Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3222▲ 222 respecto a la semana anterior
Críticas / altas1465▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)511▼ 31 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.24%—Debian Devscripts1/8/202517/6/2026
It was discovered that uscan, a tool to scan/watch upstream sources for new releases of software, included in devscripts (a collection of scripts to make the life of a Debian Package maintainer easier), skips OpenPGP verification if the upstream source is already downloaded from a previous run even if the verification…
ModificadaAlta (8.8)1.8%—Debian DevscriptsDebian Linux3/12/201917/6/2026
An issue exists in uscan in devscripts before 2.13.19, which could let a remote malicious user execute arbitrary code via a crafted tarball.
ModificadaCrítica (9.8)2.5%—Debian DevscriptsCanonical Ubuntu Linux1/7/201817/6/2026
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.
ModificadaAlta (7.8)0.53%—Devscripts Devel Team DevscriptsFedoraproject Fedora25/9/201717/6/2026
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
ModificadaAlta (7.5)3.1%—Devscripts Devel Team DevscriptsFedoraproject Fedora6/9/201717/6/2026
Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename.
ModificadaMedia (5)3.7%—Devscripts Devel Team Devscripts5/2/201417/6/2026
Directory traversal vulnerability in uupdate in devscripts 2.14.1 allows remote attackers to modify arbitrary files via a crafted .orig.tar file, related to a symlink.
ModificadaAlta (7.5)4.1%—Devscripts Devel Team Devscripts7/1/201417/6/2026
Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
ModificadaMedia (5.8)2.5%—Devscripts Devel Team Devscripts14/12/201317/6/2026
Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename.
ModificadaMedia (6.8)1.9%—Devscripts Devel Team Devscripts13/12/201317/6/2026
The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a directory name.
ModificadaBaja (1.2)0.27%—Devscripts Devel Team Devscripts1/10/201216/6/2026
scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via a symlink attack on the temporary (1) standard output or (2) standard error output file.
ModificadaMedia (6.8)1.7%—Devscripts Devel Team Devscripts1/10/201216/6/2026
scripts/dget.pl in devscripts before 2.10.73 allows remote attackers to execute arbitrary commands via a crafted (1) .dsc or (2) .changes file, related to "arguments to external commands" that are not properly escaped, a different vulnerability than CVE-2012-2240.
ModificadaMedia (5)1.5%—Devscripts Devel Team Devscripts1/10/201216/6/2026
scripts/dget.pl in devscripts before 2.12.3 allows remote attackers to delete arbitrary files via a crafted (1) .dsc or (2) .changes file, probably related to a NULL byte in a filename.
ModificadaAlta (7.5)3.2%—Devscripts Devel Team Devscripts1/10/201216/6/2026
scripts/dscverify.pl in devscripts before 2.12.3 allows remote attackers to execute arbitrary commands via unspecified vectors related to "arguments to external commands."
ModificadaAlta (9.3)5.8%—Devscripts Devel Team Devscripts16/6/201216/6/2026
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via shell metacharacters in the file name argument.
ModificadaAlta (9.3)5.8%—Devscripts Devel Team Devscripts16/6/201216/6/2026
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to execute arbitrary code via a crafted tarball file name in the top-level directory of an original (.orig) source tarball of a source package.
ModificadaAlta (9.3)5.3%—Devscripts Devel Team Devscripts16/6/201216/6/2026
debdiff.pl in devscripts 2.10.x before 2.10.69 and 2.11.x before 2.11.4 allows remote attackers to obtain system information and execute arbitrary code via the file name in a (1) .dsc or (2) .changes file.
ModificadaAlta (9.3)2.9%—Devscripts Devel Team Devscripts4/9/200916/6/2026
Eval injection vulnerability in scripts/uscan.pl before Rev 1984 in devscripts allows remote attackers to execute arbitrary Perl code via crafted pathnames on distribution servers for upstream source code used in Debian GNU/Linux packages.
ModificadaAlta (7.5)2.8%—Devscripts Admbook23/2/200616/6/2026
Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via the X-Forwarded-For HTTP header field, which is inserted into content-data.php.