Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
286 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 4.1% | — | LibarchiveRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+6 | 21/9/2016 | 17/6/2026 | Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file. | |
| Modificada | Alta (7.5) | 4.7% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+6 | 21/9/2016 | 17/6/2026 | The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file. | |
| Modificada | Alta (7.5) | 4.8% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+5 | 21/9/2016 | 17/6/2026 | The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink. | |
| Modificada | Alta (7.8) | 4.8% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+4 | 21/9/2016 | 17/6/2026 | Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary. | |
| Modificada | Alta (7.8) | 3.7% | — | Libarchive | 21/9/2016 | 17/6/2026 | Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file. | |
| Modificada | Alta (7.8) | 4.9% | — | LibarchiveRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+4 | 21/9/2016 | 17/6/2026 | Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow. | |
| Modificada | Media (5.5) | 2.3% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITCanonical Ubuntu Linux+1 | 20/9/2016 | 17/6/2026 | The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file. | |
| Modificada | Media (5.5) | 2.0% | — | LibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+1 | 20/9/2016 | 17/6/2026 | Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file. | |
| Modificada | Media (5.5) | 2.2% | — | Canonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 20/9/2016 | 17/6/2026 | The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift. | |
| Modificada | Alta (7.8) | 2.1% | — | LibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+2 | 20/9/2016 | 17/6/2026 | Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtree file, which triggers undefined behavior. | |
| Modificada | Alta (7.5) | 4.3% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITLibarchive+1 | 20/9/2016 | 17/6/2026 | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself. | |
| Modificada | Media (5.5) | 1.5% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITLibarchive | 20/9/2016 | 17/6/2026 | Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file. | |
| Modificada | Media (5.5) | 2.1% | — | Canonical Ubuntu LinuxLibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 20/9/2016 | 17/6/2026 | The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. | |
| Modificada | Media (5.5) | 1.5% | — | Libarchive | 20/9/2016 | 17/6/2026 | The trad_enc_decrypt_update function in archive_read_support_format_zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted zip file, related to reading the password. | |
| Modificada | Media (5.5) | 2.0% | — | Canonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+1 | 20/9/2016 | 17/6/2026 | The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted rar archive. | |
| Modificada | Media (5.5) | 2.1% | — | Canonical Ubuntu LinuxLibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 20/9/2016 | 17/6/2026 | The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newline parsing. | |
| Modificada | Media (5.5) | 5.4% | — | LibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+1 | 20/9/2016 | 17/6/2026 | The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file. | |
| Modificada | Media (6.5) | 2.9% | — | LibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+1 | 20/9/2016 | 17/6/2026 | The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file. | |
| Modificada | Media (5.5) | 2.1% | — | LibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+2 | 20/9/2016 | 17/6/2026 | The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct. | |
| Modificada | Alta (7.5) | 12% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerLibarchive+1 | 20/9/2016 | 17/6/2026 | The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. | |
| Modificada | Media (5.5) | 1.9% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerCanonical Ubuntu Linux+1 | 20/9/2016 | 17/6/2026 | The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file. | |
| Modificada | Alta (7.5) | 4.5% | — | Canonical Ubuntu LinuxLibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Desktop+1 | 20/9/2016 | 17/6/2026 | The lha_read_file_extended_header function in archive_read_support_format_lha.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds heap) via a crafted (1) lzh or (2) lha file. | |
| Modificada | Alta (7.5) | 3.8% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerLibarchive | 20/9/2016 | 17/6/2026 | The archive_string_append function in archive_string.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted cab files, related to "overlapping memcpy." | |
| Modificada | Alta (7.5) | 4.3% | — | Debian LinuxLibarchiveCanonical Ubuntu Linux | 20/9/2016 | 17/6/2026 | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an invalid character in the name of a cab file. | |
| Modificada | Media (6.5) | 3.2% | — | Canonical Ubuntu LinuxDebian LinuxLibarchive | 20/9/2016 | 17/6/2026 | bsdtar in libarchive before 3.2.0 returns a success code without filling the entry when the header is a "split file in multivolume RAR," which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted rar file. |