Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 4.8% | — | GNU GlibcOracle Communications Cloud Native Core Unified Data RepositoryOracle Enterprise Operations MonitorDebian Linux | 14/1/2022 | 17/6/2026 | The deprecated compatibility function svcunix_create in the sunrpc module of the GNU C Library (aka glibc) through 2.34 copies its path argument on the stack without validating its length, which may result in a buffer overflow, potentially resulting in a denial of service or (if an application is not built with a… | |
| Modificada | Alta (7.5) | 3.3% | — | GNU GlibcOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+3 | 4/11/2021 | 17/6/2026 | In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This may affect data integrity in certain iconv() use cases. NOTE: the vendor states "the bug cannot be… | |
| Modificada | Alta (7.5) | 3.0% | — | GNU GlibcFedoraproject FedoraOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native Environment+4 | 12/8/2021 | 17/6/2026 | In librt in the GNU C Library (aka glibc) through 2.34, sysdeps/unix/sysv/linux/mq_notify.c mishandles certain NOTIFY_REMOVED data, leading to a NULL pointer dereference. NOTE: this vulnerability was introduced as a side effect of the CVE-2021-33574 fix. | |
| Modificada | Crítica (9.1) | 2.6% | — | GNU GlibcNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp HCI Management Node+3 | 22/7/2021 | 17/6/2026 | The wordexp function in the GNU C Library (aka glibc) through 2.33 may crash or read arbitrary memory in parse_param (in posix/wordexp.c) when called with an untrusted, crafted pattern, potentially resulting in a denial of service or disclosure of information. This occurs because atoi was used but strtoul should have… | |
| Modificada | Crítica (9.8) | 2.9% | — | GNU GlibcFedoraproject FedoraNetapp Cloud BackupNetapp E-series Santricity OS Controller+9 | 25/5/2021 | 17/6/2026 | The mq_notify function in the GNU C Library (aka glibc) versions 2.32 and 2.33 has a use-after-free. It may use the notification thread attributes object (passed through its struct sigevent parameter) after it has been freed by the caller, leading to a denial of service (application crash) or possibly unspecified… | |
| Modificada | Media (5.5) | 0.89% | — | Cpp-peglib Project Cpp-peglib | 21/4/2021 | 17/6/2026 | An issue was discovered in cpp-peglib through v0.1.12. peg::resolve_escape_sequence() in peglib.h has a heap-based buffer over-read. | |
| Modificada | Media (5.5) | 0.87% | — | Cpp-peglib Project Cpp-peglib | 21/4/2021 | 17/6/2026 | An issue was discovered in cpp-peglib through v0.1.12. A NULL pointer dereference exists in the peg::AstOptimizer::optimize() located in peglib.h. It allows an attacker to cause Denial of Service. | |
| Modificada | Media (5.3) | 2.6% | — | Gnome GlibBroadcom Brocade Fabric Operating System FirmwareDebian LinuxFedoraproject Fedora | 11/3/2021 | 17/6/2026 | An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is… | |
| Modificada | Media (5.5) | 0.89% | — | GNU GlibcNetapp Ontap Select Deploy Administration UtilityNetapp A250 FirmwareNetapp 500f Firmware+10 | 26/2/2021 | 17/6/2026 | The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a… | |
| Modificada | Baja (2.5) | 0.37% | — | GNU GlibcFedoraproject FedoraDebian Linux | 24/2/2021 | 17/6/2026 | The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c. | |
| Modificada | Alta (7.5) | 3.0% | — | Gnome GlibFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+3 | 15/2/2021 | 17/6/2026 | An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption. | |
| Modificada | Alta (7.5) | 4.1% | — | Gnome GlibFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Cloud Backup+3 | 15/2/2021 | 17/6/2026 | An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing unintended length truncation. | |
| Modificada | Alta (7.5) | 3.1% | — | GNU GlibcNetapp E-series Santricity OS ControllerNetapp Ontap Select Deploy Administration UtilityOracle Communications Cloud Native Core Security Edge Protection Proxy+7 | 27/1/2021 | 17/6/2026 | The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service. | |
| Modificada | Media (5.9) | 3.6% | — | GNU GlibcFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp Service Processor+4 | 4/1/2021 | 17/6/2026 | The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read. | |
| Modificada | Alta (7.8) | 0.57% | — | Gnome Glib | 14/12/2020 | 17/6/2026 | GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern is for callers to provide a static list of option entries in a fixed number of calls to… | |
| Modificada | Alta (7.5) | 2.7% | — | GNU GlibcRedhat Enterprise LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller | 6/12/2020 | 17/6/2026 | sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long double with a non-canonical bit pattern, as seen when passing a \x00\x04\x00\x00\x00\x00\x00\x00\x00\x04 value to… | |
| Modificada | Media (4.8) | 1.5% | — | GNU GlibcFedoraproject FedoraNetapp E-series Santricity OS Controller | 4/12/2020 | 17/6/2026 | The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service. | |
| Modificada | Crítica (9.8) | 2.4% | — | GNU Glibc | 6/10/2020 | 25/9/2026 | manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999. | |
| Modificada | Media (6.5) | 2.0% | — | Gnome BalsaGnome Glib-networkingCanonical Ubuntu LinuxFedoraproject Fedora+2 | 28/5/2020 | 17/6/2026 | In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications… | |
| Modificada | Alta (7) | 0.53% | — | GNU GlibcCanonical Ubuntu LinuxNetapp Active IQ Unified ManagerNetapp HCI Management Node+4 | 30/4/2020 | 17/6/2026 | A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that,… | |
| Modificada | Alta (7) | 0.54% | — | GNU GlibcRedhat Enterprise LinuxCanonical Ubuntu Linux | 17/4/2020 | 17/6/2026 | An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this… | |
| Modificada | Alta (8.1) | 5.4% | — | GNU GlibcFedoraproject FedoraDebian Linux | 1/4/2020 | 17/6/2026 | An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the… | |
| Modificada | Crítica (9.8) | 1.5% | — | Svglib Project Svglib | 20/3/2020 | 17/6/2026 | The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call. | |
| Modificada | Media (5.5) | 0.76% | — | GNU GlibcFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap+7 | 4/3/2020 | 17/6/2026 | The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to… | |
| Modificada | Media (5.9) | 2.2% | — | Gnome GlibFedoraproject Fedora | 9/1/2020 | 17/6/2026 | GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security… |