Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.9% | — | GNU Glibc | 8/4/2011 | 16/6/2026 | Integer overflow in posix/fnmatch.c in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows context-dependent attackers to cause a denial of service (application crash) via a long UTF8 string that is used in an fnmatch call with a crafted pattern argument, a different vulnerability than CVE-2011-1071. | |
| Modificada | Baja (3.7) | 0.31% | — | GNU Glibc | 8/4/2011 | 16/6/2026 | ld.so in the GNU C Library (aka glibc or libc6) 2.13 and earlier expands the $ORIGIN dynamic string token when RPATH is composed entirely of this token, which might allow local users to gain privileges by creating a hard link in an arbitrary directory to a (1) setuid or (2) setgid program with this RPATH value, and… | |
| Modificada | Media (5.1) | 14% | 💥 Exploit | GNU EglibcGNU Glibc | 8/4/2011 | 16/6/2026 | The GNU C Library (aka glibc or libc6) before 2.12.2 and Embedded GLIBC (EGLIBC) allow context-dependent attackers to execute arbitrary code or cause a denial of service (memory consumption) via a long UTF8 string that is used in an fnmatch call, aka a "stack extension attack," a related issue to CVE-2010-2898,… | |
| Modificada | Media (6.9) | 0.79% | 💥 Exploit | GNU GlibcRedhat Enterprise Linux | 8/4/2011 | 16/6/2026 | Multiple untrusted search path vulnerabilities in elf/dl-object.c in certain modified versions of the GNU C Library (aka glibc or libc6), including glibc-2.5-49.el5_5.6 and glibc-2.12-1.7.el6_0.3 in Red Hat Enterprise Linux, allow local users to gain privileges via a crafted dynamic shared object (DSO) in a… | |
| Modificada | Media (6.9) | 0.52% | — | GNU Glibc | 30/3/2011 | 16/6/2026 | ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states "This is just nonsense. There are a gazillion other ways to… | |
| Modificada | Media (4) | 2.6% | — | GNU Glibc | 2/3/2011 | 16/6/2026 | The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability… | |
| Modificada | Media (5) | 51% | 💥 Exploit | GNU Glibc | 13/1/2011 | 16/6/2026 | Stack consumption vulnerability in the regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (resource exhaustion) via a regular expression containing adjacent repetition operators, as demonstrated by… | |
| Modificada | Media (5) | 40% | 💥 Exploit | GNU Glibc | 13/1/2011 | 16/6/2026 | The regcomp implementation in the GNU C Library (aka glibc or libc6) through 2.11.3, and 2.12.x through 2.12.2, allows context-dependent attackers to cause a denial of service (application crash) via a regular expression containing adjacent bounded repetitions that bypass the intended RE_DUP_MAX limitation, as… | |
| Modificada | Alta (7.2) | 11% | 💥 Exploit | GNU Glibc | 7/1/2011 | 16/6/2026 | ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use of the LD_AUDIT environment variable to reference dynamic shared objects (DSOs) as audit objects, which allows local users to gain privileges by leveraging an unsafe DSO located in a trusted library… | |
| Modificada | Media (6.9) | 9.5% | 💥 Exploit | GNU Glibc | 7/1/2011 | 16/6/2026 | elf/dl-load.c in ld.so in the GNU C Library (aka glibc or libc6) through 2.11.2, and 2.12.x through 2.12.1, does not properly handle a value of $ORIGIN for the LD_AUDIT environment variable, which allows local users to gain privileges via a crafted dynamic shared object (DSO) located in an arbitrary directory. | |
| Modificada | Media (5) | 1.6% | — | GNU Glibc | 14/10/2010 | 16/6/2026 | Certain run-time memory protection mechanisms in the GNU C Library (aka glibc or libc6) print argv[0] and backtrace information, which might allow context-dependent attackers to obtain sensitive information from process memory by executing an incorrect program, as demonstrated by a setuid program that contains a… | |
