Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

286 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%—Compression AND Archive Extensions TZ Project23/6/202017/6/2026
In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
ModificadaAlta (7.5)1.4%—Compression AND Archive Extensions Project Compression AND Archive Extensions ZIP Project23/6/202017/6/2026
In all versions of the package github.com/unknwon/cae/zip, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
ModificadaAlta (8.8)2.3%—LibarchiveCanonical Ubuntu LinuxFedoraproject Fedora20/2/202017/6/2026
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
ModificadaMedia (4.4)0.30%—IBM Spectrum Protect Backup-archive Client25/11/201917/6/2026
IBM Spectrum Protect Backup-Archive Client 7.1 and 8.1 may be vulnerable to a denial of service attack due to a timing issue between client and server TCP/IP communications. IBM X-Force ID: 162477.
ModificadaMedia (5.5)0.66%—LibarchiveDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux21/11/201917/6/2026
In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive.
ModificadaAlta (8.1)0.92%—Archivemail Project ArchivemailDebian Linux6/11/201916/6/2026
archivemail 0.6.2 uses temporary files insecurely leading to a possible race condition.
ModificadaMedia (5.5)6.4%💥 PoCArchiver Project Archiver29/10/201917/6/2026
All versions of archiver allow attacker to perform a Zip Slip attack via the "unarchive" functions. It is exploited using a specially crafted zip archive, that holds path traversal filenames. When exploited, a filename in a malicious archive is concatenated to the target extraction directory, which results in the…
ModificadaAlta (7.5)4.0%—LibarchiveDebian LinuxCanonical Ubuntu Linux24/10/201917/6/2026
archive_read_format_rar_read_data in archive_read_support_format_rar.c in libarchive before 3.4.0 has a use-after-free in a certain ARCHIVE_FAILED situation, related to Ppmd7_DecodeSymbol.
ModificadaCrítica (9.8)2.3%—Archivesunleashed Graphpass15/7/201917/6/2026
borg-reducer c6d5240 is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Output parameter within the executable.
ModificadaMedia (6.1)2.3%💥 ExploitHeidelberg Prinect Archiver24/5/201917/6/2026
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Heidelberg Prinect Archiver v2013 release 1.0.
ModificadaMedia (5.5)1.3%—Libarchive23/4/201917/6/2026
A memory leak in archive_read_format_zip_cleanup in archive_read_support_format_zip.c in libarchive 3.3.4-dev allows remote attackers to cause a denial of service via a crafted ZIP file because of a HAVE_LZMA_H typo. NOTE: this only affects users who downloaded the development code from GitHub. Users of the product's…
ModificadaMedia (4.7)0.22%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments8/4/201917/6/2026
In a certain atypical IBM Spectrum Protect 7.1 and 8.1 configurations, the node password could be displayed in plain text in the IBM Spectrum Protect client trace file. IBM X-Force ID: 151968.
ModificadaMedia (6.1)1.2%—IBM Spectrum Protect Backup-archive Client8/4/201917/6/2026
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks…
ModificadaMedia (5.5)0.30%—IBM Spectrum Protect Backup-archive ClientIBM Spectrum Protect FOR Virtual Environments8/4/201917/6/2026
IBM Spectrum Protect 7.1 and 8.1 is affected by a password exposure vulnerability caused by insecure file permissions. IBM X-Force ID: 148872.
ModificadaMedia (6.5)3.2%—LibarchiveCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+44/2/201917/6/2026
libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso9660.c, read_CE()/parse_rockridge() that can result in DoS by infinite loop.…
ModificadaMedia (6.5)3.4%—LibarchiveDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+44/2/201917/6/2026
libarchive version commit bf9aec176c6748f0ee7a678c5f9f9555b9a757c1 onwards (release v3.0.2 onwards) contains a CWE-125: Out-of-bounds Read vulnerability in 7zip decompression, archive_read_support_format_7zip.c, header_bytes() that can result in a crash (denial of service). This attack appears to be exploitable via…
ModificadaAlta (8.8)19%💥 ExploitPHP Pear Archive TARCanonical Ubuntu LinuxDebian Linux28/12/201817/6/2026
PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific prefix path, we can trigger unserialization…
ModificadaMedia (6.1)0.69%—Barracuda Message Archiver23/12/201817/6/2026
Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module.
ModificadaMedia (6.5)4.1%—LibarchiveCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap20/12/201817/6/2026
libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc.c, _warc_read() that can result in DoS - quasi-infinite run time and disk usage from tiny file.…
ModificadaMedia (6.5)3.4%—LibarchiveFedoraproject FedoraOpensuse Leap20/12/201817/6/2026
libarchive version commit 379867ecb330b3a952fb7bfa7bffb7bbd5547205 onwards (release v3.3.0 onwards) contains a CWE-476: NULL Pointer Dereference vulnerability in ACL parser - libarchive/archive_acl.c, archive_acl_from_text_l() that can result in Crash/DoS. This attack appear to be exploitable via the victim must open…
ModificadaAlta (8.8)4.4%—LibarchiveDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+420/12/201817/6/2026
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via…
ModificadaAlta (8.8)4.6%—LibarchiveDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+320/12/201817/6/2026
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS. This attack…
ModificadaAlta (8.8)23%—Microsoft.powershell.archiveMicrosoft Powershell CoreMicrosoft Windows 10Microsoft Windows 7+614/11/201817/6/2026
A remote code execution vulnerability exists when PowerShell improperly handles specially crafted files, aka "Microsoft PowerShell Remote Code Execution Vulnerability." This affects Windows RT 8.1, PowerShell Core 6.0, Microsoft.PowerShell.Archive 1.2.2.0, Windows Server 2016, Windows Server 2012, Windows Server 2008…
ModificadaCrítica (9.8)1.7%—Slack Archivebot Project Slack Archivebot20/9/201817/6/2026
SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text parameter to cursor.execute().
ModificadaMedia (5.5)2.5%—Archiver Project Archiver25/7/201817/6/2026
mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
Orbitaley — Vulnerabilidades