Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.6% | — | OpenimageioDebian Linux | 22/12/2022 | 17/6/2026 | An out-of-bounds write vulnerability exists in the OpenImageIO::add_exif_item_to_spec functionality of OpenImageIO Project OpenImageIO v2.4.4.2. Specially-crafted exif metadata can lead to stack-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.9% | — | OpenimageioDebian Linux | 22/12/2022 | 17/6/2026 | A heap based buffer overflow vulnerability exists in the PSD thumbnail resource parsing code of OpenImageIO 2.3.19.0. A specially-crafted PSD file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Media (5.5) | 0.77% | — | Openimageio | 22/12/2022 | 17/6/2026 | A heap out of bounds read vulnerability exists in the OpenImageIO master-branch-9aeece7a when parsing the image file directory part of a PSD image file. A specially-crafted .psd file can cause a read of arbitrary memory address which can lead to denial of service. An attacker can provide a malicious file to trigger… | |
| Modificada | Crítica (9.1) | 1.5% | — | OpenimageioDebian Linux | 22/12/2022 | 17/6/2026 | A heap out of bounds read vulnerability exists in the handling of IPTC data while parsing TIFF images in OpenImageIO v2.3.19.0. A specially-crafted TIFF file can cause a read of adjacent heap memory, which can leak sensitive process information. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.9% | — | OpenimageioDebian Linux | 22/12/2022 | 17/6/2026 | A heap based buffer overflow vulnerability exists in tile decoding code of TIFF image parser in OpenImageIO master-branch-9aeece7a and v2.3.19.0. A specially-crafted TIFF file can lead to an out of bounds memory corruption, which can result in arbitrary code execution. An attacker can provide a malicious file to… | |
| Modificada | Crítica (9.8) | 1.5% | — | Openimageio | 22/12/2022 | 17/6/2026 | A heap out-of-bounds write vulnerability exists in the way OpenImageIO v2.3.19.0 processes RLE encoded BMP images. A specially-crafted bmp file can write to arbitrary out of bounds memory, which can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Media (5.3) | 0.79% | — | OpenimageioDebian Linux | 22/12/2022 | 17/6/2026 | A heap out-of-bounds read vulnerability exists in the RLA format parser of OpenImageIO master-branch-9aeece7a and v2.3.19.0. More specifically, in the way run-length encoded byte spans are handled. A malformed RLA file can lead to an out-of-bounds read of heap metadata which can result in sensitive information leak.… | |
| Modificada | Alta (9.3) | 6.5% | — | Apple ImageioApple Safari | 21/7/2011 | 16/6/2026 | Heap-based buffer overflow in ImageIO in Apple Safari before 5.0.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with CCITT Group 4 encoding. | |
| Modificada | Alta (9.3) | 4.5% | — | Apple ImageioApple Safari | 21/7/2011 | 16/6/2026 | ImageIO in Apple Safari before 5.0.6 on Windows does not properly address re-entrancy issues, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file. | |
| Modificada | Media (6.8) | 3.8% | — | Apple ImageioApple MAC OS XApple MAC OS X Server | 24/6/2011 | 16/6/2026 | Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image. | |
| Modificada | Media (6.8) | 3.9% | — | Apple MAC OS XApple ImageioApple MAC OS X Server | 24/6/2011 | 16/6/2026 | Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image. | |
| Modificada | Media (6.8) | 2.5% | — | Apple ImageioApple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Integer overflow in ImageIO in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image with JPEG encoding. | |
| Modificada | Media (6.8) | 2.8% | — | Apple MAC OS XApple ImageioApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Integer overflow in ImageIO in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XBM image. | |
| Modificada | Alta (9.3) | 7.3% | — | Apple Imageio | 13/3/2007 | 16/6/2026 | Unspecified vulnerability in ImageIO in Apple Mac OS X 10.3.9 and 10.4 through 10.4.8 allows remote user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted RAW image that triggers memory corruption. | |
| Modificada | Media (5) | 4.4% | — | Apple SafariApple ImageioApple MAC OS XApple MAC OS X Server | 31/3/2006 | 16/6/2026 | Integer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.5 allows remote attackers to cause a denial of service (crash) via a crafted JPEG image with malformed JPEG metadata, as demonstrated using Safari, aka "Deja-Doom". |