Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.3% | — | Gdraheim ZziplibRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 6/3/2018 | 17/6/2026 | An issue was discovered in ZZIPlib 0.13.68. There is a memory leak triggered in the function zzip_mem_disk_new in memdisk.c, which will lead to a denial of service attack. | |
| Modificada | Media (6.5) | 1.7% | — | Gdraheim ZziplibCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 6/3/2018 | 17/6/2026 | An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the __zzip_parse_root_directory function of zip.c. Attackers could leverage this vulnerability to cause a denial of service via a crafted zip file. | |
| Modificada | Media (6.5) | 1.7% | — | Gdraheim ZziplibCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 6/3/2018 | 17/6/2026 | An issue was discovered in ZZIPlib 0.13.68. An invalid memory address dereference was discovered in zzip_disk_fread in mmapped.c. The vulnerability causes an application crash, which leads to denial of service. | |
| Modificada | Media (6.5) | 2.8% | — | Gdraheim ZziplibDebian LinuxCanonical Ubuntu Linux | 9/2/2018 | 17/6/2026 | In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file. | |
| Modificada | Media (6.5) | 1.2% | — | Gdraheim Zziplib | 2/2/2018 | 17/6/2026 | In ZZIPlib 0.13.67, there is a bus error (when handling a disk64_trailer seek value) caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c. | |
| Modificada | Media (6.5) | 2.3% | — | Gdraheim ZziplibCanonical Ubuntu Linux | 2/2/2018 | 17/6/2026 | In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address (when handling disk64_trailer local entries) in __zzip_fetch_disk_trailer (zzip/zip.c). Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file. | |
| Modificada | Media (6.5) | 2.3% | — | Gdraheim ZziplibCanonical Ubuntu Linux | 2/2/2018 | 17/6/2026 | In ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file. | |
| Modificada | Media (6.5) | 2.2% | — | Gdraheim ZziplibCanonical Ubuntu Linux | 1/2/2018 | 17/6/2026 | In ZZIPlib 0.13.67, there is a memory alignment error and bus error in the __zzip_fetch_disk_trailer function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file. | |
| Modificada | Media (6.5) | 1.7% | — | Gdraheim ZziplibCanonical Ubuntu Linux | 29/1/2018 | 17/6/2026 | In ZZIPlib 0.13.67, 0.13.66, 0.13.65, 0.13.64, 0.13.63, 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57 and 0.13.56 there is a segmentation fault caused by invalid memory access in the zzip_disk_fread function (zzip/mmapped.c) because the size variable is not validated against the amount of file->stored data. | |
| Modificada | Crítica (9.8) | 3.0% | — | Axcient Replibit | 27/8/2017 | 17/6/2026 | Privilege escalation in Replibit Backup Manager earlier than version 2017.08.04 allows attackers to gain root privileges via sudo command execution. The vi program can be accessed through sudo, in order to navigate the filesystem and modify a critical file such as /etc/passwd. | |
| Modificada | Media (5.5) | 1.6% | — | Gdraheim Zziplib | 1/3/2017 | 17/6/2026 | seeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (assertion failure and crash) via a crafted ZIP file. | |
| Modificada | Media (5.5) | 1.3% | — | Gdraheim Zziplib | 1/3/2017 | 17/6/2026 | The zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file. | |
| Modificada | Media (5.5) | 1.6% | — | Gdraheim Zziplib | 1/3/2017 | 17/6/2026 | The prescan_entry function in fseeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file. | |
| Modificada | Media (5.5) | 1.6% | — | Gdraheim Zziplib | 1/3/2017 | 17/6/2026 | The zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted ZIP file. | |
| Modificada | Media (5.5) | 1.7% | — | Gdraheim Zziplib | 1/3/2017 | 17/6/2026 | The zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (invalid memory read and crash) via a crafted ZIP file. | |
| Modificada | Media (5.5) | 2.0% | — | Gdraheim ZziplibDebian Linux | 1/3/2017 | 17/6/2026 | Heap-based buffer overflow in the zzip_mem_entry_extra_block function in memdisk.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file. | |
| Modificada | Media (5.5) | 2.1% | — | Gdraheim ZziplibDebian Linux | 1/3/2017 | 17/6/2026 | Heap-based buffer overflow in the __zzip_get64 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file. | |
| Modificada | Media (5.5) | 1.8% | — | Gdraheim ZziplibDebian Linux | 1/3/2017 | 17/6/2026 | Heap-based buffer overflow in the __zzip_get32 function in fetch.c in zziplib 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57, 0.13.56 allows remote attackers to cause a denial of service (crash) via a crafted ZIP file. | |
| Modificada | Baja (2.6) | 1.3% | — | Canonical Ubuntu LinuxHttplib2 Project Httplib2 | 18/1/2014 | 16/6/2026 | httplib2 0.7.2, 0.8, and earlier, after an initial connection is made, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Media (6.8) | 10.0% | 💥 Exploit | Steve J Baker Plib | 18/11/2012 | 16/6/2026 | Stack-based buffer overflow in the error function in ssg/ssgParser.cxx in PLIB 1.8.5 allows remote attackers to execute arbitrary code via a crafted 3d model file that triggers a long error message, as demonstrated by a .ase file. | |
| Modificada | Alta (9.3) | 13% | 💥 Exploit | Steve J Baker Plib | 31/12/2011 | 16/6/2026 | Buffer overflow in the ulSetError function in util/ulError.cxx in PLIB 1.8.5, as used in TORCS 1.3.1 and other products, allows user-assisted remote attackers to execute arbitrary code via vectors involving a long error message, as demonstrated by a crafted acc file for TORCS. NOTE: some of these details are obtained… | |
| Modificada | Alta (7.5) | 8.6% | 💥 Exploit | Speedtech Stphplibrary | 6/9/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the STPHPLIB_DIR parameter to (1) stphpapplication.php, (2) stphpbtnimage.php, or (3) stphpform.php. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Speedtech Stphplibrary | 6/9/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) db_conf or (2) ADODB_DIR parameter to utils/stphpimage_show.php; or a URL in the STPHPLIB_DIR parameter to (3) stphpbutton.php, (4)… | |
| Modificada | Alta (9.3) | 6.6% | — | Zziplib | 23/3/2007 | 16/6/2026 | Stack-based buffer overflow in the zzip_open_shared_io function in zzip/file.c in ZZIPlib Library before 0.13.49 allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long filename. | |
| Modificada | Alta (10) | 2.8% | — | Ftplib | 16/3/2007 | 16/6/2026 | Buffer overflow in the set_umask function in QFTP in LIBFtp 3.1-1 allows local users to execute arbitrary code via a long -m argument. NOTE: CVE disputes this issue because QFTP is not setuid, and it is unlikely that there are web interfaces to QFTP that would accept untrusted command line arguments |