Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
3731 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.30% | — | GimpRedhat Enterprise Linux | 27/7/2026 | 24/8/2026 | A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data buffer without verifying if the cursor exceeds the allocated resource size. If a crafted file contains a truncated mask resource, the icns_decompress function continues… | |
| Analizada | Media (5.5) | 0.23% | — | GimpRedhat Enterprise Linux | 27/7/2026 | 10/8/2026 | A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image header dimensions (ysize and zsize) are read as 16-bit unsigned integers. If a crafted file sets both dimensions to their maximum value (65535), the multiplication ysize… | |
| Modificada | Alta (7.8) | 0.30% | — | GimpRedhat Enterprise Linux | 27/7/2026 | 30/9/2026 | A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bit integers for width and height. If a crafted file sets both values to large values, their product exceeds 2^31 and overflows, resulting in an undersized heap-based… | |
| Analizada | Media (6.5) | 0.25% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information… | |
| Analizada | Alta (7.2) | 0.28% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing… | |
| Analizada | Media (6.5) | 0.38% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or… | |
| Analizada | Media (4.2) | 0.25% | — | Gnome LibsoupRedhat Enterprise Linux | 21/7/2026 | 24/8/2026 | A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-read. A remote attacker could use this flaw to crash an application… | |
| Modificada | Alta (8.8) | 0.49% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 17/8/2026 | A flaw was found in libssh. On servers with GSSAPIKeyExchange enabled, the gssapi-keyex path does not verify whether the authenticated Kerberos principal is authorized for the requested local user, allowing authenticated clients to log in as arbitrary users. | |
| Modificada | Alta (7.5) | 0.35% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-free conditions. | |
| Modificada | Media (5.3) | 0.34% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. A malicious SFTP server can send responses for unknown request IDs that libssh clients keep queued indefinitely, causing unbounded memory growth and client-side denial of service. | |
| Analizada | Alta (7.5) | 0.33% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 4/9/2026 | A flaw was found in libssh. Incorrect AES-GCM finalization checks in builds using the OpenSSL backend can effectively remove integrity protection, allowing an in-path attacker to modify plaintext on the wire without detection. | |
| Modificada | Baja (3.9) | 0.12% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior. | |
| Analizada | Alta (7.5) | 0.44% | — | LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+7 | 21/7/2026 | 22/9/2026 | A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a server, leading to denial of service. | |
| Modificada | Media (5.9) | 0.10% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. When ProxyCommand is used, an unchecked fork() failure can be stored as process ID -1; during cleanup, signals may then be sent across the caller's accessible process tree, leading to local denial of service. | |
| Modificada | Media (6.5) | 0.57% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. A remote authenticated client can issue SSH_FXP_READ requests with an arbitrarily large length, causing a libssh SFTP server to allocate excessive memory and potentially exhaust it through repeated requests. | |
| Modificada | Media (6.5) | 0.73% | — | LibsshRedhat Hardened ImagesRedhat Enterprise Linux | 21/7/2026 | 1/9/2026 | A flaw was found in libssh. A remote authenticated peer can advertise a zero maximum packet size in SSH_MSG_CHANNEL_OPEN, causing later channel writes to loop indefinitely and consume CPU, leading to denial of service. | |
| Analizada | Media (5.3) | 0.49% | — | LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+7 | 21/7/2026 | 22/9/2026 | A flaw was found in libssh. During server-side GSSAPI key exchange, a client-supplied Curve25519 public key shorter than the expected length is copied without proper length validation, leading to an out-of-bounds heap read. This could allow a remote unauthenticated attacker to disclose small amounts of server memory. | |
| Analizada | Alta (7.3) | 0.17% | — | LibsshRedhat Hardened ImagesRedhat Enterprise LinuxRedhat Enterprise Linux FOR ELS+7 | 21/7/2026 | 22/9/2026 | A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack buffer. When a client causes the server to list attacker-controlled filenames, sufficiently long names can overflow that stack buffer and may lead to crashes or possible… | |
| Analizada | Baja (3.7) | 0.36% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 8/7/2026 | 9/7/2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though… | |
| Analizada | Media (4.4) | 0.11% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 7/7/2026 | 9/7/2026 | A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks. | |
| Analizada | Media (5.3) | 0.49% | — | Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux | 7/7/2026 | 9/7/2026 | A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted value encoding a multivalued nested Relative Distinguished Name (RDN), the server can write past the end of a heap allocation while sorting RDN attribute-value pairs. An… | |
| Modificada | Alta (7.8) | 0.26% | — | GimpRedhat Enterprise Linux | 7/7/2026 | 30/9/2026 | A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table, after which subsequent per-row writes corrupt heap memory. This could lead to memory corruption, potentially resulting in denial of service or arbitrary code execution. | |
| Analizada | Media (5.5) | 0.30% | — | GimpRedhat Enterprise Linux | 6/7/2026 | 21/8/2026 | A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color Look-Up Table (CLUT) due to an integer overflow. This occurs when multiplying num_colors and num_cluts, both 16-bit unsigned short integers, resulting in a value… | |
| Modificada | Alta (7.8) | 0.26% | — | GimpRedhat Enterprise Linux | 6/7/2026 | 30/9/2026 | A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null terminator one byte past the end of a stack-allocated buffer due to an off-by-one error in the loop boundary check. This could lead to memory corruption, potentially resulting… | |
| Analizada | Alta (7.3) | 0.29% | — | GimpRedhat Enterprise Linux | 2/7/2026 | 22/9/2026 | A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially crafted PSP file. This could allow an attacker to cause memory corruption, potentially leading to denial of service or arbitrary code execution. |