Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.31% | — | Fossies CatdocDebian Linux | 2/6/2025 | 17/6/2026 | An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Alta (7.8) | 0.31% | — | Fossies CatdocDebian Linux | 2/6/2025 | 17/6/2026 | An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 0.58% | — | Fossies Catdoc | 26/10/2023 | 17/6/2026 | Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/xlsparse.c. | |
| Analizada | Media (5.5) | 0.22% | — | Fossies Catdoc | 1/9/2023 | 17/6/2026 | Catdoc v0.95 was discovered to contain a NULL pointer dereference via the component xls2csv at src/fileutil.c. | |
| Analizada | Alta (7.8) | 0.28% | — | Fossies Catdoc | 9/5/2023 | 17/6/2026 | Catdoc v0.95 was discovered to contain a global buffer overflow via the function process_file at /src/reader.c. | |
| Modificada | Alta (7.8) | 1.2% | — | Fossies Catdoc | 8/7/2017 | 17/6/2026 | The ole_init function in ole.c in catdoc 0.95 allows remote attackers to cause a denial of service (heap-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted file, i.e., data is written to memory addresses before the beginning of the tmpBuf buffer. | |
| Modificada | Baja (2.1) | 0.34% | — | Catdoc | 18/8/2004 | 16/6/2026 | msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html"). |