Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.7% | — | GNU Screen | 24/2/2020 | 17/6/2026 | A buffer overflow was found in the way GNU Screen before 4.8.0 treated the special escape OSC 49. Specially crafted output, or a special program, could corrupt memory and crash Screen or possibly have unspecified other impact. | |
| Modificada | Alta (7.5) | 1.6% | — | GnutlsDebian LinuxRedhat Enterprise Linux | 27/1/2020 | 17/6/2026 | GnuTLS before 3.3.13 does not validate that the signature algorithms match when importing a certificate. | |
| Modificada | Crítica (9.1) | 1.7% | — | GNU Aspell | 27/1/2020 | 17/6/2026 | libaspell.a in GNU Aspell before 0.60.8 has a buffer over-read for a string ending with a single '\0' byte, if the encoding is set to ucs-2 or ucs-4 outside of the application, as demonstrated by the ASPELL_CONF environment variable. | |
| Modificada | Crítica (9.8) | 2.3% | — | GNU Coreutils | 24/1/2020 | 17/6/2026 | Integer overflow in the keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 might allow attackers to cause a denial of service (application crash) or possibly have unspecified other impact via long strings. | |
| Modificada | Alta (7.8) | 0.52% | — | GNU Coreutils | 24/1/2020 | 17/6/2026 | The keycompare_mb function in sort.c in sort in GNU Coreutils through 8.23 on 64-bit platforms performs a size calculation without considering the number of bytes occupied by multibyte characters, which allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have… | |
| Modificada | Alta (7.8) | 0.52% | — | Gnump3dOpensuse Leap | 24/1/2020 | 17/6/2026 | UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of gnump3d in openSUSE Leap 15.1 allows local attackers to escalate from user gnump3d to root. This issue affects: openSUSE Leap 15.1 gnump3d version 3.0-lp151.2.1 and prior versions. | |
| Modificada | Media (6.5) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dynapi.pl). | |
| Modificada | Alta (8.1) | 1.7% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c. | |
| Modificada | Alta (8.1) | 1.7% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c. | |
| Modificada | Alta (8.1) | 1.7% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c. | |
| Modificada | Media (6.5) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse BackportsOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c. | |
| Modificada | Alta (8.8) | 1.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c. | |
| Modificada | Alta (7.3) | 0.69% | — | GNU CpioRedhat Enterprise Linux | 7/1/2020 | 17/6/2026 | In all versions of cpio before 2.13 does not properly validate input files when generating TAR archives. When cpio is used to create TAR archives from paths an attacker can write to, the resulting archive may contain files with permissions the attacker did not have or in paths he did not have access to. Extracting… | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec. | |
| Modificada | Alta (8.8) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec. | |
| Modificada | Alta (8.8) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c. | |
| Modificada | Alta (8.8) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec. | |
| Modificada | Media (5.9) | 1.7% | — | GnutlsDebian Linux | 20/12/2019 | 17/6/2026 | GnuTLS incorrectly validates the first byte of padding in CBC modes | |
| Modificada | Media (5.9) | 2.0% | — | GnupgGnupg LibgcryptDebian Linux | 29/11/2019 | 17/6/2026 | The mpi_powm function in Libgcrypt before 1.6.3 and GnuPG before 1.4.19 allows attackers to obtain sensitive information by leveraging timing differences when accessing a pre-computed table during modular exponentiation, related to a "Last-Level Cache Side-Channel Attack." | |
| Modificada | Media (4.2) | 0.58% | — | GnupgGnupg LibgcryptDebian Linux | 29/11/2019 | 17/6/2026 | Libgcrypt before 1.6.3 and GnuPG before 1.4.19 does not implement ciphertext blinding for Elgamal decryption, which allows physically proximate attackers to obtain the server's private key by determining factors using crafted ciphertext and the fluctuations in the electromagnetic field during multiplication. | |
| Analizada | Media (5.9) | 0.32% | — | GNU Grub2 | 29/11/2019 | 17/6/2026 | A flaw was found in the grub2-set-bootflag utility of grub2. A local attacker could run this utility under resource pressure (for example by setting RLIMIT), causing grub2 configuration files to be truncated and leaving the system unbootable on subsequent reboots. |