Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.3) | 0.94% | — | Autotrace Project AutotraceFedoraproject Fedora | 14/7/2022 | 17/6/2026 | AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660. | |
| Modificada | Alta (7.8) | 0.97% | — | Autotrace Project AutotraceFedoraproject Fedora | 11/2/2021 | 17/6/2026 | A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitmap image. This may occur after the use-after-free in CVE-2017-9182. | |
| Modificada | Baja (3.3) | 1.0% | — | Autotrace Project AutotraceFedoraproject Fedora | 11/2/2021 | 17/6/2026 | A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image. | |
| Modificada | Crítica (9.8) | 2.3% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-tga.c:528:63. | |
| Modificada | Crítica (9.8) | 1.9% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-tga.c:192:19. | |
| Modificada | Crítica (9.8) | 1.9% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-tga.c:508:18. | |
| Modificada | Crítica (9.8) | 1.9% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-tga.c:498:55. | |
| Modificada | Crítica (9.8) | 1.8% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a "negative-size-param" issue in the ReadImage function in input-tga.c:528:7. | |
| Modificada | Crítica (9.8) | 1.9% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:620:27. | |
| Modificada | Crítica (9.8) | 1.9% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:559:29. | |
| Modificada | Crítica (9.8) | 1.9% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer over-read in the ReadImage function in input-tga.c:538:33. | |
| Modificada | Crítica (9.8) | 1.8% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the ReadImage function in input-tga.c:528:7. | |
| Modificada | Crítica (9.8) | 1.8% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a heap-based buffer overflow in the rle_fread function in input-tga.c:252:15. | |
| Modificada | Alta (7.5) | 2.5% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid free), related to the free_bitmap function in bitmap.c:24:5. | |
| Modificada | Alta (7.5) | 1.8% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and application crash), related to the GET_COLOR function in color.c:16:11. | |
| Modificada | Crítica (9.8) | 2.3% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a "left shift ... cannot be represented in type int" issue in input-bmp.c:516:63. | |
| Modificada | Crítica (9.8) | 1.9% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:486:7. | |
| Modificada | Crítica (9.8) | 1.9% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:326:17. | |
| Modificada | Crítica (9.8) | 1.9% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:319:7. | |
| Modificada | Crítica (9.8) | 1.9% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:314:7. | |
| Modificada | Crítica (9.8) | 1.9% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 has a "cannot be represented in type int" issue in input-bmp.c:309:7. | |
| Modificada | Alta (7.5) | 2.2% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (use-after-free and invalid heap read), related to the GET_COLOR function in color.c:16:11. | |
| Modificada | Alta (7.5) | 2.4% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid write and SEGV), related to the ReadImage function in input-bmp.c. | |
| Modificada | Alta (7.5) | 2.2% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:440:14. | |
| Modificada | Alta (7.5) | 2.0% | — | Autotrace Project Autotrace | 23/5/2017 | 17/6/2026 | libautotrace.a in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (invalid read and SEGV), related to the ReadImage function in input-bmp.c:425:14. |