Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.67%—Fasterxml Jackson-dataformats-binaryAI1/10/20262/10/2026
The Smile parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. SmileParser._handleLongFieldName() grows its internal name buffer through an unconstrained…
Pendiente de análisisAlta (7.5)0.67%—Fasterxml Jackson Dataformats BinaryAI1/10/20262/10/2026
The CBOR parser in FasterXML jackson-dataformats-binary never invokes StreamReadConstraints.validateNameLength() when decoding JSON object property names, so the maxNameLength limit is not enforced for this format. CBORParser._decodeLongerName() decodes a definite-length property name with no length check, and…
AnalizadaMedia (6.8)0.51%—Openmicroscopy Bio-formats7/1/202617/6/2026
Bio-Formats versions up to and including 8.3.0 perform unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing. The loci.formats.Memoizer class automatically loads and deserializes memo files associated with images without validation, integrity checks, or trust…
ModificadaMedia (4.6)0.17%—Openmicroscopy Bio-formats7/1/202617/6/2026
Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing component (e.g., XLEF). The parser uses an insecurely configured DocumentBuilderFactory when processing Leica XML-based metadata files, allowing external entity expansion and…
AnalizadaBaja (1.9)0.34%—Rareprob HD Video Player ALL Formats2/12/202517/6/2026
A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is an unknown function of the component com.rocks.music.videoplayer. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit has been disclosed publicly and may…
AnalizadaAlta (7.8)0.51%—Irfanview Formats22/11/202417/6/2026
IrfanView PIC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious…
AnalizadaAlta (7.8)0.50%—Irfanview Formats22/11/202417/6/2026
IrfanView PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
AnalizadaAlta (7.8)0.51%—Irfanview Formats22/11/202417/6/2026
IrfanView SHP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious…
AnalizadaAlta (7.8)0.51%—Irfanview Formats22/11/202417/6/2026
IrfanView PNT File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious…
ModificadaAlta (8.8)0.21%—Blackbam Tinymce AND Tinymce Advanced Professsional Formats AND Styles21/2/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in David Stockl TinyMCE and TinyMCE Advanced Professsional Formats and Styles.This issue affects TinyMCE and TinyMCE Advanced Professsional Formats and Styles: from n/a through 1.1.2.
ModificadaAlta (8.8)0.61%—Apple PRO Video Formats6/9/202317/6/2026
A logic issue was addressed with improved state management. This issue is fixed in Pro Video Formats 2.2.5. A user may be able to elevate privileges.
ModificadaAlta (7.5)0.91%—Fasterxml Jackson-dataformats-text8/8/202317/6/2026
Those using jackson-dataformats-text to parse TOML data may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. This effect may support a denial of service attack.
ModificadaAlta (7.8)0.85%—Ok-file-formats Project Ok-file-formats15/6/202217/6/2026
ok-file-formats master 2021-9-12 is affected by a buffer overflow in ok_jpg_convert_data_unit_grayscale and ok_jpg_convert_YCbCr_to_RGB.
ModificadaAlta (7.8)0.73%—Ok-file-formats Project Ok-file-formats3/3/202217/6/2026
David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_png_read_data() in "/ok_png.c".
ModificadaAlta (7.8)0.73%—Ok-file-formats Project Ok-file-formats3/3/202217/6/2026
David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_png_transform_scanline() in "/ok_png.c:533".
ModificadaAlta (7.8)0.73%—Ok-file-formats Project Ok-file-formats28/2/202217/6/2026
David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow via function ok_png_transform_scanline() in "/ok_png.c:494".
ModificadaAlta (7.8)0.73%—Ok-file-formats Project Ok-file-formats28/2/202217/6/2026
David Brackeen ok-file-formats dev version is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_jpg_generate_huffman_table() in "/ok_jpg.c:403".
ModificadaAlta (7.8)0.73%—Ok-file-formats Project Ok-file-formats28/2/202217/6/2026
David Brackeen ok-file-formats 203defd is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurred in function ok_png_transform_scanline() in "/ok_png.c:712".
ModificadaAlta (7.8)0.73%—Ok-file-formats Project Ok-file-formats28/2/202217/6/2026
David Brackeen ok-file-formats 97f78ca is vulnerable to Buffer Overflow. When the function of the ok-file-formats project is used, a heap-buffer-overflow occurs in function ok_jpg_convert_YCbCr_to_RGB() in "/ok_jpg.c:513" .
ModificadaAlta (8.8)1.1%—Ok-file-formats Project Ok-file-formats27/8/202117/6/2026
Heap-based Buffer Overflow vulnerability exists in ok-file-formats 1 via the ok_jpg_generate_huffman_table function in ok_jpg.c.
ModificadaAlta (7.8)0.87%—Ok-file-formats Project Ok-file-formats24/8/202117/6/2026
ok-file-formats through 2021-04-29 has a heap-based buffer overflow in the ok_csv_circular_buffer_read function in ok_csv.c.
ModificadaMedia (6.5)1.1%—Ok-file-formats Project Ok-file-formats15/7/202117/6/2026
A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_progressive() at ok_jpg.c:1054 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.
ModificadaMedia (6.5)1.0%—Ok-file-formats Project Ok-file-formats15/7/202117/6/2026
A heap-based buffer overflow vulnerability in the function ok_jpg_decode_block_subsequent_scan() ok_jpg.c:1102 of ok-file-formats through 2020-06-26 allows attackers to cause a Denial of Service (DOS) via a crafted jpeg file.
ModificadaMedia (5.5)0.95%—KDE Kimageformats1/7/202117/6/2026
KDE KImageFormats 5.70.0 through 5.81.0 has a stack-based buffer overflow in XCFImageFormat::loadTileRLE.
ModificadaAlta (7.5)3.1%—Fasterxml Jackson-dataformats-binaryQuarkusOracle Weblogic Server18/2/202117/6/2026
This affects the package com.fasterxml.jackson.dataformat:jackson-dataformat-cbor from 0 and before 2.11.4, from 2.12.0-rc1 and before 2.12.1. Unchecked allocation of byte buffer can cause a java.lang.OutOfMemoryError exception.