Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.2) | 0.47% | — | GNU Glibc | 18/10/2017 | 16/6/2026 | scanf and related functions in glibc before 2.15 allow local users to cause a denial of service (segmentation fault) via a large string of 0s. | |
| Modificada | Alta (7.5) | 1.8% | — | Libcsoap Project Libcsoap | 6/10/2017 | 17/6/2026 | nanohttp in libcsoap allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted Authorization header. | |
| Modificada | Alta (7.5) | 8.5% | — | Haxx Libcurl | 6/10/2017 | 17/6/2026 | libcurl may read outside of a heap allocated buffer when doing FTP. When libcurl connects to an FTP server and successfully logs in (anonymous or not), it asks the server for the current directory with the `PWD` command. The server then responds with a 257 response containing the path, inside double quotes. The… | |
| Modificada | Media (6.5) | 4.0% | — | Haxx Libcurl | 5/10/2017 | 17/6/2026 | When doing a TFTP transfer and curl/libcurl is given a URL that contains a very long file name (longer than about 515 bytes), the file name is truncated to fit within the buffer boundaries, but the buffer size is still wrongly updated to use the untruncated length. This too large value is then used in the sendto()… | |
| Modificada | Media (6.5) | 2.7% | — | Haxx Libcurl | 5/10/2017 | 17/6/2026 | When asking to get a file from a file:// URL, libcurl provides a feature that outputs meta-data about the file using HTTP-like headers. The code doing this would send the wrong buffer to the user (stdout or the application's provide callback), which could lead to other private data from the heap to get inadvertently… | |
| Modificada | Media (5.9) | 2.4% | — | GNU Glibc | 7/9/2017 | 17/6/2026 | Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors related to error path. | |
| Modificada | Crítica (9.8) | 2.2% | — | Musl-libc Musl | 18/8/2017 | 17/6/2026 | Stack-based buffer overflow in the inet_pton function in network/inet_pton.c in musl libc 0.9.15 through 1.0.4, and 1.1.0 through 1.1.7 allows attackers to have unspecified impact via unknown vectors. | |
| Modificada | Media (5.9) | 2.0% | — | GNU Glibc | 1/8/2017 | 17/6/2026 | The DNS stub resolver in the GNU C Library (aka glibc or libc6) before version 2.26, when EDNS support is enabled, will solicit large UDP responses from name servers, potentially simplifying off-path DNS spoofing attacks due to IP fragmentation. | |
| Modificada | Alta (7.5) | 6.2% | — | Canonical Ubuntu LinuxGNU Glibc | 27/6/2017 | 17/6/2026 | res_query in libresolv in glibc before 2.25 allows remote attackers to cause a denial of service (NULL pointer dereference and process crash). | |
| Modificada | Alta (7.8) | 2.7% | 💥 Exploit | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+16 | 19/6/2017 | 17/6/2026 | glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these… | |
| Modificada | Alta (7.5) | 1.1% | — | Uclibc | 16/6/2017 | 17/6/2026 | In uClibc 0.9.33.2, there is stack exhaustion (uncontrolled recursion) in the check_dst_limits_calc_pos_1 function in misc/regex/regexec.c when processing a crafted regular expression. | |
| Modificada | Crítica (9.8) | 1.2% | — | Uclibc | 16/6/2017 | 17/6/2026 | In uClibc 0.9.33.2, there is an out-of-bounds read in the get_subexp function in misc/regex/regexec.c when processing a crafted regular expression. | |
| Modificada | Crítica (9.8) | 4.5% | — | GNU Glibc | 12/6/2017 | 17/6/2026 | nscd in the GNU C Library (aka glibc or libc6) before version 2.20 does not correctly compute the size of an internal buffer when processing netgroup requests, possibly leading to an nscd daemon crash or code execution as the user running nscd. | |
| Modificada | Media (6.5) | 13% | 💥 Exploit | Gnome LibcrocoOpensuse Leap | 12/6/2017 | 17/6/2026 | The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file. | |
| Modificada | Media (6.5) | 3.8% | — | Gnome LibcrocoOpensuse Leap | 12/6/2017 | 17/6/2026 | The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file. | |
| Modificada | Alta (7.5) | 7.7% | — | GNU Glibc | 7/5/2017 | 17/6/2026 | The xdr_bytes and xdr_string functions in the GNU C Library (aka glibc or libc6) 2.25 mishandle failures of buffer deserialization, which allows remote attackers to cause a denial of service (virtual memory allocation, or memory consumption if an overcommit setting is not used) via a crafted UDP packet to port 111, a… | |
| Modificada | Alta (7.8) | 2.0% | — | Gnome Libcroco | 19/4/2017 | 17/6/2026 | The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CSS file.… | |
| Modificada | Media (5.5) | 2.0% | — | Gnome Libcroco | 19/4/2017 | 17/6/2026 | The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file. | |
| Modificada | Alta (7.5) | 2.5% | — | Uclibc-ng Project Uclibc-ng | 24/3/2017 | 17/6/2026 | The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet. | |
| Modificada | Alta (7.5) | 2.8% | — | Uclibc-ng Project Uclibc-ng | 24/3/2017 | 17/6/2026 | The __decode_dotted function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via vectors involving compressed items in a reply. | |
| Modificada | Media (5.9) | 2.9% | — | GNU Glibc | 20/3/2017 | 17/6/2026 | The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion failure and application crash) via vectors related to extended regular expression processing. | |
| Modificada | Media (5.9) | 2.4% | — | GNU Glibc | 20/3/2017 | 17/6/2026 | The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash) via a malformed pattern, which triggers an out-of-bounds read. | |
| Modificada | Alta (8.1) | 3.9% | — | GNU Glibc | 20/3/2017 | 17/6/2026 | Integer overflow in the _IO_wstr_overflow function in libio/wstrops.c in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors related to computing a size in bytes, which triggers a… | |
| Modificada | Alta (8.1) | 3.8% | — | GNU Glibc | 15/3/2017 | 17/6/2026 | Integer overflow in the strxfrm function in the GNU C Library (aka glibc or libc6) before 2.21 allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a stack-based buffer overflow. | |
| Modificada | Media (6.5) | 0.44% | — | Libcacard Project Libcacard | 15/3/2017 | 17/6/2026 | Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object. |