Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 411 respecto a la semana anterior
Críticas / altas1311▲ 26 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.9) | 0.48% | — | EttercapAI | 24/5/2026 | 23/7/2026 | A vulnerability has been found in Ettercap up to 0.8.3. The affected element is the function FUNC_DECODER of the file src/dissectors/ec_gg.c of the component GG Dissector. The manipulation of the argument gg leads to heap-based buffer overflow. The attack is possible to be carried out remotely. The complexity of an… | |
| Aplazada | Baja (2.9) | 0.62% | — | BettercapAI | 11/5/2026 | 17/6/2026 | A flaw has been found in bettercap up to 2.41.5. Affected by this issue is some unknown functionality of the file modules/mysql_server/mysql_server.go of the component MySQL Server. Executing a manipulation can lead to integer coercion error. The attack can be launched remotely. The attack requires a high level of… | |
| Aplazada | Baja (2.9) | 0.62% | — | BettercapAI | 11/5/2026 | 17/6/2026 | A vulnerability was detected in bettercap up to 2.41.5. Affected by this vulnerability is the function ippReadChunkedBody of the file modules/zerogod/zerogod_ipp_primitives.go of the component zerogod IPP Service. Performing a manipulation results in integer coercion error. The attack can be initiated remotely. The… | |
| Analizada | Baja (1.9) | 0.19% | — | Ettercap-project Ettercap | 5/3/2026 | 17/6/2026 | A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has… | |
| Modificada | Alta (7.8) | 0.31% | — | Ettercap-project Ettercap | 28/5/2021 | 16/6/2026 | The GTK version of ettercap uses a global settings file at /tmp/.ettercap_gtk and does not verify ownership of this file. When parsing this file for settings in gtkui_conf_read() (src/interfacesgtk/ec_gtk_conf.c), an unchecked sscanf() call allows a maliciously placed settings file to overflow a statically-sized… | |
| Modificada | Alta (8.8) | 1.4% | — | Ettercap-project EttercapDebian Linux | 12/11/2019 | 16/6/2026 | An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack. | |
| Modificada | Crítica (9.8) | 1.7% | — | Ettercap Project Ettercap | 30/4/2017 | 17/6/2026 | The strescape function in ec_strings.c in Ettercap 0.8.2 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted filter that is mishandled by etterfilter. | |
| Modificada | Media (5.5) | 2.0% | — | Ettercap-project Ettercap | 15/3/2017 | 17/6/2026 | The compile_tree function in ef_compiler.c in the Etterfilter utility in Ettercap 0.8.2 and earlier allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted filter. | |
| Modificada | Media (5) | 2.8% | — | Ettercap-project Ettercap | 19/12/2014 | 17/6/2026 | Integer signedness error in the dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (crash) via a crafted password, which triggers a large memory allocation. | |
| Modificada | Media (5) | 2.4% | — | Ettercap-project Ettercap | 19/12/2014 | 17/6/2026 | The dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a packet containing only a CVS_LOGIN signature. | |
| Modificada | Alta (7.5) | 4.0% | — | Ettercap-project Ettercap | 19/12/2014 | 17/6/2026 | The radius_get_attribute function in dissectors/ec_radius.c in Ettercap 0.8.1 performs an incorrect cast, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which triggers a stack-based buffer overflow. | |
| Modificada | Alta (7.5) | 3.9% | — | Ettercap-project Ettercap | 19/12/2014 | 17/6/2026 | Ettercap 0.8.1 does not validate certain return values, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted (1) name to the parse_line function in mdns_spoof/mdns_spoof.c or (2) base64 encoded password to the dissector_imap function in… | |
| Modificada | Alta (7.5) | 4.0% | — | Ettercap-project Ettercap | 19/12/2014 | 17/6/2026 | Heap-based buffer overflow in the nbns_spoof function in plug-ins/nbns_spoof/nbns_spoof.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a large netbios packet. | |
| Modificada | Alta (7.5) | 4.1% | — | Ettercap-project Ettercap | 19/12/2014 | 17/6/2026 | Integer underflow in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds write) and possibly execute arbitrary code via a small (1) size variable value in the dissector_dhcp function in dissectors/ec_dhcp.c, (2) length value to the dissector_gg function in dissectors/ec_gg.c, or (3)… | |
| Modificada | Alta (7.5) | 3.6% | — | Ettercap-project Ettercap | 19/12/2014 | 17/6/2026 | The dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted password length, which triggers a 0 character to be written to an arbitrary memory location. | |
| Modificada | Alta (7.5) | 13% | — | Ettercap-project Ettercap | 19/12/2014 | 17/6/2026 | Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted password length value that is inconsistent with the actual length of the password. | |
| Modificada | Media (4.4) | 0.84% | — | Ettercap-project Ettercap | 11/1/2013 | 16/6/2026 | Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow local users to gain privileges via a Trojan horse hosts list containing a long line. | |
| Modificada | Alta (7.5) | 5.5% | — | EttercapDebian Linux | 31/5/2005 | 16/6/2026 | Format string vulnerability in the curses_msg function in the Ncurses interface (ec_curses.c) for Ettercap before 0.7.3 allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 5.0% | — | Ettercap | 31/5/2002 | 16/6/2026 | Buffer overflow in various decoders in Ettercap 0.6.3.1 and earlier, when running on networks with an MTU greater than 2000, allows remote attackers to execute arbitrary code via large packets. |