Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 301 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Gnome LibrsvgAI | 23/9/2026 | 25/9/2026 | A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially… | |
| Pendiente de análisis | Alta (7.5) | 0.79% | — | Gnome Remote DesktopAI | 23/9/2026 | 24/9/2026 | A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections without completing the handshake and retain the connection-throttling slots indefinitely because no pre-authentication handshake deadline is enforced. By exhausting the global connection limit, an… | |
| Pendiente de análisis | Media (6.1) | 0.13% | — | Gnome ShellAI | 15/9/2026 | 16/9/2026 | A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to validate the icon's declared dimensions against the actual data buffer size. A malicious or compromised remote search provider could exploit this by providing oversized icon dimensions, leading to an… | |
| Pendiente de análisis | Alta (7) | 0.17% | — | Gnome GvfsAI | 10/9/2026 | 1/10/2026 | A flaw was found in the admin backend of gvfs. The privileged gvfsd-admin daemon changes the ownership of newly created private D-Bus sockets by calling the link-following chown() function on a pathname inside a user-controlled directory. A local attacker can exploit this via a Time-of-Check Time-of-Use (TOCTOU) race… | |
| Pendiente de análisis | Media (6.1) | 0.17% | — | Gnome Gdk-pixbufAI | 8/9/2026 | 14/9/2026 | A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This… | |
| Pendiente de análisis | Media (6.8) | 0.17% | — | Gnome TweaksAI | 8/9/2026 | 9/9/2026 | The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files outside ~/.themes by using ../ path traversal, absolute paths, or symlink entries. | |
| Pendiente de análisis | Media (5.9) | 0.32% | — | Gnome LibsoupAI | 4/9/2026 | 8/9/2026 | A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control window later allows. A malicious HTTP/2 server can shrink SETTINGS_INITIAL_WINDOW_SIZE while that buffered read is still in progress. The client then… | |
| Pendiente de análisis | Alta (7.6) | 0.27% | — | Gnome LibsoupAI | 4/9/2026 | 16/9/2026 | A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the-Middle (MITM) attacker can exploit a heap use-after-free vulnerability in the HTTP/2 client implementation. This occurs when a GNOME application uploads a file using HTTP/2, and the server sends a GOAWAY frame while the file body is being read… | |
| Pendiente de análisis | Media (4.3) | 0.22% | — | Gnome GvfsAI | 1/9/2026 | 2/9/2026 | A flaw was found in the MTP backend in gvfs. When reading a file from a mounted MTP device, do_read() in gvfsbackendmtp.c trusts the data length returned by the device without limiting it to the original size requested by the client. If a malicious MTP device responds with more bytes than requested, this unrestricted… | |
| Pendiente de análisis | Media (6.5) | 0.45% | — | Gnome GvfsAI | 1/9/2026 | 4/9/2026 | A flaw was found in the AFP backend in gvfs. When mounting a share, a malicious AFP server can cause the DSI read path to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the pre-sized reply buffer, causing the operation to access past the… | |
| Pendiente de análisis | Media (4.3) | 0.37% | — | Gnome GvfsAI | 1/9/2026 | 2/9/2026 | A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the function does not verify that the buffer is completely filled, leaving the remainder of the buffer containing uninitialized heap contents. If the… | |
| Pendiente de análisis | Alta (8.8) | 0.36% | — | Gnome GvfsAI | 1/9/2026 | 1/10/2026 | A flaw was found in the SFTP backend in gvfs. When mounting a share and reading a file, a malicious SFTP server can cause read_reply() to process a length that exceeds the size requested by the client. The function does not verify the server-provided length against the allocated buffer size, causing the operation to… | |
| Pendiente de análisis | Media (4.7) | 0.15% | — | Gnome Gdk-pixbufAI | 27/8/2026 | 28/8/2026 | A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the… | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Gnome LibsoupAI | 25/8/2026 | 28/8/2026 | An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 fix. CVE-2025-32907 addressed memory amplification when a client repeated the same range many times in a single Range header. Commit 9bb92f7a corrected merge correctness in… | |
| Pendiente de análisis | Media (5.4) | 0.34% | — | Gnome EpiphanyAI | 6/8/2026 | 28/8/2026 | A flaw was found in Epiphany. An issue in how the browser reads web addresses allows attackers to fake the domain name shown in the address bar. If a user clicks a specially crafted link containing a colon (for example, [https://trusted.com:80@attacker.com/](https://trusted.com:80@attacker.com/)), the address bar and… | |
| Pendiente de análisis | Alta (7.5) | 0.52% | — | Gnome Remote DesktopAIRedhat Enterprise LinuxAI | 31/7/2026 | 13/8/2026 | A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP… | |
| Analizada | Media (6.5) | 0.25% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header to subsequent HTTPS requests sent through that tunnel to the destination server. This allows the destination server to capture proxy credentials, leading to information… | |
| Analizada | Alta (7.2) | 0.28% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs violating RFC 9112, including leading whitespace, plus sign prefixes, and trailing invalid characters. When libsoup operates behind a strict frontend proxy, this parsing… | |
| Analizada | Media (6.5) | 0.38% | — | Gnome LibsoupRedhat Enterprise Linux | 24/7/2026 | 24/8/2026 | A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when parsing multipart HTTP responses. A malicious HTTP server can exploit this by sending a crafted multipart response, potentially causing the client application to crash or… | |
| Pendiente de análisis | Media (5.3) | 0.24% | — | Gnome Gdk-pixbufAI | 23/7/2026 | 31/7/2026 | A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and… | |
| Aplazada | Alta (7.1) | 0.16% | — | Linux-gaming PortprotonqtAIGnome NetworkmanagerAI | 23/7/2026 | 23/7/2026 | An Incorrect Authorization vulnerability in Linux-Gaming PortProtonQt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager. This issue affects PortProtonQt before 0d0f0950ebd948cdf82e8c3e1ebd2bcb9b8bafbe. | |
| Pendiente de análisis | Media (6.8) | 0.25% | — | Gnome LibrestAI | 22/7/2026 | 1/9/2026 | A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure pseudo-random number generator. Because the generated "code verifier" lacks sufficient cryptographic entropy, a malicious actor can reverse-engineer the pseudo-random… | |
| Analizada | Media (4.2) | 0.25% | — | Gnome LibsoupRedhat Enterprise Linux | 21/7/2026 | 24/8/2026 | A heap out-of-bounds read flaw was found in libsoup. When parsing multipart HTTP messages, an integer type mismatch between the caller and soup_headers_parse() can cause the length parameter to be incorrectly truncated, leading to a heap buffer over-read. A remote attacker could use this flaw to crash an application… | |
| Aplazada | Media (6.8) | 0.18% | — | Gnome EvinceAITUG TEX LiveAI | 21/7/2026 | 23/7/2026 | The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedded by downstream consumers such as GNOME Evince contains a heap use-after-free vulnerability that allows attackers to crash applications or potentially execute arbitrary code by supplying a malformed .synctex or .synctex.gz file. A malformed SyncTeX… | |
| Pendiente de análisis | Media (5.3) | 0.48% | — | Gnome GlibAI | 20/7/2026 | 6/10/2026 | A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending… |