Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1563 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.6%💥 PoCGNU BashNetapp HCI Management NodeNetapp Oncommand Unified ManagerNetapp Solidfire+128/11/201917/6/2026
An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID to its real UID. However, it does so incorrectly. On Linux and other systems that support "saved…
ModificadaMedia (5.3)1.2%—GnupgRedhat Enterprise LinuxDebian Linux27/11/201916/6/2026
dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate.
ModificadaAlta (7.5)3.3%—GNU PatchDebian Linux25/11/201917/6/2026
A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196.
ModificadaMedia (5.5)2.5%—GnupgCanonical Ubuntu Linux20/11/201917/6/2026
kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges."
ModificadaMedia (5.5)1.9%—GnupgDebian Linux20/11/201917/6/2026
The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a crafted keyring file.
ModificadaAlta (7.5)1.5%—GNU Serveez20/11/201917/6/2026
GNU Serveez through 0.2.2 has an Information Leak. An attacker may send an HTTP POST request to the /cgi-bin/reader URI. The attacker must include a Content-length header with a large positive value that, when represented in 32 bit binary, evaluates to a negative number. The problem exists in the http_cgi_write…
ModificadaBaja (3.3)0.41%—GNU GlibcCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux19/11/201917/6/2026
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid…
ModificadaCrítica (9.8)1.8%—Gnusound19/11/201916/6/2026
gnusound 0.7.5 has format string issue
ModificadaAlta (7.8)2.2%—GNU FribidiDebian Linux13/11/201917/6/2026
A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses…
ModificadaAlta (7.8)1.2%💥 ExploitGNU Mailutils11/11/201917/6/2026
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
ModificadaMedia (6.1)1.2%—SIR Gnuboard7/11/201917/6/2026
GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka the adm/board_form_update.php bo_content_tail parameter.
ModificadaMedia (6.1)1.1%—SIR Gnuboard30/10/201917/6/2026
GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, aka the adm/boardgroup_form_update.php gr_1~10 parameter.
ModificadaAlta (7.8)0.55%—GNU GCC23/10/201916/6/2026
Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts.
ModificadaAlta (7.5)3.0%—GNU Libidn222/10/201917/6/2026
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain…
ModificadaCrítica (9.8)3.7%—GNU Libidn221/10/201917/6/2026
idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.
ModificadaAlta (7.8)0.34%—GNU Guix17/10/201917/6/2026
GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365.
ModificadaCrítica (9.1)3.3%—GNU AspellCanonical Ubuntu Linux14/10/201917/6/2026
libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character.
ModificadaCrítica (9.8)3.1%—Nongnu LibntlmDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+210/10/201917/6/2026
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.
ModificadaMedia (6.5)2.4%—GNU BinutilsOpensuse LeapCanonical Ubuntu Linux10/10/201917/6/2026
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.
ModificadaMedia (6.5)2.8%—GNU BinutilsOpensuse LeapCanonical Ubuntu Linux10/10/201917/6/2026
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.
ModificadaAlta (7.8)1.1%—Gnucobol Project Gnucobol17/9/201917/6/2026
GnuCOBOL 2.2 has a use-after-free in the end_scope_of_program_name() function in cobc/parser.y via crafted COBOL source code.
ModificadaAlta (7.8)0.98%—Gnucobol Project Gnucobol17/9/201917/6/2026
GnuCOBOL 2.2 has a stack-based buffer overflow in the cb_name() function in cobc/tree.c via crafted COBOL source code.
ModificadaMedia (6.5)1.1%—GNU Cflow9/9/201917/6/2026
GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c.
ModificadaMedia (6.5)1.1%—GNU Cflow9/9/201917/6/2026
GNU cflow through 1.6 has a use-after-free in the reference function in parser.c.
ModificadaAlta (7.5)3.2%—GNU GCCOpensuse Leap2/9/201917/6/2026
The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a…