Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

3731 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.30%—GimpRedhat Enterprise Linux27/7/202624/8/2026
A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues…
AnalizadaMedia (5.5)0.23%—GimpRedhat Enterprise Linux27/7/202610/8/2026
A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize…
ModificadaAlta (7.8)0.30%—GimpRedhat Enterprise Linux27/7/202630/9/2026
A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based…
AnalizadaMedia (6.5)0.25%—Gnome LibsoupRedhat Enterprise Linux24/7/202624/8/2026
A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information…
AnalizadaAlta (7.2)0.28%—Gnome LibsoupRedhat Enterprise Linux24/7/202624/8/2026
A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing…
AnalizadaMedia (6.5)0.38%—Gnome LibsoupRedhat Enterprise Linux24/7/202624/8/2026
A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or…
AnalizadaMedia (4.2)0.25%—Gnome LibsoupRedhat Enterprise Linux21/7/202624/8/2026
A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-read. A remote attacker could use this flaw to crash an application…
ModificadaAlta (8.8)0.49%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/202617/8/2026
A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users.
ModificadaAlta (7.5)0.35%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20261/9/2026
A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions.
ModificadaMedia (5.3)0.34%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20261/9/2026
A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service.
AnalizadaAlta (7.5)0.33%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20264/9/2026
A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection.
ModificadaBaja (3.9)0.12%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20261/9/2026
A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.
AnalizadaAlta (7.5)0.44%—LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+721/7/202622/9/2026
A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service.
ModificadaMedia (5.9)0.10%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20261/9/2026
A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service.
ModificadaMedia (6.5)0.57%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20261/9/2026
A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests.
ModificadaMedia (6.5)0.73%—LibsshRedhat Hardened ImagesRedhat Enterprise Linux21/7/20261/9/2026
A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service.
AnalizadaMedia (5.3)0.49%—LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+721/7/202622/9/2026
A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory.
AnalizadaAlta (7.3)0.17%—LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+721/7/202622/9/2026
A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible…
AnalizadaBaja (3.7)0.36%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux8/7/20269/7/2026
A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though…
AnalizadaMedia (4.4)0.11%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux7/7/20269/7/2026
A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.
AnalizadaMedia (5.3)0.49%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux7/7/20269/7/2026
A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the end of a heap allocation while sorting RDN attribute-value pairs. An…
ModificadaAlta (7.8)0.26%—GimpRedhat Enterprise Linux7/7/202630/9/2026
A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution.
AnalizadaMedia (5.5)0.30%—GimpRedhat Enterprise Linux6/7/202621/8/2026
A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color Look-Up Table (CLUT) due to an integer overflow. This occurs when multiplying num_colors and num_cluts, both 16-bit unsigned short integers, resulting in a value…
ModificadaAlta (7.8)0.26%—GimpRedhat Enterprise Linux6/7/202630/9/2026
A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting…
AnalizadaAlta (7.3)0.29%—GimpRedhat Enterprise Linux2/7/202622/9/2026
A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution.