Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 1.7% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c. | |
| Modificada | Alta (8.1) | 1.7% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c. | |
| Modificada | Media (6.5) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse BackportsOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has an attempted excessive memory allocation in read_sections_map in decode_r2007.c. | |
| Modificada | Alta (8.8) | 1.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 8/1/2020 | 17/6/2026 | GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LWPOLYLINE_private in dwg.spec. | |
| Modificada | Alta (8.8) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode_3dsolid in dwg.spec. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HATCH_private in dwg.spec. | |
| Modificada | Alta (8.8) | 1.5% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c. | |
| Modificada | Alta (8.8) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c. | |
| Modificada | Media (6.5) | 1.4% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 27/12/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_SPLINE_private in dwg.spec. | |
| Modificada | Alta (7.5) | 2.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (earlier than CVE-2019-9776). | |
| Modificada | Alta (7.5) | 2.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at dwg.spec. | |
| Modificada | Alta (7.5) | 2.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write at header_variables_dxf.spec. | |
| Modificada | Alta (7.5) | 2.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (later than CVE-2019-9779). | |
| Modificada | Crítica (9.1) | 3.0% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_CONTROL at dwg.spec. | |
| Modificada | Crítica (9.1) | 3.0% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at bits.c. | |
| Modificada | Alta (7.5) | 2.9% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the z dimension. | |
| Modificada | Alta (7.5) | 2.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dwg.spec. | |
| Modificada | Alta (7.5) | 2.8% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bits.c. | |
| Modificada | Alta (7.5) | 2.9% | — | GNU LibredwgOpensuse Backports SLEOpensuse Leap | 14/3/2019 | 17/6/2026 | An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the y dimension. | |
| Modificada | Media (6.5) | 1.1% | — | GNU Libredwg | 23/7/2018 | 17/6/2026 | dwg_decode_eed in decode.c in GNU LibreDWG before 0.6 leads to a double free (in dwg_free_eed in free.c) because it does not properly manage the obj->eed value after a free occurs. | |
| Modificada | Media (6.5) | 1.4% | — | GNU Libredwg | 20/7/2018 | 17/6/2026 | dwg_obj_block_control_get_block_headers in dwg_api.c in GNU LibreDWG 0.5.1048 allows remote attackers to cause a denial of service (NULL pointer dereference and SEGV) via a crafted dwg file. | |
| Modificada | Media (6.5) | 1.1% | — | GNU Libredwg | 20/7/2018 | 17/6/2026 | get_first_owned_object in dwg.c in GNU LibreDWG 0.5.1036 allows remote attackers to cause a denial of service (SEGV). |