Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
58 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.8) | 0.18% | — | FluidsynthAI | 18/9/2026 | 24/9/2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates ptbl chunks with the unsigned expression cues * 4 + cbsize without checking whether the multiplication and addition fit in 32 bits. A crafted DLS file can supply a large cues value that… | |
| Pendiente de análisis | Media (6.8) | 0.20% | — | FluidsynthAI | 18/9/2026 | 23/9/2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned expression cbsize + connblocks * 12 without first ensuring that the multiplication and addition fit in 32 bits. A crafted DLS file can supply a… | |
| Pendiente de análisis | Alta (8) | 0.19% | — | FluidsynthAI | 18/9/2026 | 23/9/2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or fluid_sample_sanitize_loop(). A crafted DLS file can place sample loop… | |
| Aplazada | Media (6.2) | 0.18% | — | FluidsynthAI | 18/9/2026 | 24/9/2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one record. A crafted SF2 file containing a zero-sized DMOD chunk makes the unsigned subtraction… | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | FluidsynthAI | 18/9/2026 | 25/9/2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active channels. The resulting out-of-bounds reads and… | |
| Aplazada | Crítica (9.8) | 0.80% | — | FluidsynthAI | 18/9/2026 | 24/9/2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth channel. An out-of-range channel can… | |
| Analizada | Alta (7.5) | 0.47% | — | Fluidsynth | 9/1/2026 | 17/6/2026 | fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file. | |
| Analizada | Alta (7) | 0.21% | — | Fluidsynth | 23/12/2025 | 17/6/2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From versions 2.5.0 to before 2.5.2, a race condition during unloading of a DLS file can trigger a heap-based use-after-free. A concurrently running thread may be pending to unload a DLS file, leading to use of freed memory, if the… | |
| Analizada | Alta (7.5) | 0.33% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.33% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Improper Null Termination vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of10::Port:unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.42% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::ActionList::unpack10. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.37% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyTable::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.37% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyPortStats::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.37% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyGroup::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.37% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyGroupDesc::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.37% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyMeter::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.37% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyMeterConfig::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.39% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartRequestTableFeatures::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.39% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyTableFeatures::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.39% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MultipartReplyPortDescription::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.39% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::QueueGetConfigReply::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.44% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MeterBandList::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.39% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::MeterStats::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.39% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Out-of-bounds Read vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::of13::Hello::unpack. This issue affects libfluid: 0.1.0. | |
| Analizada | Alta (7.5) | 0.44% | — | Opennetworking Libfluid MSG | 18/9/2024 | 17/6/2026 | Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program routine fluid_msg::QueuePropertyList::unpack10. This issue affects libfluid: 0.1.0. |