Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.31%—Fossies CatdocDebian Linux2/6/202517/6/2026
An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaAlta (7.8)0.31%—Fossies CatdocDebian Linux2/6/202517/6/2026
An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (7.5)0.58%—Fossies Catdoc26/10/202317/6/2026
Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c.
AnalizadaMedia (5.5)0.22%—Fossies Catdoc1/9/202317/6/2026
Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/fileutil.c.
AnalizadaAlta (7.8)0.28%—Fossies Catdoc9/5/202317/6/2026
Catdoc v0.95 was discovered to contain a global buffer overflow via the function process_file at /src/reader.c.
ModificadaAlta (7.8)1.2%—Fossies Catdoc8/7/201717/6/2026
The ole_init function in ole.c in catdoc 0.95 allows remote attackers to cause a denial of service (heap-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted file, i.e., data is written to memory addresses before the beginning of the tmpBuf buffer.
ModificadaBaja (2.1)0.34%—Catdoc18/8/200416/6/2026
msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").