Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.5) | 0.37% | — | GNU GlibcFedoraproject FedoraDebian Linux | 24/2/2021 | 17/6/2026 | The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c. | |
| Modificada | Alta (7.8) | 0.56% | — | Libcaca Project LibcacaDebian LinuxFedoraproject Fedora | 23/2/2021 | 17/6/2026 | A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context. | |
| Modificada | Alta (7.5) | 3.1% | — | GNU GlibcNetapp E-series Santricity OS ControllerNetapp Ontap Select Deploy Administration UtilityOracle Communications Cloud Native Core Security Edge Protection Proxy+7 | 27/1/2021 | 17/6/2026 | The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service. | |
| Modificada | Media (5.9) | 3.6% | — | GNU GlibcFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp Service Processor+4 | 4/1/2021 | 17/6/2026 | The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read. | |
| Modificada | Alta (7.5) | 4.6% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+13 | 14/12/2020 | 17/6/2026 | curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. | |
| Modificada | Alta (7.5) | 9.8% | — | Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. | |
| Modificada | Alta (7.5) | 3.8% | — | Haxx LibcurlSiemens Sinec Infrastructure Network ServicesDebian LinuxOracle Communications Cloud Native Core Policy+1 | 14/12/2020 | 17/6/2026 | Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data. | |
| Modificada | Alta (7.5) | 2.7% | — | GNU GlibcRedhat Enterprise LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller | 6/12/2020 | 17/6/2026 | sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long double with a non-canonical bit pattern, as seen when passing a \x00\x04\x00\x00\x00\x00\x00\x00\x00\x04 value to… | |
| Modificada | Media (4.8) | 1.5% | — | GNU GlibcFedoraproject FedoraNetapp E-series Santricity OS Controller | 4/12/2020 | 17/6/2026 | The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service. | |
| Modificada | Media (5.5) | 0.65% | — | Musl-libc MuslDebian LinuxFedoraproject FedoraOracle Graalvm | 24/11/2020 | 17/6/2026 | In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow). | |
| Modificada | Crítica (9.8) | 2.4% | — | GNU Glibc | 6/10/2020 | 25/9/2026 | manual/search.texi in the GNU C Library (aka glibc) before 2.2 lacks a statement about the unspecified tdelete return value upon deletion of a tree's root, which might allow attackers to access a dangling pointer in an application whose developer was unaware of a documentation update from 1999. | |
| Modificada | Alta (7.1) | 2.3% | — | Gnome Libcroco | 12/5/2020 | 17/6/2026 | libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption. | |
| Modificada | Alta (7) | 0.53% | — | GNU GlibcCanonical Ubuntu LinuxNetapp Active IQ Unified ManagerNetapp HCI Management Node+4 | 30/4/2020 | 17/6/2026 | A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that,… | |
| Modificada | Alta (7) | 0.54% | — | GNU GlibcRedhat Enterprise LinuxCanonical Ubuntu Linux | 17/4/2020 | 17/6/2026 | An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this… | |
| Modificada | Alta (8.1) | 5.4% | — | GNU GlibcFedoraproject FedoraDebian Linux | 1/4/2020 | 17/6/2026 | An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the… | |
| Modificada | Media (5.5) | 0.76% | — | GNU GlibcFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap+7 | 4/3/2020 | 17/6/2026 | The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to… | |
| Modificada | Crítica (9.8) | 2.2% | — | Musl-libc Musl | 20/2/2020 | 17/6/2026 | Multiple stack-based buffer overflows in the __dn_expand function in network/dn_expand.c in musl libc 1.1x before 1.1.2 and 0.9.13 through 1.0.3 allow remote attackers to (1) have unspecified impact via an invalid name length in a DNS response or (2) cause a denial of service (crash) via an invalid name length in a… | |
| Modificada | Alta (7.5) | 3.2% | — | EglibcNovell Suse Linux Enterprise ServerDebian LinuxCanonical Ubuntu Linux+1 | 31/12/2019 | 16/6/2026 | The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service. | |
| Modificada | Crítica (9.8) | 1.6% | — | Dietlibc Project DietlibcOpenbsdDebian Linux | 10/12/2019 | 16/6/2026 | lib/libc/stdlib/random.c in OpenBSD returns 0 when seeded with 0. | |
| Modificada | Baja (3.3) | 0.41% | — | GNU GlibcCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux | 19/11/2019 | 17/6/2026 | On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to restrict the possible mapping addresses for loaded libraries and thus bypass ASLR for a setuid… | |
| Modificada | Crítica (9.8) | 21% | 💥 Exploit | Klibc Project KlibcDebian Linux | 14/11/2019 | 16/6/2026 | In klibc 1.5.20 and 1.5.21, the DHCP options written by ipconfig to /tmp/net-$DEVICE.conf are not properly escaped. This may allow a remote attacker to send a specially crafted DHCP reply which could execute arbitrary code with the privileges of any process which sources DHCP options. | |
| Modificada | Crítica (9.8) | 2.5% | — | Musl-libc Musl | 6/8/2019 | 17/6/2026 | musl libc through 1.1.23 has an x87 floating-point stack adjustment imbalance, related to the math/i386/ directory. In some cases, use of this library could introduce out-of-bounds writes that are not present in an application's source code. | |
| Modificada | Media (5.3) | 2.3% | — | GNU Glibc | 15/7/2019 | 17/6/2026 | GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability. | |
| Modificada | Media (5.3) | 3.2% | — | GNU Glibc | 15/7/2019 | 17/6/2026 | GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat. | |
| Modificada | Media (5.4) | 3.0% | — | GNU Glibc | 15/7/2019 | 17/6/2026 | GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate… |