Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

172 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)4.5%—Opensuse LeapOpensuseGNU GlibcCanonical Ubuntu Linux10/6/201617/6/2026
Stack-based buffer overflow in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) allows remote servers to cause a denial of service (crash) or possibly unspecified other impact via a flood of crafted ICMP and UDP packets.
ModificadaAlta (7.5)5.9%—OpensuseGNU Glibc10/6/201617/6/2026
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in the GNU C Library (aka glibc or libc6) allows remote attackers to cause a denial of service (crash) via vectors involving hostent conversion. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4458.
ModificadaAlta (7.5)7.3%—OpensuseGNU GlibcFedoraproject FedoraCanonical Ubuntu Linux1/6/201617/6/2026
Stack-based buffer overflow in the nss_dns implementation of the getnetbyname function in GNU C Library (aka glibc) before 2.24 allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a long name.
ModificadaAlta (7.5)5.4%—GNU GlibcOpensuse LeapOpensuseFedoraproject Fedora1/6/201617/6/2026
Stack-based buffer overflow in the glob implementation in GNU C Library (aka glibc) before 2.24, when GLOB_ALTDIRFUNC is used, allows context-dependent attackers to cause a denial of service (crash) via a long name.
ModificadaCrítica (9.8)6.2%—Suse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+619/4/201617/6/2026
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.
ModificadaCrítica (9.8)5.7%—Fedoraproject FedoraDebian LinuxCanonical Ubuntu LinuxGNU Glibc+619/4/201617/6/2026
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access.
ModificadaCrítica (9.1)4.8%—Suse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+619/4/201617/6/2026
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
ModificadaCrítica (9.8)5.5%—Suse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+519/4/201617/6/2026
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function.
ModificadaAlta (8.1)91%💥 ExploitDebian LinuxCanonical Ubuntu LinuxHP Helion OpenstackHP Server Migration Pack+2618/2/201617/6/2026
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the…
ModificadaMedia (5.5)0.57%—GNU Glibc20/1/201617/6/2026
The process_envvars function in elf/rtld.c in the GNU C Library (aka glibc or libc6) before 2.23 allows local users to bypass a pointer-guarding protection mechanism via a zero value of the LD_POINTER_GUARD environment variable.
ModificadaAlta (7.2)0.59%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+217/12/201517/6/2026
The get_contents function in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) before 2.20 might allow local users to cause a denial of service (heap corruption) or gain privileges via a long line in the NSS files database.
ModificadaMedia (6.8)5.0%—Suse Linux Enterprise DebuginfoSuse Linux Enterprise DesktopSuse Linux Enterprise ServerGNU Glibc+228/9/201517/6/2026
Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer.
ModificadaMedia (5.1)2.7%—GNU Glibc26/8/201517/6/2026
The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.
ModificadaMedia (6.4)2.1%—Canonical Ubuntu LinuxGNU Glibc8/4/201517/6/2026
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite…
ModificadaAlta (7.5)4.7%—Canonical Ubuntu LinuxGNU Glibc8/4/201517/6/2026
The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing…
ModificadaMedia (5)5.6%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerGNU GlibcCanonical Ubuntu Linux27/3/201517/6/2026
DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up on a database while iterating over it, which triggers…
ModificadaAlta (7.8)7.8%—GNU GlibcCanonical Ubuntu LinuxOpensuse24/2/201517/6/2026
The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process.
ModificadaMedia (5)5.8%—Redhat Enterprise Linux Server AUSCanonical Ubuntu LinuxOpensuseGNU Glibc24/2/201517/6/2026
The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.
ModificadaAlta (10)95%💥 ExploitGNU GlibcOracle Communications Application Session ControllerOracle Communications Eagle Application ProcessorOracle Communications Eagle LNP Application Processor+1428/1/201517/6/2026
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
ModificadaMedia (5)6.6%—GNU Glibc5/12/201417/6/2026
GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte character value of "0xffff" to the iconv function when converting (1) IBM933, (2) IBM935, (3) IBM937, (4) IBM939, or (5) IBM1364 encoded data to UTF-8.
ModificadaMedia (5)3.4%—Debian LinuxCanonical Ubuntu LinuxGNU Glibc5/12/201416/6/2026
iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when converting IBM930 encoded data to UTF-8.
ModificadaMedia (4.6)0.58%—Canonical Ubuntu LinuxDebian LinuxGNU GlibcOpensuse24/11/201417/6/2026
The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))".
ModificadaMedia (6.8)8.5%💥 ExploitGNU GlibcGNU Eglibc27/10/201416/6/2026
Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allows context-dependent attackers to execute arbitrary code via a negative length parameter to (1) memcpy-ssse3-rep.S, (2) memcpy-ssse3.S, or (3) memset-sse2.S in…
ModificadaAlta (7.5)3.9%—GNU GlibcOpensuse6/10/201417/6/2026
The posix_spawn_file_actions_addopen function in glibc before 2.20 does not copy its path argument in accordance with the POSIX specification, which allows context-dependent attackers to trigger use-after-free vulnerabilities.
ModificadaAlta (7.5)17%💥 ExploitGNU GlibcDebian Linux29/8/201417/6/2026
Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.
Orbitaley — Vulnerabilidades