Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
208 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.2% | — | GNU LibextractorDebian Linux | 24/12/2018 | 17/6/2026 | GNU Libextractor through 1.8 has an out-of-bounds read vulnerability in the function history_extract() in plugins/ole2_extractor.c, related to EXTRACTOR_common_convert_to_utf8 in common/convert.c. | |
| Modificada | Media (5.4) | 0.79% | — | Pixar Tractor | 13/12/2018 | 17/6/2026 | Pixar's Tractor software, versions 2.2 and earlier, contain a stored cross-site scripting vulnerability in the field that allows a user to add a note to an existing node. The stored information is displayed when a user requests information about the node. An attacker could insert Javascript into this note field that… | |
| Modificada | Media (6.5) | 3.1% | — | Cabextract Project CabextractLibmspack Project LibmspackDebian LinuxRedhat Enterprise Linux+3 | 23/10/2018 | 17/6/2026 | In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write. | |
| Modificada | Alta (8.8) | 2.6% | — | GNU LibextractorDebian Linux | 4/9/2018 | 17/6/2026 | GNU Libextractor through 1.7 has an out-of-bounds read vulnerability in EXTRACTOR_zip_extract_method() in zip_extractor.c. | |
| Modificada | Alta (7.5) | 1.6% | — | Suncontract | 3/8/2018 | 17/6/2026 | The mintTokens function of a smart contract implementation for SunContract, an Ethereum token, has an integer overflow via the _amount variable. | |
| Modificada | Alta (8.8) | 3.8% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the TOLOWER() macro for CHM decompression. | |
| Modificada | Alta (8.8) | 3.8% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite. | |
| Modificada | Media (6.5) | 3.7% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames. | |
| Modificada | Media (6.5) | 3.3% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash). | |
| Modificada | Media (6.5) | 1.7% | — | Debian LinuxGNU Libextractor | 17/7/2018 | 17/6/2026 | GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c). | |
| Modificada | Alta (8.8) | 2.1% | — | Debian LinuxGNU Libextractor | 17/7/2018 | 17/6/2026 | GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c). | |
| Modificada | Crítica (9.8) | 1.2% | — | Tracto | 15/7/2018 | 17/6/2026 | The increaseApproval function of a smart contract implementation for Tracto (TRCT), an Ethereum ERC20 token, has an integer overflow. | |
| Modificada | Alta (7.5) | 1.4% | — | Exacorecontract Project Exacorecontract | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for ExacoreContract, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 1.1% | — | Icocontract Project Icocontract | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for IcoContract, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (8.8) | 0.50% | — | Beims Contractorweb.net | 15/1/2018 | 17/6/2026 | ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) on /CWEBNET/* authenticated pages. A successful CSRF attack can force the user to modify state: creating users, changing an email address, and so forth. If the victim is an administrative account, CSRF can compromise the entire… | |
| Modificada | Crítica (9.8) | 1.3% | — | Beims Contractorweb.net | 15/1/2018 | 17/6/2026 | ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows access to various /UserManagement/ privileged modules without authenticating the user; an attacker can misuse these functionalities to perform unauthorized actions, as demonstrated by Edit User Details. | |
| Modificada | Crítica (9.8) | 3.6% | 💥 Exploit | Zuuse Beims Contractorweb .net | 18/12/2017 | 17/6/2026 | CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, assignto, building, domain, jobtype, site, trade, woType, workorderno, or workorderstatus parameter. | |
| Modificada | Media (6.5) | 2.4% | — | GNU Libextractor | 6/12/2017 | 17/6/2026 | GNU Libextractor 1.6 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted GIF, IT (Impulse Tracker), NSFE, S3M (Scream Tracker 3), SID, or XM (eXtended Module) file, as demonstrated by the EXTRACTOR_xm_extract_method function in plugins/xm_extractor.c. | |
| Modificada | Crítica (9.8) | 2.1% | 💥 Exploit | Contractorscripts Mybuildersite | 29/10/2017 | 17/6/2026 | MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter. | |
| Modificada | Media (5.5) | 1.3% | — | GNU Libextractor | 26/10/2017 | 17/6/2026 | In GNU Libextractor 1.4, there is an out-of-bounds read in the EXTRACTOR_dvi_extract_method function in plugins/dvi_extractor.c. | |
| Modificada | Alta (7.5) | 1.5% | — | GNU Libextractor | 18/10/2017 | 17/6/2026 | In GNU Libextractor 1.4, there is an integer signedness error for the chunk size in the EXTRACTOR_nsfe_extract_method function in plugins/nsfe_extractor.c, leading to an infinite loop for a crafted size. | |
| Modificada | Alta (7.5) | 1.6% | — | GNU Libextractor | 18/10/2017 | 17/6/2026 | In GNU Libextractor 1.4, there is a heap-based buffer overflow in the EXTRACTOR_png_extract_method function in plugins/png_extractor.c, related to processiTXt and stndup. | |
| Modificada | Alta (7.5) | 2.1% | — | GNU Libextractor | 18/10/2017 | 17/6/2026 | In GNU Libextractor 1.4, there is a NULL Pointer Dereference in the EXTRACTOR_nsf_extract_method function of plugins/nsf_extractor.c. | |
| Modificada | Alta (7.5) | 2.6% | — | GNU Libextractor | 11/10/2017 | 17/6/2026 | In GNU Libextractor 1.4, there is a NULL Pointer Dereference in flac_metadata in flac_extractor.c. | |
| Modificada | Media (5.5) | 1.4% | — | GNU Libextractor | 11/10/2017 | 17/6/2026 | In GNU Libextractor 1.4, there is a Divide-By-Zero in EXTRACTOR_wav_extract_method in wav_extractor.c via a zero sample rate. |