exists in the Binary File Descriptor (BFD) (aka libbrd) in GNU Binutils 2.35 in the process_symbol_table, as demonstrated in readelf, via a crafted file. | |
| Modificada | Alta (7.5) | 2.7% | — | GNU GlibcRedhat Enterprise LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller | 6/12/2020 | 17/6/2026 | sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long double with a non-canonical bit pattern, as seen when passing a \x00\x04\x00\x00\x00\x00\x00\x00\x00\x04 value to… | |
| Modificada | Media (4.8) | 1.5% | — | GNU GlibcFedoraproject FedoraNetapp E-series Santricity OS Controller | 4/12/2020 | 17/6/2026 | The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service. | |
| Modificada | Crítica (9.8) | 2.4% | — | GNU Glibc | 6/10/2020 | 25/9/2026 | manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999. | |
| Modificada | Crítica (9.8) | 2.6% | — | Gnuplot | 16/9/2020 | 17/6/2026 | com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 1.6% | — | Gnuplot | 16/9/2020 | 17/6/2026 | gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary code execution. | |
| Modificada | Alta (7.5) | 3.7% | — | GnutlsFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux | 4/9/2020 | 17/6/2026 | An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs. The crash happens in the application's error handling path, where the gnutls_deinit function is… | |
| Modificada | Alta (7.8) | 1.3% | — | GnupgGpg4win | 3/9/2020 | 17/6/2026 | GnuPG 2.2.21 and 2.2.22 (and Gpg4win 3.1.12) has an array overflow, leading to a crash or possibly unspecified other impact, when a victim imports an attacker's OpenPGP key, and this key has AEAD preferences. The overflow is caused by a g10/key-check.c error. NOTE: GnuPG 2.3.x is unaffected. GnuPG 2.2.23 is a fixed… | |
| Modificada | Media (5.5) | 1.3% | — | GNU Bison | 25/8/2020 | 17/6/2026 | GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug report was… | |
| Modificada | Media (6) | 0.46% | — | GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+3 | 31/7/2020 | 17/6/2026 | There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow. | |
| Modificada | Media (6) | 0.48% | — | GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+3 | 31/7/2020 | 17/6/2026 | There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file… | |
| Modificada | Media (6.7) | 0.48% | — | GNU Grub2Opensuse Leap | 30/7/2020 | 17/6/2026 | There's an issue with grub2 in all versions before 2.06 when handling squashfs filesystems containing a symbolic link with name length of UINT32 bytes in size. The name size leads to an arithmetic overflow leading to a zero-size allocation further causing a heap-based buffer overflow with attacker controlled data. | |
| Modificada | Alta (8.2) | 1.7% | 💥 PoC | GNU Grub2Debian LinuxOpensuse LeapVmware Photon OS | 30/7/2020 | 17/6/2026 | A flaw was found in grub2, prior to version 2.06. An attacker may use the GRUB 2 flaw to hijack and tamper the GRUB verification process. This flaw also allows the bypass of Secure Boot protections. In order to load an untrusted or modified kernel, an attacker would first need to establish access to the system such as… | |
| Modificada | Media (6.4) | 0.43% | — | GNU Grub2Opensuse Leap | 29/7/2020 | 17/6/2026 | In grub2 versions before 2.06 the grub memory allocator doesn't check for possible arithmetic overflows on the requested allocation size. This leads the function to return invalid memory allocations which can be further used to cause possible integrity, confidentiality and availability impacts during the boot process. | |
| Modificada | Media (6.4) | 1.6% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformRedhat Enterprise Linux+11 | 29/7/2020 | 17/6/2026 | Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of… | |
| Modificada | Media (6.4) | 0.98% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+10 | 29/7/2020 | 17/6/2026 | GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and… | |
| Modificada | Media (6.4) | 1.4% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+10 | 29/7/2020 | 17/6/2026 | GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects… | |
| Modificada | Media (6.5) | 1.5% | — | GNU Libredwg | 17/7/2020 | 17/6/2026 | GNU LibreDWG before 0.11 allows NULL pointer dereferences via crafted input files. | |
| Modificada | Alta (8.1) | 1.2% | — | GNU Libredwg | 16/7/2020 | 17/6/2026 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in bit_write_TF in bits.c. | |
| Modificada | Crítica (9.8) | 1.9% | — | GNU Libredwg | 16/7/2020 | 17/6/2026 | An issue was discovered in GNU LibreDWG through 0.9.3. There is a NULL pointer dereference in the function dwg_encode_common_entity_handle_data in common_entity_handle_data.spec. | |
| Modificada | Alta (8.1) | 1.2% | — | GNU Libredwg | 16/7/2020 | 17/6/2026 | An issue was discovered in GNU LibreDWG through 0.9.3. Crafted input will lead to a heap-based buffer over-read in dwg_encode_entity in common_entity_data.spec. |