Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 4.7% | — | Haxx Libcurl | 31/7/2018 | 17/6/2026 | The URL percent-encoding decode function in libcurl before 7.51.0 is called `curl_easy_unescape`. Internally, even if this function would be made to allocate a unscape destination buffer larger than 2GB, it would return that new length in a signed 32 bit integer variable, thus the length would get either just… | |
| Modificada | Alta (8.8) | 1.8% | — | Libconfuse Project LibconfuseDebian Linux | 20/7/2018 | 17/6/2026 | trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read. | |
| Modificada | Alta (7.5) | 1.7% | — | Haxx Libcurl | 16/7/2018 | 17/6/2026 | In curl and libcurl 7.52.0 to and including 7.53.1, libcurl would attempt to resume a TLS session even if the client certificate had changed. That is unacceptable since a server by specification is allowed to skip the client certificate check on resume, and may instead use the old identity which was established by the… | |
| Modificada | Alta (7.8) | 0.88% | — | GNU GlibcRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+6 | 18/5/2018 | 17/6/2026 | An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper. | |
| Modificada | Crítica (9.8) | 7.1% | — | GNU GlibcRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+5 | 18/5/2018 | 17/6/2026 | stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution. | |
| Modificada | Crítica (9.8) | 4.6% | — | GNU Glibc | 18/5/2018 | 17/6/2026 | An SSE2-optimized memmove implementation for i386 in sysdeps/i386/i686/multiarch/memcpy-sse2-unaligned.S in the GNU C Library (aka glibc or libc6) 2.21 through 2.27 does not correctly perform the overlapping memory check if the source memory range spans the middle of the address space, resulting in corrupt data being… | |
| Modificada | Crítica (9.8) | 3.3% | — | GNU Libcdio | 26/2/2018 | 17/6/2026 | An issue was discovered in GNU libcdio before 2.0.0. There is a double free in get_cdtext_generic() in lib/driver/_cdio_generic.c. | |
| Modificada | Media (6.5) | 3.3% | — | GNU Libcdio | 24/2/2018 | 17/6/2026 | realloc_symlink in rock.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (NULL Pointer Dereference) via a crafted iso file. | |
| Modificada | Alta (8.8) | 3.4% | — | GNU Libcdio | 24/2/2018 | 17/6/2026 | print_iso9660_recurse in iso-info.c in GNU libcdio before 1.0.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted iso file. | |
| Modificada | Crítica (9.8) | 2.2% | — | GNU Glibc | 2/2/2018 | 17/6/2026 | The malloc implementation in the GNU C Library (aka glibc or libc6), from version 2.24 to 2.26 on powerpc, and only in version 2.26 on i386, did not properly handle malloc calls with arguments close to SIZE_MAX and could return a pointer to a heap region that is smaller than requested, eventually leading to heap… | |
| Modificada | Crítica (9.8) | 4.7% | — | GNU GlibcRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+11 | 1/2/2018 | 17/6/2026 | An integer overflow in the implementation of the posix_memalign in memalign functions in the GNU C Library (aka glibc or libc6) 2.26 and earlier could cause these functions to return a pointer to a heap area that is too small, potentially leading to heap corruption. | |
| Modificada | Alta (7) | 1.2% | 💥 Exploit | GNU Glibc | 1/2/2018 | 17/6/2026 | A buffer overflow in glibc 2.5 (released on September 29, 2006) and can be triggered through the LD_LIBRARY_PATH environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366. | |
| Modificada | Alta (7.8) | 1.5% | 💥 Exploit | GNU Glibc | 1/2/2018 | 17/6/2026 | A memory leak in glibc 2.1.1 (released on May 24, 1999) can be reached and amplified through the LD_HWCAP_MASK environment variable. Please note that many versions of glibc are not vulnerable to this issue if patched for CVE-2017-1000366. | |
| Modificada | Alta (7.8) | 13% | 💥 Exploit | GNU GlibcCanonical Ubuntu LinuxRedhat Virtualization HostRedhat Enterprise Linux Desktop+5 | 31/1/2018 | 17/6/2026 | In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution. | |
