Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
5546 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.9% | — | FreerdpFedoraproject Fedora | 22/4/2024 | 17/6/2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI` drawing path with a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use modern drawing paths (e.g.… | |
| Modificada | Crítica (9.8) | 3.7% | 💥 PoC | FreerdpFedoraproject Fedora | 22/4/2024 | 17/6/2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available. | |
| Modificada | Crítica (9.8) | 1.9% | — | FreerdpFedoraproject Fedora | 22/4/2024 | 17/6/2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by default, require server side support). | |
| Analizada | Crítica (9.8) | 1.9% | — | FreerdpFedoraproject Fedora | 22/4/2024 | 17/6/2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, deactivate `/gfx` (on by default, set `/bpp` or `/rfx` options instead. | |
| Modificada | Crítica (9.8) | 1.9% | — | FreerdpFedoraproject Fedora | 22/4/2024 | 17/6/2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the `NSC` codec are vulnerable to integer underflow. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use the NSC codec… | |
| Modificada | Crítica (9.8) | 2.3% | — | FreerdpFedoraproject Fedora | 22/4/2024 | 17/6/2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to integer overflow and out-of-bounds write. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use `/gfx` options (e.g. deactivate with `/bpp:32` or… | |
| Analizada | Alta (7.8) | 0.32% | — | FfmpegFedoraproject Fedora | 19/4/2024 | 17/6/2026 | Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate. | |
| Analizada | Media (6.7) | 0.42% | — | FfmpegFedoraproject Fedora | 19/4/2024 | 17/6/2026 | Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame | |
| Analizada | Baja (3.6) | 0.25% | — | FfmpegFedoraproject Fedora | 19/4/2024 | 17/6/2026 | Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reverse.c:269:26 in areverse_request_frame. | |
| Analizada | Alta (8) | 0.27% | — | FfmpegFedoraproject Fedora | 19/4/2024 | 17/6/2026 | Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame | |
| Analizada | Alta (7.8) | 0.27% | — | FfmpegFedoraproject Fedora | 19/4/2024 | 17/6/2026 | Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map. | |
| Modificada | Alta (7.8) | 0.48% | — | FfmpegFedoraproject Fedora | 19/4/2024 | 17/6/2026 | FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id function in /fftools/ffmpeg_enc.c component. | |
| Modificada | Alta (8) | 0.44% | — | FfmpegFedoraproject Fedora | 19/4/2024 | 17/6/2026 | FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component. | |
| Modificada | Alta (7.8) | 0.37% | — | FfmpegFedoraproject Fedora | 19/4/2024 | 17/6/2026 | FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component. | |
| Modificada | Media (4) | 0.35% | — | FfmpegFedoraproject Fedora | 19/4/2024 | 17/6/2026 | FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component. | |
| Modificada | Alta (8.8) | 1.5% | — | FfmpegFedoraproject Fedora | 19/4/2024 | 17/6/2026 | Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component. | |
| Modificada | Alta (8) | 0.39% | — | FfmpegFedoraproject Fedora | 19/4/2024 | 17/6/2026 | Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component. | |
| Modificada | Alta (7.5) | 1.3% | 💥 PoC | Tcpdf Project TcpdfFedoraproject Fedora | 19/4/2024 | 17/6/2026 | TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color. | |
| Modificada | Alta (7.1) | 1.0% | — | Fedoraproject SssdRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64+19 | 18/4/2024 | 17/6/2026 | A race condition flaw was found in sssd where the GPO policy is not consistently applied for authenticated users. This may lead to improper authorization issues, granting or denying access to resources inappropriately. | |
| Analizada | Alta (8.4) | 0.51% | 💥 PoC | FlatpakFedoraproject Fedora | 18/4/2024 | 17/6/2026 | Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. Normally, the `--command` argument of `flatpak run` expects to be given a… | |
| Modificada | Media (6.1) | 0.67% | — | AiohttpFedoraproject Fedora | 18/4/2024 | 17/6/2026 | aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. A XSS vulnerability exists on index pages for static file handling. This vulnerability is fixed in 3.9.4. We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are… | |
| Modificada | Alta (8.1) | 0.94% | — | Ofono Project OfonoFedoraproject Fedora | 17/4/2024 | 17/6/2026 | A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this… | |
| Modificada | Alta (8.1) | 1.1% | — | Ofono Project OfonoFedoraproject Fedora | 17/4/2024 | 17/6/2026 | A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_submit_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this… | |
| Modificada | Alta (8.1) | 1.0% | — | Ofono Project OfonoFedoraproject Fedora | 17/4/2024 | 17/6/2026 | A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the sms_decode_address_field() function during the SMS PDU decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. | |
| Modificada | Alta (8.1) | 0.95% | — | Ofono Project OfonoFedoraproject Fedora | 17/4/2024 | 17/6/2026 | A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this… |