Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

208 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.2%—GNU LibextractorDebian Linux24/12/201817/6/2026
GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c.
ModificadaMedia (5.4)0.79%—Pixar Tractor13/12/201817/6/2026
Pixar's Tractor software, versions 2.2 and earlier, contain a stored cross-site scripting vulnerability in the field that allows a user to add a note to an existing node. The stored information is displayed when a user requests information about the node. An attacker could insert Javascript into this note field that…
ModificadaMedia (6.5)3.1%—Cabextract Project CabextractLibmspack Project LibmspackDebian LinuxRedhat Enterprise Linux+323/10/201817/6/2026
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
ModificadaAlta (8.8)2.6%—GNU LibextractorDebian Linux4/9/201817/6/2026
GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c.
ModificadaAlta (7.5)1.6%—Suncontract3/8/201817/6/2026
The mintTokens function of a smart contract implementation for SunContract, an Ethereum token, has an integer overflow via the _amount variable.
ModificadaAlta (8.8)3.8%—Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+428/7/201817/6/2026
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression.
ModificadaAlta (8.8)3.8%—Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+428/7/201817/6/2026
An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite.
ModificadaMedia (6.5)3.7%—Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+428/7/201817/6/2026
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames.
ModificadaMedia (6.5)3.3%—Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+428/7/201817/6/2026
An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash).
ModificadaMedia (6.5)1.7%—Debian LinuxGNU Libextractor17/7/201817/6/2026
GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).
ModificadaAlta (8.8)2.1%—Debian LinuxGNU Libextractor17/7/201817/6/2026
GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).
ModificadaCrítica (9.8)1.2%—Tracto15/7/201817/6/2026
The increaseApproval function of a smart contract implementation for Tracto (TRCT), an Ethereum ERC20 token, has an integer overflow.
ModificadaAlta (7.5)1.4%—Exacorecontract Project Exacorecontract9/7/201817/6/2026
The mintToken function of a smart contract implementation for ExacoreContract, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.1%—Icocontract Project Icocontract9/7/201817/6/2026
The mintToken function of a smart contract implementation for IcoContract, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (8.8)0.50%—Beims Contractorweb.net15/1/201817/6/2026
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. A successful CSRF attack can force the user to modify state: creating users, changing an email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire…
ModificadaCrítica (9.8)1.3%—Beims Contractorweb.net15/1/201817/6/2026
ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticating the user; an attacker can misuse these functionalities to perform unauthorized actions, as demonstrated by Edit User Details.
ModificadaCrítica (9.8)3.6%💥 ExploitZuuse Beims Contractorweb .net18/12/201717/6/2026
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter.
ModificadaMedia (6.5)2.4%—GNU Libextractor6/12/201717/6/2026
GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c.
ModificadaCrítica (9.8)2.1%💥 ExploitContractorscripts Mybuildersite29/10/201717/6/2026
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.
ModificadaMedia (5.5)1.3%—GNU Libextractor26/10/201717/6/2026
In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c.
ModificadaAlta (7.5)1.5%—GNU Libextractor18/10/201717/6/2026
In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size.
ModificadaAlta (7.5)1.6%—GNU Libextractor18/10/201717/6/2026
In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/png_extractor.c, related to processiTXt and stndup.
ModificadaAlta (7.5)2.1%—GNU Libextractor18/10/201717/6/2026
In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf_extractor.c.
ModificadaAlta (7.5)2.6%—GNU Libextractor11/10/201717/6/2026
In GNU Libextractor 1.4, there is a NULL Pointer Dereference in flac_metadata in flac_extractor.c.
ModificadaMedia (5.5)1.4%—GNU Libextractor11/10/201717/6/2026
In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor.c via a zero sample rate.
Orbitaley — Vulnerabilidades