| Modificada | Crítica (9.1) | 4.6% | — | Haxx LibcurlDebian LinuxCanonical Ubuntu Linux | 24/1/2018 | 17/6/2026 | libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers since the stored size was one byte less than required. The problem is that the code that creates… | |
| Modificada | Alta (7.8) | 2.9% | 💥 PoC | GNU GlibcRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 18/12/2017 | 17/6/2026 | elf/dl-load.c in the GNU C Library (aka glibc or libc6) 2.19 through 2.26 mishandles RPATH and RUNPATH containing $ORIGIN for a privileged (setuid or AT_SECURE) program, which allows local users to gain privileges via a Trojan horse library in the current working directory, related to the fillin_rpath and… | |
| Modificada | Alta (8.1) | 1.6% | — | GNU Glibc | 5/12/2017 | 17/6/2026 | The malloc function in the GNU C Library (aka glibc or libc6) 2.26 could return a memory block that is too small if an attempt is made to allocate an object whose size is close to SIZE_MAX, potentially leading to a subsequent heap overflow. This occurs because the per-thread cache (aka tcache) feature enables a code… | |
| Modificada | Crítica (9.8) | 3.8% | — | Haxx CurlHaxx Libcurl | 29/11/2017 | 17/6/2026 | curl and libcurl before 7.57.0 on 32-bit platforms allow attackers to cause a denial of service (out-of-bounds access and application crash) or possibly have unspecified other impact because too little memory is allocated for interfacing to an SSL library. | |
| Modificada | Crítica (9.8) | 11% | — | Haxx CurlHaxx LibcurlDebian Linux | 29/11/2017 | 17/6/2026 | The FTP wildcard function in curl and libcurl before 7.57.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) or possibly have unspecified other impact via a string that ends with an '[' character. | |
| Modificada | Crítica (9.8) | 8.5% | — | Haxx CurlHaxx LibcurlDebian Linux | 29/11/2017 | 17/6/2026 | The NTLM authentication feature in curl and libcurl before 7.57.0 on 32-bit platforms allows attackers to cause a denial of service (integer overflow and resultant buffer overflow, and application crash) or possibly have unspecified other impact via vectors involving long user and password fields. | |
| Modificada | Crítica (9.1) | 6.2% | — | Haxx LibcurlDebian Linux | 31/10/2017 | 17/6/2026 | An IMAP FETCH response line indicates the size of the returned data, in number of bytes. When that response says the data is zero bytes, libcurl would pass on that (non-existing) data with a pointer and the size (zero) to the deliver-data function. libcurl's deliver-data function treats zero as a magic number and… | |
| Modificada | Crítica (9.8) | 2.8% | — | GNU Glibc | 22/10/2017 | 17/6/2026 | The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27 contains a buffer overflow during unescaping of user names with the ~ operator. | |
| Modificada | Media (5.9) | 1.4% | — | GNU Glibc | 20/10/2017 | 17/6/2026 | The glob function in glob.c in the GNU C Library (aka glibc or libc6) before 2.27, when invoked with GLOB_TILDE, could skip freeing allocated memory when processing the ~ operator with a long user name, potentially leading to a denial of service (memory leak). | |
| Modificada | Crítica (9.8) | 3.0% | — | GNU Glibc | 20/10/2017 | 17/6/2026 | The GNU C Library (aka glibc or libc6) before 2.27 contains an off-by-one error leading to a heap-based buffer overflow in the glob function in glob.c, related to the processing of home directories using the ~ operator followed by a long string. | |
| Modificada | Alta (7.5) | 2.0% | — | Musl-libc Musl | 19/10/2017 | 17/6/2026 | musl libc before 1.1.17 has a buffer overflow via crafted DNS replies because dns_parse_callback in network/lookup_name.c does not restrict the number of addresses, and thus an attacker can provide an unexpected number by sending A records in a reply to an AAAA query. |