Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

231 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.2%—EglibcNovell Suse Linux Enterprise ServerDebian LinuxCanonical Ubuntu Linux+131/12/201916/6/2026
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
ModificadaBaja (3.3)0.41%—GNU GlibcCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux19/11/201917/6/2026
On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid…
ModificadaMedia (5.3)2.3%—GNU Glibc15/7/201917/6/2026
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.
ModificadaMedia (5.3)3.2%—GNU Glibc15/7/201917/6/2026
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.
ModificadaMedia (5.4)3.0%—GNU Glibc15/7/201917/6/2026
GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate…
ModificadaCrítica (9.8)3.2%—GNU Glibc15/7/201917/6/2026
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a…
ModificadaAlta (7.5)3.2%—Gnome Glib28/6/201917/6/2026
The keyfile settings backend in GNOME GLib (aka glib2.0) before 2.60.0 creates directories using g_file_make_directory_with_parents (kfsb->dir, NULL, NULL) and files using g_file_replace_contents (kfsb->file, contents, length, NULL, FALSE, G_FILE_CREATE_REPLACE_DESTINATION, NULL, NULL, NULL). Consequently, it does not…
ModificadaCrítica (9.8)2.6%—Gnome GlibDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUS+529/5/201917/6/2026
file_copy_fallback in gio/gfile.c in GNOME GLib 2.15.0 through 2.61.1 does not properly restrict file permissions while a copy operation is in progress. Instead, default permissions are used.
ModificadaMedia (5.5)0.30%—GNU Glibc10/4/201916/6/2026
The nscd daemon in the GNU C Library (glibc) before version 2.5 does not close incoming client sockets if they cannot be handled by the daemon, allowing local users to carry out a denial of service attack on the daemon.
ModificadaCrítica (9.8)2.1%—GNU Glibc10/4/201916/6/2026
The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if the specified array size is zero, leading to a buffer overflow and potentially allowing attackers to corrupt memory.
ModificadaMedia (6.5)2.3%—Gnome Glib8/3/201917/6/2026
gio/gsocketclient.c in GNOME GLib 2.59.2 does not ensure that a parent GTask remains alive during the execution of a connection-attempting enumeration, which allows remote attackers to cause a denial of service (g_socket_client_connected_callback mishandling and application crash) via a crafted web site, as…
ModificadaAlta (7.5)2.4%—GNU Glibc26/2/201917/6/2026
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with…
ModificadaCrítica (9.8)4.7%—GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage+226/2/201917/6/2026
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
ModificadaAlta (7.5)5.8%—GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage26/2/201917/6/2026
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.
ModificadaAlta (7.5)3.9%—GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage26/2/201916/6/2026
In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
ModificadaMedia (5.5)0.61%—GNU Glibc3/2/201917/6/2026
In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled.
ModificadaMedia (5.3)0.48%—GNU GlibcOpensuse Leap21/1/201917/6/2026
In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded…
ModificadaAlta (7.8)0.44%—GNU Glibc18/1/201917/6/2026
The string component in the GNU C Library (aka glibc or libc6) through 2.28, when running on the x32 architecture, incorrectly attempts to use a 64-bit register for size_t in assembly codes, which can lead to a segmentation fault or possibly unspecified other impact, as demonstrated by a crash in…
ModificadaAlta (7.5)5.5%—GNU GlibcFedoraproject Fedora4/12/201817/6/2026
In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.
ModificadaAlta (7.5)3.5%—Gnome GlibCanonical Ubuntu Linux4/9/201817/6/2026
GNOME GLib 2.56.1 has an out-of-bounds read vulnerability in g_markup_parse_context_parse() in gmarkup.c, related to utf8_str().
ModificadaCrítica (9.8)4.7%—Gnome GlibCanonical Ubuntu Linux4/9/201817/6/2026
In GNOME GLib 2.56.1, g_markup_parse_context_end_parse() in gmarkup.c has a NULL pointer dereference.
ModificadaMedia (6.5)2.9%—TaglibDebian Linux30/5/201817/6/2026
The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file.
ModificadaAlta (7.8)0.88%—GNU GlibcRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+618/5/201817/6/2026
An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper.
ModificadaCrítica (9.8)7.1%—GNU GlibcRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+518/5/201817/6/2026
stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.
ModificadaCrítica (9.8)4.6%—GNU Glibc18/5/201817/6/2026
An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans the middle of the address space, resulting in corrupt data being…
Orbitaley — Vulnerabilidades