| Modificada | Baja (3.6) | 0.39% | — | Freedesktop Dbus-glib | 20/8/2010 | 16/6/2026 | DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services. | |
| Modificada | Media (5.1) | 4.5% | — | GNU Glibc | 1/6/2010 | 16/6/2026 | Integer signedness error in the elf_get_dynamic_info function in elf/dynamic-link.h in ld.so in the GNU C Library (aka glibc or libc6) 2.0.1 through 2.11.1, when the --verify option is used, allows user-assisted remote attackers to execute arbitrary code via a crafted ELF program with a negative value for a certain… | |
| Modificada | Alta (7.2) | 0.57% | — | GNU Glibc | 1/6/2010 | 16/6/2026 | The encode_name macro in misc/mntent_r.c in the GNU C Library (aka glibc or libc6) 2.11.1 and earlier, as used by ncpmount and mount.cifs, does not properly handle newline characters in mountpoint names, which allows local users to cause a denial of service (mtab corruption), or possibly modify mount options and gain… | |
| Modificada | Media (5) | 2.0% | — | GNU Glibc | 1/6/2010 | 16/6/2026 | Integer overflow in the __vstrfmon_l function in stdlib/strfmon_l.c in the strfmon implementation in the GNU C Library (aka glibc or libc6) before 2.10.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted format string, as demonstrated by the %99999999999999999999n… | |
| Modificada | Media (5) | 11% | 💥 Exploit | GNU Glibc | 1/6/2010 | 16/6/2026 | Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory consumption or application crash) via a crafted format string, as demonstrated by a crafted first argument to the money_format… | |
| Modificada | Alta (7.5) | 3.1% | — | GNU Glibc | 14/1/2010 | 16/6/2026 | nis/nss_nis/nis-pwd.c in the GNU C Library (aka glibc or libc6) 2.7 and Embedded GLIBC (EGLIBC) 2.10.2 adds information from the passwd.adjunct.byname map to entries in the passwd map, which allows remote attackers to obtain the encrypted passwords of NIS accounts by calling the getpwnam function. | |
| Modificada | Alta (7.8) | 0.36% | — | Gnome GlibOpensuseSuse Linux Enterprise Server | 22/9/2009 | 16/6/2026 | The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory. | |
| Modificada | Media (4.6) | 0.49% | — | Gnome Glib | 14/3/2009 | 16/6/2026 | Multiple integer overflows in glib/gbase64.c in GLib before 2.20 allow context-dependent attackers to execute arbitrary code via a long string that is converted either (1) from or (2) to a base64 representation. | |
| Modificada | Alta (7.2) | 0.45% | — | Gentoo Glibc | 3/7/2007 | 16/6/2026 | Integer overflow in the process_envvars function in elf/rtld.c in glibc before 2.5-rc4 might allow local users to execute arbitrary code via a large LD_HWCAP_MASK environment variable value. NOTE: the glibc maintainers state that they do not believe that this issue is exploitable for code execution | |
| Modificada | Baja (2.1) | 0.39% | — | GNU GlibcRedhat Enterprise LinuxRedhat Enterprise Linux Desktop | 9/2/2005 | 16/6/2026 | The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Baja (2.1) | 0.36% | — | GNU Glibc | 31/12/2004 | 16/6/2026 | The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968. | |
| Modificada | Baja (2.1) | 0.36% | — | GNU Glibc | 31/12/2004 | 16/6/2026 | GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program. | |
| Modificada | Media (4.9) | 0.38% | — | GNU GlibcGNU ZebraQuagga Routing Software SuiteSGI Propack+3 | 15/12/2003 | 16/6/2026 | The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface. | |
| Modificada | Alta (7.5) | 15% | — | GNU GlibcMIT Kerberos 5OpenafsSGI Irix+9 | 25/3/2003 | 16/6/2026 | Integer overflow in the xdrmem_getbytes() function, and possibly other functions, of XDR (external data representation) libraries derived from SunRPC, including libnsl, libc, glibc, and dietlibc, allows remote attackers to execute arbitrary code via certain integer values in length fields, a different vulnerability… |