Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1563 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.6% | 💥 PoC | GNU BashNetapp HCI Management NodeNetapp Oncommand Unified ManagerNetapp Solidfire+1 | 28/11/2019 | 17/6/2026 | An issue was discovered in disable_priv_mode in shell.c in GNU Bash through 5.0 patch 11. By default, if Bash is run with its effective UID not equal to its real UID, it will drop privileges by setting its effective UID to its real UID. However, it does so incorrectly. On Linux and other systems that support "saved… | |
| Modificada | Media (5.3) | 1.2% | — | GnupgRedhat Enterprise LinuxDebian Linux | 27/11/2019 | 16/6/2026 | dirmngr before 2.1.0 improperly handles certain system calls, which allows remote attackers to cause a denial of service (DOS) via a specially-crafted certificate. | |
| Modificada | Alta (7.5) | 3.3% | — | GNU PatchDebian Linux | 25/11/2019 | 17/6/2026 | A Directory Traversal vulnerability exists in the GNU patch before 2.7.4. A remote attacker can write to arbitrary files via a symlink attack in a patch file. NOTE: this issue exists because of an incomplete fix for CVE-2015-1196. | |
| Modificada | Media (5.5) | 2.5% | — | GnupgCanonical Ubuntu Linux | 20/11/2019 | 17/6/2026 | kbx/keybox-search.c in GnuPG before 1.4.19, 2.0.x before 2.0.27, and 2.1.x before 2.1.2 does not properly handle bitwise left-shifts, which allows remote attackers to cause a denial of service (invalid read operation) via a crafted keyring file, related to sign extensions and "memcpy with overlapping ranges." | |
| Modificada | Media (5.5) | 1.9% | — | GnupgDebian Linux | 20/11/2019 | 17/6/2026 | The keyring DB in GnuPG before 2.1.2 does not properly handle invalid packets, which allows remote attackers to cause a denial of service (invalid read and use-after-free) via a crafted keyring file. | |
| Modificada | Alta (7.5) | 1.5% | — | GNU Serveez | 20/11/2019 | 17/6/2026 | GNU Serveez through 0.2.2 has an Information Leak. An attacker may send an HTTP POST request to the /cgi-bin/reader URI. The attacker must include a Content-length header with a large positive value that, when represented in 32 bit binary, evaluates to a negative number. The problem exists in the http_cgi_write… | |
| Modificada | Baja (3.3) | 0.41% | — | GNU GlibcCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux | 19/11/2019 | 17/6/2026 | On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid… | |
| Modificada | Crítica (9.8) | 1.8% | — | Gnusound | 19/11/2019 | 16/6/2026 | gnusound 0.7.5 has format string issue | |
| Modificada | Alta (7.8) | 2.2% | — | GNU FribidiDebian Linux | 13/11/2019 | 17/6/2026 | A buffer overflow in the fribidi_get_par_embedding_levels_ex() function in lib/fribidi-bidi.c of GNU FriBidi through 1.0.7 allows an attacker to cause a denial of service or possibly execute arbitrary code by delivering crafted text content to a user, when this content is then rendered by an application that uses… | |
| Modificada | Alta (7.8) | 1.2% | 💥 Exploit | GNU Mailutils | 11/11/2019 | 17/6/2026 | maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode. | |
| Modificada | Media (6.1) | 1.2% | — | SIR Gnuboard | 7/11/2019 | 17/6/2026 | GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board tail contents" parameter, aka the adm/board_form_update.php bo_content_tail parameter. | |
| Modificada | Media (6.1) | 1.1% | — | SIR Gnuboard | 30/10/2019 | 17/6/2026 | GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, aka the adm/boardgroup_form_update.php gr_1~10 parameter. | |
| Modificada | Alta (7.8) | 0.55% | — | GNU GCC | 23/10/2019 | 16/6/2026 | Integer overflow in the new[] operator in gcc before 4.8.0 allows attackers to have unspecified impacts. | |
| Modificada | Alta (7.5) | 3.0% | — | GNU Libidn2 | 22/10/2019 | 17/6/2026 | GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain… | |
| Modificada | Crítica (9.8) | 3.7% | — | GNU Libidn2 | 21/10/2019 | 17/6/2026 | idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string. | |
| Modificada | Alta (7.8) | 0.34% | — | GNU Guix | 17/10/2019 | 17/6/2026 | GNU Guix 1.0.1 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable, a similar issue to CVE-2019-17365. | |
| Modificada | Crítica (9.1) | 3.3% | — | GNU AspellCanonical Ubuntu Linux | 14/10/2019 | 17/6/2026 | libaspell.a in GNU Aspell before 0.60.8 has a stack-based buffer over-read in acommon::unescape in common/getdata.cpp via an isolated \ character. | |
| Modificada | Crítica (9.8) | 3.1% | — | Nongnu LibntlmDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+2 | 10/10/2019 | 17/6/2026 | Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request. | |
| Modificada | Media (6.5) | 2.4% | — | GNU BinutilsOpensuse LeapCanonical Ubuntu Linux | 10/10/2019 | 17/6/2026 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm. | |
| Modificada | Media (6.5) | 2.8% | — | GNU BinutilsOpensuse LeapCanonical Ubuntu Linux | 10/10/2019 | 17/6/2026 | find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file. | |
| Modificada | Alta (7.8) | 1.1% | — | Gnucobol Project Gnucobol | 17/9/2019 | 17/6/2026 | GnuCOBOL 2.2 has a use-after-free in the end_scope_of_program_name() function in cobc/parser.y via crafted COBOL source code. | |
| Modificada | Alta (7.8) | 0.98% | — | Gnucobol Project Gnucobol | 17/9/2019 | 17/6/2026 | GnuCOBOL 2.2 has a stack-based buffer overflow in the cb_name() function in cobc/tree.c via crafted COBOL source code. | |
| Modificada | Media (6.5) | 1.1% | — | GNU Cflow | 9/9/2019 | 17/6/2026 | GNU cflow through 1.6 has a heap-based buffer over-read in the nexttoken function in parser.c. | |
| Modificada | Media (6.5) | 1.1% | — | GNU Cflow | 9/9/2019 | 17/6/2026 | GNU cflow through 1.6 has a use-after-free in the reference function in parser.c. | |
| Modificada | Alta (7.5) | 3.2% | — | GNU GCCOpensuse Leap | 2/9/2019 | 17/6/2026 | The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a… |