Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

141 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)1.1%—Qpdf Project Qpdf13/2/201817/6/2026
An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.
ModificadaMedia (5.5)1.1%—Qpdf Project Qpdf13/2/201817/6/2026
An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizer.cc, related to the QPDF::resolve function in QPDF.cc.
ModificadaAlta (7.8)1.8%—Qpdf Project Qpdf27/8/201717/6/2026
The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack consumption and segmentation fault) or possibly have unspecified other impact via a PDF document with a deep data structure, as demonstrated by a crash in…
ModificadaMedia (5.5)1.2%—Qpdf Project Qpdf25/7/201717/6/2026
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the PointerHolder function in PointerHolder.hh, aka an "infinite loop."
ModificadaMedia (5.5)1.2%—Qpdf Project Qpdf25/7/201717/6/2026
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after four consecutive calls to QPDFObjectHandle::parseInternal, aka an "infinite loop."
ModificadaMedia (5.5)1.2%—Qpdf Project Qpdf25/7/201717/6/2026
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDF::resolveObjectsInStream function in QPDF.cc, aka an "infinite loop."
ModificadaMedia (5.5)1.2%—Qpdf Project Qpdf25/7/201717/6/2026
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after two consecutive calls to QPDFObjectHandle::parseInternal, aka an "infinite loop."
ModificadaMedia (5.5)1.5%—Qpdf Project QpdfCanonical Ubuntu Linux23/5/201717/6/2026
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, aka qpdf-infiniteloop3.
ModificadaMedia (5.5)1.5%—Qpdf Project QpdfCanonical Ubuntu Linux23/5/201717/6/2026
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpdf-infiniteloop2.
ModificadaMedia (5.5)1.4%—Qpdf Project QpdfCanonical Ubuntu Linux23/5/201717/6/2026
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to releaseResolved functions, aka qpdf-infiniteloop1.
ModificadaAlta (7.5)1.5%—Tcpdf Project Tcpdf23/2/201717/6/2026
tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP.
ModificadaAlta (7.8)1.1%—Gonitro Nitro PDF PRO10/2/201717/6/2026
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10.5.9.9. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to trigger this vulnerability.
ModificadaAlta (7.8)2.0%—Gonitro Nitro PDF PRO10/2/201717/6/2026
A potential remote code execution vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential code execution. An attacker can send the victim a specific PDF file to trigger this vulnerability.
ModificadaAlta (7.8)1.3%—Gonitro Nitro PDF PRO10/2/201717/6/2026
A remote out of bound write / memory corruption vulnerability exists in the PDF parsing functionality of Nitro Pro 10. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to trigger this vulnerability.
ModificadaMedia (5)1.4%—Pass2pdf Project Pass2pdf18/8/201517/6/2026
The pass2pdf module for Drupal does not restrict access to generated PDF files, which allows remote attackers to obtain user passwords via unspecified vectors.
ModificadaMedia (6.8)8.6%—Apple CupsFreedesktop PopplerGpdf Project GpdfXpdfreader Xpdf+230/7/200716/6/2026
Integer overflow in the StreamPredictor::StreamPredictor function in xpdf 3.02, as used in (1) poppler before 0.5.91, (2) gpdf before 2.8.2, (3) kpdf, (4) kdegraphics, (5) CUPS, (6) PDFedit, and other products, might allow remote attackers to execute arbitrary code via a crafted PDF file that triggers a stack-based…
Orbitaley — Vulnerabilidades