Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.5% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns decompression in… | |
| Modificada | Alta (7.8) | 1.5% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns legacy decompression in `vcd_main`. | |
| Modificada | Alta (7.8) | 1.5% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns `.ghw` decompression. | |
| Modificada | Alta (7.8) | 0.43% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the copy… | |
| Modificada | Alta (7.8) | 0.42% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the… | |
| Modificada | Alta (7.8) | 0.43% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the… | |
| Modificada | Alta (7.8) | 0.43% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple heap-based buffer overflow vulnerabilities exist in the fstReaderIterBlocks2 VCDATA parsing functionality of GTKWave 3.3.115. A specially-crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the… | |
| Modificada | Alta (7.8) | 0.43% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the… | |
| Modificada | Alta (7.8) | 0.43% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the fstReaderVarint64… | |
| Modificada | Alta (7.8) | 0.43% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | Multiple stack-based buffer overflow vulnerabilities exist in the FST LEB128 varint functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability concerns the fstReaderVarint32… | |
| Modificada | Alta (7.8) | 0.38% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | An integer overflow vulnerability exists in the fstReaderIterBlocks2 time_table tsec_nitems functionality of GTKWave 3.3.115. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.39% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | An integer overflow vulnerability exists in the LXT2 lxt2_rd_trace value elements allocation functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.43% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | An integer overflow vulnerability exists in the VZT longest_len value allocation functionality of GTKWave 3.3.115. A specially crafted .vzt file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.43% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | An out-of-bounds write vulnerability exists in the LXT2 num_time_table_entries functionality of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.40% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | An improper array index validation vulnerability exists in the EVCD var len parsing functionality of GTKWave 3.3.115. A specially crafted .evcd file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.38% | — | Tonybybell Gtkwave | 8/1/2024 | 17/6/2026 | An integer overflow vulnerability exists in the FST_BL_GEOM parsing maxhandle functionality of GTKWave 3.3.115, when compiled as a 32-bit binary. A specially crafted .fst file can lead to memory corruption. A victim would need to open a malicious file to trigger this vulnerability. | |
| Modificada | Media (6.5) | 0.35% | — | Silabs Z-wave Software Development KIT | 15/12/2023 | 17/6/2026 | A denial of service vulnerability exists in all Silicon Labs Z-Wave controller and endpoint devices running Z-Wave SDK v7.20.3 (Gecko SDK v4.3.3) and earlier. This attack can be carried out only by devices on the network sending a stream of packets to the device. | |
| Modificada | Crítica (9.8) | 1.3% | — | Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+4 | 15/12/2023 | 17/6/2026 | When handling contactless cards, usage of a specific function to get additional information from the card which doesn't check the boundary on the data received while reading. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device | |
| Modificada | Crítica (9.8) | 1.0% | — | Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+4 | 15/12/2023 | 17/6/2026 | When reading DesFire keys, the function that reads the card isn't properly checking the boundaries when copying internally the data received. This allows a heap based buffer overflow that could lead to a potential Remote Code Execution on the targeted device. This is especially problematic if you use Default DESFire… | |
| Modificada | Crítica (9.8) | 1.1% | — | Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+4 | 15/12/2023 | 17/6/2026 | During the retrofit validation process, the firmware doesn't properly check the boundaries while copying some attributes to check. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device | |
| Modificada | Crítica (9.8) | 1.1% | — | Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+4 | 15/12/2023 | 17/6/2026 | The handler of the retrofit validation command doesn't properly check the boundaries when performing certain validation operations. This allows a stack-based buffer overflow that could lead to a potential Remote Code Execution on the targeted device | |
| Modificada | Crítica (9.8) | 1.1% | — | Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+4 | 15/12/2023 | 17/6/2026 | The Parameter Zone Read and Parameter Zone Write command handlers allow performing a Stack buffer overflow. This could potentially lead to a Remote Code execution on the targeted device. | |
| Modificada | Alta (7.5) | 0.68% | — | Idemia Sigma Lite FirmwareIdemia Sigma Lite+ FirmwareIdemia Sigma Extreme FirmwareIdemia Sigma Wide Firmware+4 | 15/12/2023 | 17/6/2026 | By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's possible to cause a permanent denial of service for the terminal. the only way to recover the terminal is by sending back the terminal to the manufacturer | |
| Modificada | Media (6.1) | 0.61% | — | Carrierwave Project Carrierwave | 29/11/2023 | 17/6/2026 | CarrierWave is a solution for file uploads for Rails, Sinatra and other Ruby web frameworks. CarrierWave has a Content-Type allowlist bypass vulnerability, possibly leading to XSS. The validation in `allowlisted_content_type?` determines Content-Type permissions by performing a partial match. If the `content_type`… | |
| Modificada | Media (4.8) | 0.42% | — | Idemia Sgima Lite & Lite+ FirmwareIdemia Sigma Wide FirmwareIdemia Sigma Extreme FirmwareIdemia Morphowave Compact Firmware+2 | 28/11/2023 | 17/6/2026 | The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fields. The stored malicious script is then executed when the GUI is opened by any users of the webserver administration interface. The root cause of the vulnerability is inadequate input validation and… |