Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 10% | — | Jasper Project JasperOracle Outside IN TechnologyCanonical Ubuntu LinuxDebian Linux+5 | 15/12/2011 | 16/6/2026 | The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component… | |
| Modificada | Media (6.8) | 10% | — | Jasper Project JasperOracle Outside IN TechnologyCanonical Ubuntu LinuxDebian Linux+4 | 15/12/2011 | 16/6/2026 | Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file. | |
| Modificada | Media (6.8) | 1.5% | — | Jasperforge Jasperreports Server Community Project | 20/9/2011 | 16/6/2026 | JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach. | |
| Modificada | Alta (7.5) | 1.3% | — | Jasper Httpdx | 20/4/2010 | 16/6/2026 | The FTP server component in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 has a default password of pass123 for the moderator account, which makes it easier for remote attackers to obtain privileged access. | |
| Modificada | Alta (9.3) | 38% | 💥 Exploit | Jasper Httpdx | 20/4/2010 | 16/6/2026 | Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remote attackers to execute arbitrary code via format string specifiers in a GET request to the HTTP server component when logging is enabled, and allow (2) remote authenticated users to execute… | |
| Modificada | Media (5) | 7.1% | 💥 Exploit | Jasper Httpdx | 31/12/2009 | 16/6/2026 | httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI. | |
| Modificada | Alta (10) | 64% | 💥 Exploit | Jasper Httpdx | 16/10/2009 | 16/6/2026 | Stack-based buffer overflow in the h_handlepeer function in http.cpp in httpdx 1.4, and possibly 1.4.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request. | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Jasper Httpdx | 11/10/2009 | 16/6/2026 | Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in the Host header. | |
| Modificada | Alta (10) | 4.5% | — | Redhat Enterprise VirtualizationJasper Project Jasper | 2/10/2008 | 16/6/2026 | Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf. | |
| Modificada | Alta (7.2) | 0.45% | — | Jasper Project Jasper | 2/10/2008 | 16/6/2026 | Race condition in the jas_stream_tmpfile function in libjasper/base/jas_stream.c in JasPer 1.900.1 allows local users to cause a denial of service (program exit) by creating the appropriate tmp.XXXXXXXXXX temporary file, which causes Jasper to exit. NOTE: this was originally reported as a symlink issue, but this was… | |
| Modificada | Alta (9.3) | 3.2% | — | Jasper Project Jasper | 2/10/2008 | 16/6/2026 | Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation. | |
| Modificada | Media (4.3) | 2.3% | — | Jasper Jpeg-2000 | 16/5/2007 | 16/6/2026 | The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) before 1.900 allows remote user-assisted attackers to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert. |