Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.51% | — | File RollerAI | 25/8/2026 | 28/8/2026 | A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a stack buffer overflow and cause… | |
| Modificada | Baja (3.9) | 0.61% | — | Gnome File-rollerFedoraproject Fedora | 7/4/2021 | 17/6/2026 | fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736. | |
| Modificada | Baja (3.9) | 0.77% | — | Gnome File-rollerDebian LinuxCanonical Ubuntu Linux | 13/4/2020 | 17/6/2026 | fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location. | |
| Modificada | Media (4.3) | 2.1% | — | Gnome File-rollerCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux | 21/9/2019 | 17/6/2026 | An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction. | |
| Modificada | Alta (7.5) | 3.3% | — | Canonical Ubuntu LinuxFile Roller Project File Roller | 26/9/2016 | 17/6/2026 | The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive. | |
| Modificada | Media (5) | 4.3% | — | File Roller Project File RollerCanonical Ubuntu Linux | 18/7/2013 | 16/6/2026 | Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrary files via a crafted archive that is not properly handled in a "Keep directory structure" action, related to fr-archive-libarchive.c and… |