Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1338▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 8.7% | — | Fedoraproject FedoraDigia QTQT | 12/5/2015 | 17/6/2026 | Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image. | |
| Modificada | Media (6.8) | 7.1% | — | Fedoraproject FedoraDigia QTQT | 12/5/2015 | 17/6/2026 | Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted ICO image. | |
| Modificada | Media (6.8) | 7.2% | — | Digia QTQTFedoraproject Fedora | 12/5/2015 | 17/6/2026 | Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted BMP image. | |
| Modificada | Media (5) | 6.3% | — | Fedoraproject FedoraOpensuseDigia QT | 25/3/2015 | 17/6/2026 | The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file. | |
| Modificada | Media (5) | 3.1% | — | Digia QTQT | 23/12/2013 | 16/6/2026 | QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) via an XML Entity Expansion (XEE) attack. | |
| Modificada | Media (4.3) | 1.9% | — | Digia QTQTCanonical Ubuntu Linux | 24/2/2013 | 16/6/2026 | The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML application. | |
| Modificada | Media (4.3) | 1.4% | — | Digia QTQT | 29/6/2012 | 16/6/2026 | QSslSocket in Qt before 4.7.0-rc1 recognizes a wildcard IP address in the subject's Common Name field of an X.509 certificate, which might allow man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. | |
| Modificada | Alta (7.5) | 2.3% | — | Digia QTWebkit | 22/7/2010 | 16/6/2026 | Off-by-one error in the WebSocketHandshake::readServerHandshake function in websockets/WebSocketHandshake.cpp in WebCore in WebKit before r56380, as used in Qt and other products, allows remote websockets servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via an upgrade… | |
| Modificada | Media (5) | 11% | — | Digia QTQT | 2/7/2010 | 16/6/2026 | The QSslSocketBackendPrivate::transmit function in src_network_ssl_qsslsocket_openssl.cpp in Qt 4.6.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed request. | |
| Modificada | Alta (7.5) | 0.97% | — | Digiappz Digiaffiliate | 18/3/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin and (2) password fields. | |
| Modificada | Alta (7.5) | 1.0% | — | Digiappz Digileave | 25/7/2008 | 16/6/2026 | SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter. | |
| Modificada | Media (4.3) | 1.5% | — | Digiappz Digidomain | 31/3/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Digiappz DigiDomain 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) domain parameter to lookup_result.asp, and the (2) word1 and (3) word2 parameters to suggest_result.asp. | |
| Modificada | Media (4.3) | 1.3% | — | Digiappz Digirez | 29/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Digirez 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) Room_name parameter to room/info_book.asp or the (2) curYear parameter to room/week.asp. | |
| Modificada | Alta (7.5) | 1.1% | — | Digiappz Digiaffiliate | 18/1/2007 | 16/6/2026 | SQL injection vulnerability in visu_user.asp in Digiappz DigiAffiliate 1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Digiappz Digirez | 9/1/2007 | 16/6/2026 | SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the book_id parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Digiappz Freekot | 1/9/2006 | 16/6/2026 | Multiple SQL injection vulnerabilities in login_verif.asp in Digiappz Freekot 1.01 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) password parameters. NOTE: some of these details are obtained from third party information. |