Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.46% | — | LibsoupAIGnomeAIWebkitAI | 23/10/2025 | 30/6/2026 | A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-based applications to manage HTTP/2 communications. When network operations are aborted at specific timing intervals, an internal message queue item may be freed twice due to missing state… | |
| Aplazada | Alta (7.5) | 0.64% | — | Gnome LibsoupAI | 26/9/2025 | 29/6/2026 | A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applications for web communication. When processing cookies with specially crafted expiration dates, the library may perform an out-of-bounds memory read. This flaw could result in unintended disclosure of… | |
| Aplazada | Baja (3.7) | 0.36% | — | OpensslAIGnome Glib-networkingAI | 25/9/2025 | 30/6/2026 | glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location. | |
| Aplazada | Media (5.9) | 0.45% | — | Gnome LibsoupAI | 3/9/2025 | 30/6/2026 | A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached responses. This header ensures that responses vary appropriately based on request headers such as language or authentication. Without this check, cached content can be incorrectly reused across… | |
| Aplazada | Baja (3.7) | 0.40% | — | Gnome GlibAI | 3/9/2025 | 17/6/2026 | A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and… | |
| Modificada | Alta (7.5) | 0.45% | — | Gnome Glib | 28/7/2025 | 30/6/2026 | A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long command lines. | |
| Rechazada | Sin puntuar | — | — | Gnome LibsoupAI | 25/7/2025 | 14/8/2025 | Rejected reason: Maintainers have included reasons at https://gitlab.gnome.org/GNOME/libsoup/-/issues/465 | |
| Rechazada | Sin puntuar | — | — | Gnome LibsoupAI | 10/7/2025 | 15/7/2025 | Rejected reason: Upon investigtion upstream maintainers discovered this was not a real issue. See the references for more details. See: https://gitlab.gnome.org/GNOME/libsoup/-/issues/430#note_2494090. | |
| Aplazada | Alta (7.5) | 1.2% | — | Gnome Gdk-pixbufAIGnome GlibAI | 8/7/2025 | 30/6/2026 | A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially… | |
| Modificada | Baja (3.3) | 0.21% | — | Gnome Gdkpixbuf | 17/6/2025 | 30/6/2026 | A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included… | |
| Analizada | Media (5.5) | 0.24% | — | Gnome Libgepub | 17/6/2025 | 17/6/2026 | A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected usage includes desktop services like Tumbler, which may process… | |
| Modificada | Alta (7.5) | 0.52% | — | Gnome Glib | 13/6/2025 | 17/6/2026 | A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the… | |
| Aplazada | Alta (7.4) | 0.82% | — | Gnome-remote-desktopAI | 22/5/2025 | 30/6/2026 | A flaw was found in gnome-remote-desktop. Once gnome-remote-desktop listens for RDP connections, an unauthenticated attacker can exhaust system resources and repeatedly crash the process. There may be a resource leak after many attacks, which will also result in gnome-remote-desktop no longer being able to open files… | |
| Aplazada | Media (6.5) | 0.87% | — | Gnome LibsoupAI | 21/5/2025 | 30/6/2026 | A vulnerability was found in the libsoup package. This flaw stems from its failure to correctly verify the termination of multipart HTTP messages. This can allow a remote attacker to send a specially crafted multipart HTTP body, causing the libsoup-consuming server to read beyond its allocated memory boundaries… | |
| Aplazada | Baja (3.7) | 0.67% | — | Gnome LibsoupAI | 19/5/2025 | 30/6/2026 | A flaw was found in the cookie parsing logic of the libsoup HTTP library, used in GNOME applications and other software. The vulnerability arises when processing the expiration date of cookies, where a specially crafted value can trigger an integer overflow. This may result in undefined behavior, allowing an attacker… | |
| Aplazada | Alta (7.5) | 0.78% | — | Gnome LibsoupAI | 19/5/2025 | 30/6/2026 | A flaw was found in the soup_multipart_new_from_message() function of the libsoup HTTP library, which is commonly used by GNOME and other applications to handle web communications. The issue occurs when the library processes specially crafted multipart messages. Due to improper validation, an internal calculation can… | |
| Aplazada | Media (4.3) | 0.38% | 💥 PoC | Gnome LibsoupAI | 16/5/2025 | 30/6/2026 | A denial-of-service vulnerability has been identified in the libsoup HTTP client library. This flaw can be triggered when a libsoup client receives a 401 (Unauthorized) HTTP response containing a specifically crafted domain parameter within the WWW-Authenticate header. Processing this malformed header can lead to a… | |
| Aplazada | Media (4.8) | 0.64% | — | Gnome GlibAI | 6/5/2025 | 21/9/2026 | A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite. | |
| Analizada | Media (4.9) | 0.23% | — | Gnome Control CenterCanonical Ubuntu Linux | 15/4/2025 | 17/6/2026 | In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user. | |
| Aplazada | Media (5.3) | 0.68% | — | Gnome LibsoupAI | 14/4/2025 | 30/6/2026 | A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. This flaw allows a malicious client to request the same range many times in a single HTTP request, causing the server to use large amounts of memory. This does not allow for a full denial of service. | |
| Aplazada | Alta (7.5) | 0.95% | — | Gnome LibsoupAI | 14/4/2025 | 29/6/2026 | A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. This flaw allows a malicious user to use a specially crafted HTTP request to crash the HTTP server. | |
| Aplazada | Baja (3.7) | 0.47% | — | Gnome GlibAI | 7/4/2025 | 30/6/2026 | A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function. | |
| Modificada | Alta (7.4) | 14% | — | Gnome YelpDebian LinuxRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64+17 | 3/4/2025 | 29/6/2026 | A flaw was found in Yelp. The Gnome user help application allows the help document to execute arbitrary scripts. This vulnerability allows malicious users to input help documents, which may exfiltrate user files to an external environment. | |
| Aplazada | Alta (7.5) | 0.87% | — | Gnome LibsoupAI | 3/4/2025 | 30/6/2026 | A flaw was found in libsoup. The SoupWebsocketConnection may accept a large WebSocket message, which may cause libsoup to allocate memory and lead to a denial of service (DoS). | |
| Modificada | Media (6.5) | 0.86% | — | Gnome LibsoupRedhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR Arm64Redhat Codeready Linux Builder FOR Arm64 EUS+17 | 3/4/2025 | 30/6/2026 | A flaw was found in libsoup. The package is vulnerable to a heap buffer over-read when sniffing content via the skip_insight_whitespace() function. Libsoup clients may read one byte out-of-bounds in response to a crafted HTTP response by an HTTP server. |