Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.90% | — | Dcraw Project DcrawDebian Linux | 18/4/2022 | 17/6/2026 | There is an integer overflow vulnerability in dcraw. When the victim runs dcraw with a maliciously crafted X3F input image, arbitrary code may be executed in the victim's system. | |
| Modificada | Alta (8.8) | 2.9% | — | Dcraw Project DcrawSuse Linux Enterprise DesktopSuse Linux Enterprise Server | 29/11/2018 | 17/6/2026 | A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file. | |
| Modificada | Media (5.5) | 0.92% | — | Dcraw Project Dcraw | 26/11/2018 | 17/6/2026 | A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code. | |
| Modificada | Media (5.5) | 0.92% | — | Dcraw Project Dcraw | 26/11/2018 | 17/6/2026 | A floating point exception in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code. | |
| Modificada | Alta (7.1) | 1.1% | — | Dcraw Project Dcraw | 26/11/2018 | 17/6/2026 | A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information. | |
| Modificada | Alta (7.1) | 1.1% | — | Dcraw Project Dcraw | 26/11/2018 | 17/6/2026 | A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information. | |
| Modificada | Media (4.3) | 5.4% | — | Dcraw Project DcrawFedoraproject Fedora | 19/5/2015 | 17/6/2026 | Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable. | |
| Modificada | Media (4.3) | 2.1% | — | Dave Coffin Dcraw | 19/1/2014 | 16/6/2026 | Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference. |