Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 10% | — | Libgd GD Graphics LibraryPHP | 19/10/2009 | 16/6/2026 | The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than… | |
| Modificada | Baja (2.6) | 2.5% | — | Libgd GD Graphics Library | 28/6/2007 | 16/6/2026 | Multiple unspecified vulnerabilities in the GIF reader in the GD Graphics Library (libgd) before 2.0.35 have unspecified impact and user-assisted remote attack vectors. | |
| Modificada | Media (4.3) | 2.5% | — | GD Graphics Library Gdlib | 28/6/2007 | 16/6/2026 | The GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via a GIF image that has no global color map. | |
| Modificada | Media (4.3) | 2.5% | — | GD Graphics Library Gdlib | 28/6/2007 | 16/6/2026 | Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault. | |
| Modificada | Media (5) | 4.9% | — | Libgd GD Graphics Library | 28/6/2007 | 16/6/2026 | The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value. | |
| Modificada | Media (4.3) | 7.3% | — | Libgd GD Graphics Library | 28/6/2007 | 16/6/2026 | Integer overflow in gdImageCreateTrueColor function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to have unspecified attack vectors and impact. | |
| Modificada | Media (4.3) | 13% | — | Libgd GD Graphics Library | 28/6/2007 | 16/6/2026 | The gdImageCreateXbm function in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors involving a gdImageCreate failure. | |
| Modificada | Media (4.3) | 1.7% | — | GD Graphics Library Gdlib | 28/6/2007 | 16/6/2026 | Race condition in gdImageStringFTEx (gdft_draw_bitmap) in gdft.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash) via unspecified vectors, possibly involving truetype font (TTF) support. | |
| Modificada | Alta (7.5) | 12% | — | GD Graphics Library Project GD Graphics LibraryPHPCanonical Ubuntu LinuxFedoraproject Fedora+3 | 30/1/2007 | 16/6/2026 | Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font. | |
| Modificada | Alta (10) | 28% | — | GD Graphics Library GdlibOpenpkgGentoo LinuxSuse Linux+1 | 1/3/2005 | 16/6/2026 | Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a… | |
| Modificada | Alta (10) | 11% | — | GD Graphics Library GdlibTrustix Secure Linux | 9/2/2005 | 16/6/2026 | Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 and earlier may allow remote attackers to execute arbitrary code via malformed image files that trigger the overflows due to improper calls to the gdMalloc function, a different set of vulnerabilities than CVE-2004-0990. |