Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

102 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.33%—Webassembly Wasm28/10/202217/6/2026
wasm-interp v1.0.29 was discovered to contain a heap overflow via the component std::vector<wabt::Type, std::allocator<wabt::Type>>::size() at /bits/stl_vector.h.
ModificadaAlta (7.1)0.31%—Webassembly Wabt28/10/202217/6/2026
wasm-interp v1.0.29 was discovered to contain an out-of-bounds read via the component OnReturnCallExpr->GetReturnCallDropKeepCount.
ModificadaAlta (7.8)0.38%—Autodesk Subassembly Composer14/10/202217/6/2026
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaAlta (7.8)0.55%—Autodesk Subassembly Composer14/10/202217/6/2026
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaAlta (7.8)0.41%—Autodesk Subassembly Composer14/10/202217/6/2026
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaAlta (7.8)0.41%—Autodesk Subassembly Composer3/10/202217/6/2026
A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
ModificadaMedia (5.5)0.70%—Webassembly Binaryen10/1/202217/6/2026
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).
ModificadaMedia (5.5)0.77%—Webassembly Binaryen10/1/202217/6/2026
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::visitRethrow(wasm::Rethrow*).
ModificadaMedia (5.5)0.70%—Webassembly Binaryen10/1/202217/6/2026
A Denial of Service vulnerability exists in Binaryen 103. The program terminates with signal SIGKILL.
ModificadaMedia (5.5)0.70%—Webassembly Binaryen10/1/202217/6/2026
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::Tuple::validate.
ModificadaMedia (5.5)0.68%—Webassembly Binaryen10/1/202217/6/2026
A Stack Overflow vulnerability exists in Binaryen 103 via the printf_common function.
ModificadaMedia (5.5)0.70%—Webassembly Binaryen10/1/202217/6/2026
A Denial of Service vulnerability exists in Binaryen 104 due to an assertion abort in wasm::WasmBinaryBuilder::readFunctions.
ModificadaMedia (5.5)0.78%—Webassembly BinaryenFedoraproject Fedora21/12/202117/6/2026
A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet.
ModificadaAlta (7.5)1.5%—Webassembly BinaryenFedoraproject Fedora21/12/202117/6/2026
A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.
ModificadaAlta (7.8)1.1%—Libass Project LibassFedoraproject Fedora20/7/202117/6/2026
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
ModificadaBaja (3.7)0.74%—Getambassador Emissary-ingress9/7/202117/6/2026
Emissary-Ingress (formerly Ambassador API Gateway) through 1.13.9 allows attackers to bypass client certificate requirements (i.e., mTLS cert_required) on backend upstreams when more than one TLSContext is defined and at least one configuration exists that does not require client certificate authentication. The…
ModificadaAlta (8.8)2.6%—Libass Project Libass23/3/202117/6/2026
Stack overflow in the parse_tag function in libass/ass_parse.c in libass before 0.15.0 allows remote attackers to cause a denial of service or remote code execution via a crafted file.
ModificadaAlta (8.8)1.8%—Libass Project Libass16/10/202017/6/2026
In libass 0.14.0, the `ass_outline_construct`'s call to `outline_stroke` causes a signed integer overflow.
ModificadaCrítica (9.8)3.0%—Un4seen Bassmidi16/10/202017/6/2026
The BASSMIDI plugin 2.4.12.1 for Un4seen BASS Audio Library on Windows is prone to an out of bounds write vulnerability. An attacker may exploit this to execute code on the target machine. A failure in exploitation leads to a denial of service.
ModificadaMedia (6.5)0.93%—Un4seen Bass16/10/202017/6/2026
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Denial of Service vulnerability (infinite loop) via a crafted .mp3 file. This weakness could allow attackers to consume excessive CPU and the application becomes unresponsive.
ModificadaMedia (6.5)1.3%—Un4seen Bass16/10/202017/6/2026
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile out of bounds read vulnerability via a crafted .wav file. An attacker can exploit this issues to gain access to sensitive information that may aid in further attacks. A failure in exploitation leads to denial of service.
ModificadaMedia (6.5)1.1%—Un4seen Bass16/10/202017/6/2026
The BASS Audio Library 2.4.14 under Windows is prone to a BASS_StreamCreateFile Use after Free vulnerability via a crafted .ogg file. An attacker can exploit this to gain access to sensitive information that may aid in further attacks. A failure in exploitation leads to denial of service.
ModificadaMedia (6.5)1.3%—Webassembly Binaryen29/8/201917/6/2026
An issue was discovered in Binaryen 1.38.32. Two visitors in ir/ExpressionManipulator.cpp can lead to a NULL pointer dereference in wasm::LocalSet::finalize in wasm/wasm.cpp. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by wasm2js.
ModificadaMedia (6.5)1.2%—Webassembly Binaryen29/8/201917/6/2026
An issue was discovered in Binaryen 1.38.32. Missing validation rules in asmjs/asmangle.cpp can lead to an Assertion Failure at wasm/wasm.cpp in wasm::asmangle. A crafted input can cause denial-of-service, as demonstrated by wasm2js.
ModificadaMedia (6.5)1.2%—Webassembly Binaryen10/2/201917/6/2026
wasm::WasmBinaryBuilder::readUserSection in wasm-binary.cpp in Binaryen 1.38.22 triggers an attempt at excessive memory allocation, as demonstrated by wasm-merge and wasm-opt.
Orbitaley — Vulnerabilidades