Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.2% | — | GNU Glibc | 15/7/2019 | 17/6/2026 | GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a… | |
| Modificada | Alta (7.8) | 50% | — | Haxx LibcurlOpensuse LeapFedoraproject FedoraDebian Linux+7 | 28/5/2019 | 17/6/2026 | A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. | |
| Modificada | Media (5.5) | 0.30% | — | GNU Glibc | 10/4/2019 | 16/6/2026 | The nscd daemon in the GNU C Library (glibc) before version 2.5 does not close incoming client sockets if they cannot be handled by the daemon, allowing local users to carry out a denial of service attack on the daemon. | |
| Modificada | Crítica (9.8) | 2.1% | — | GNU Glibc | 10/4/2019 | 16/6/2026 | The getgrouplist function in the GNU C library (glibc) before version 2.3.5, when invoked with a zero argument, writes to the passed pointer even if the specified array size is zero, leading to a buffer overflow and potentially allowing attackers to corrupt memory. | |
| Modificada | Alta (8.8) | 1.7% | — | RPM Libcomps | 27/3/2019 | 17/6/2026 | A use-after-free flaw has been discovered in libcomps before version 0.1.10 in the way ObjMRTrees are merged. An attacker, who is able to make an application read a crafted comps XML file, may be able to crash the application or execute malicious code. | |
| Modificada | Alta (7.5) | 2.4% | — | GNU Glibc | 26/2/2019 | 17/6/2026 | In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\\1\\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with… | |
| Modificada | Crítica (9.8) | 4.7% | — | GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage+2 | 26/2/2019 | 17/6/2026 | In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match. | |
| Modificada | Alta (7.5) | 5.8% | — | GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage | 26/2/2019 | 17/6/2026 | In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep. | |
| Modificada | Alta (7.5) | 3.9% | — | GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage | 26/2/2019 | 16/6/2026 | In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match. | |
| Modificada | Alta (7.5) | 4.3% | — | Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Clustered Data Ontap+3 | 6/2/2019 | 17/6/2026 | libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond… | |
| Modificada | Crítica (9.8) | 13% | — | Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+12 | 6/2/2019 | 17/6/2026 | libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent… | |
| Modificada | Alta (7.5) | 5.4% | 💥 PoC | Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Clustered Data Ontap+6 | 6/2/2019 | 17/6/2026 | libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a… | |
| Modificada | Media (5.5) | 0.61% | — | GNU Glibc | 3/2/2019 | 17/6/2026 | In the GNU C Library (aka glibc or libc6) through 2.29, the memcmp function for the x32 architecture can incorrectly return zero (indicating that the inputs are equal) because the RDX most significant bit is mishandled. | |
| Modificada | Media (5.3) | 0.48% | — | GNU GlibcOpensuse Leap | 21/1/2019 | 17/6/2026 | In the GNU C Library (aka glibc or libc6) through 2.28, the getaddrinfo function would successfully parse a string that contained an IPv4 address followed by whitespace and arbitrary characters, which could lead applications to incorrectly assume that it had parsed a valid string, without the possibility of embedded… | |
| Modificada | Alta (7.8) | 0.44% | — | GNU Glibc | 18/1/2019 | 17/6/2026 | The string component in the GNU C Library (aka glibc or libc6) through 2.28, when running on the x32 architecture, incorrectly attempts to use a 64-bit register for size_t in assembly codes, which can lead to a segmentation fault or possibly unspecified other impact, as demonstrated by a crash in… | |
| Modificada | Alta (8.8) | 1.8% | — | Libcaca Project LibcacaCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 28/12/2018 | 17/6/2026 | There is an illegal WRITE memory access at caca/file.c (function caca_file_read) in libcaca 0.99.beta19. | |
| Modificada | Alta (8.8) | 1.8% | — | Libcaca Project LibcacaCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap | 28/12/2018 | 17/6/2026 | There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 1bpp data. | |
| Modificada | Alta (8.1) | 1.8% | — | Libcaca Project LibcacaCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 28/12/2018 | 17/6/2026 | There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for 24bpp data. | |
| Modificada | Alta (8.1) | 2.3% | — | Libcaca Project LibcacaCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux+1 | 28/12/2018 | 17/6/2026 | There is an illegal READ memory access at caca/dither.c (function get_rgba_default) in libcaca 0.99.beta19 for the default bpp case. | |
| Modificada | Alta (8.8) | 2.4% | — | Libcaca Project LibcacaCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap | 28/12/2018 | 17/6/2026 | There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data. | |
| Modificada | Media (6.5) | 1.9% | — | Libcaca Project LibcacaCanonical Ubuntu LinuxDebian Linux | 28/12/2018 | 17/6/2026 | There is floating point exception at caca/dither.c (function caca_dither_bitmap) in libcaca 0.99.beta19. | |
| Modificada | Alta (7.5) | 5.5% | — | GNU GlibcFedoraproject Fedora | 4/12/2018 | 17/6/2026 | In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function. | |
| Modificada | Alta (8.8) | 1.1% | — | Libconfuse Project Libconfuse | 30/11/2018 | 17/6/2026 | cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak. | |
| Modificada | Crítica (9.8) | 11% | — | Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux | 5/9/2018 | 17/6/2026 | curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to… | |
| Modificada | Alta (8.1) | 2.3% | — | Libcgroup Project LibcgroupDebian LinuxFedoraproject Fedora | 14/8/2018 | 17/6/2026 | libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information. |