Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.18% | — | Gnome EvinceAITUG TEX LiveAI | 21/7/2026 | 23/7/2026 | The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX… | |
| Modificada | Media (5.5) | 1.1% | — | Gnome EvinceDebian LinuxOpensuseRedhat Enterprise Linux | 1/11/2019 | 16/6/2026 | evince is missing a check on number of pages which can lead to a segmentation fault | |
| Modificada | Alta (7.8) | 2.1% | — | Gnome EvinceCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 15/7/2019 | 17/6/2026 | Evince 3.26.0 is affected by buffer overflow. The impact is: DOS / Possible code execution. The component is: backend/tiff/tiff-document.c. The attack vector is: Victim must open a crafted PDF file. The issue occurs because of an incorrect integer overflow protection mechanism in tiff_document_render and… | |
| Modificada | Media (5.5) | 1.4% | — | Gnome EvinceCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux+5 | 22/4/2019 | 17/6/2026 | The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files. | |
| Modificada | Alta (7.8) | 1.4% | — | Gnome Evince | 27/11/2017 | 17/6/2026 | Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91. | |
| Modificada | Alta (7.8) | 51% | — | Gnome EvinceDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 5/9/2017 | 17/6/2026 | backend/comics/comics-document.c (aka the comic book backend) in GNOME Evince before 3.24.1 allows remote attackers to execute arbitrary commands via a .cbt file that is a TAR archive containing a filename beginning with a "--" command-line option substring, as demonstrated by a --checkpoint-action=exec=bash at the… | |
| Modificada | Media (6.8) | 3.4% | — | Gnome EvinceT1libTetex | 19/11/2012 | 16/6/2026 | Multiple off-by-one errors in the (1) token and (2) linetoken functions in backend/dvi/mdvi-lib/afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted… | |
| Modificada | Media (6.8) | 4.2% | — | Gnome EvinceT1libTetex | 19/11/2012 | 16/6/2026 | Heap-based buffer overflow in the linetoken function in afmparse.c in t1lib, as used in teTeX 3.0.x, GNOME evince, and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a DVI file containing a crafted Adobe Font Metrics (AFM) file, a different… | |
| Modificada | Media (6.8) | 1.1% | — | Devincentiis Gazie | 21/2/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in modules/config/admin_utente.php in GAzie 5.20 and earlier allows remote attackers to hijack the authentication of administrators for requests that change account information via an update action, as demonstrated by changing the password. | |
| Modificada | Alta (7.6) | 6.0% | — | Redhat Evince | 7/1/2011 | 16/6/2026 | Integer overflow in the TFM font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer. | |
| Modificada | Alta (7.6) | 14% | — | Redhat EvinceT1libTUG Tetex | 7/1/2011 | 16/6/2026 | Heap-based buffer overflow in the AFM font parser in the dvi-backend component in Evince 2.32 and earlier, teTeX 3.0, t1lib 5.1.2, and possibly other products allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file… | |
| Modificada | Alta (7.6) | 4.9% | — | Redhat Evince | 7/1/2011 | 16/6/2026 | Array index error in the VF font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer. | |
| Modificada | Alta (7.6) | 4.9% | — | Redhat Evince | 7/1/2011 | 16/6/2026 | Array index error in the PK font parser in the dvi-backend component in Evince 2.32 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted font in conjunction with a DVI file that is processed by the thumbnailer. |