Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2577▼ 311 respecto a la semana anterior
Críticas / altas1352▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.9) | 0.25% | — | Sony Xav-9500esAIGpsdAI | 20/8/2026 | 31/8/2026 | Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling… | |
| Aplazada | Alta (8.5) | 0.27% | — | GpsdAIGnuplotAI | 23/7/2026 | 30/7/2026 | gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot… | |
| Analizada | Alta (8.4) | 2.9% | — | Gpsd Project Gpsd | 9/7/2026 | 14/7/2026 | gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from… | |
| Modificada | Alta (7.5) | 0.56% | — | Gpsd Project Gpsd | 2/1/2026 | 15/7/2026 | An integer underflow vulnerability exists in the `nextstate()` function in `gpsd/packet.c` of gpsd versions prior to commit `ffa1d6f40bca0b035fc7f5e563160ebb67199da7`. When parsing a NAVCOM packet, the payload length is calculated using `lexer->length = (size_t)c - 4` without checking if the input byte `c` is less… | |
| Modificada | Crítica (9.8) | 0.79% | — | Gpsd Project Gpsd | 2/1/2026 | 15/7/2026 | gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file. The hnd_129540 function, which handles NMEA2000 PGN 129540 (GNSS Satellites in View) packets, fails to validate the user-supplied satellite count against the size of the skyview array (184… | |
| Modificada | Alta (7.5) | 1.2% | — | Gpsd Project Gpsd | 5/12/2023 | 17/6/2026 | An integer underflow vulnerability exists in the NTRIP Stream Parsing functionality of GPSd 3.25.1~dev. A specially crafted network packet can lead to memory corruption. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 2.7% | — | Gpsd Project GpsdMicrojson Project MicrojsonDebian Linux | 13/3/2019 | 17/6/2026 | gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary code on embedded platforms via traffic on Port 2947/TCP or crafted JSON inputs. | |
| Modificada | Media (4.3) | 4.2% | — | Gpsd Project GpsdCanonical Ubuntu Linux | 6/2/2014 | 16/6/2026 | The NMEA0183 driver in gpsd before 3.9 allows remote attackers to cause a denial of service (daemon termination) and possibly execute arbitrary code via a GPS packet with a malformed $GPGGA interpreted sentence that lacks certain fields and a terminator. NOTE: a separate issue in the AIS driver was also reported, but… | |
| Modificada | Alta (7.6) | 1.2% | — | Gpsdrive | 22/12/2008 | 16/6/2026 | src/unit_test.c in gpsdrive (aka gpsdrive-scripts) 2.10~pre4 might allow local users to overwrite arbitrary files via a symlink attack on the /tmp/gpsdrive-unit-test/proc temporary file, a different vector than CVE-2008-4959 and CVE-2008-5380. | |
| Modificada | Media (6.2) | 0.30% | — | Gpsdrive | 22/12/2008 | 16/6/2026 | gpsdrive (aka gpsdrive-scripts) 2.10~pre4 allows local users to overwrite arbitrary files via a symlink attack on the (a) /tmp/.smswatch or (b) /tmp/gpsdrivepos temporary file, related to (1) examples/gpssmswatch and (2) src/splash.c, different vectors than CVE-2008-4959 and CVE-2008-5380. | |
| Modificada | Media (6.9) | 0.30% | — | Gpsdrive | 8/12/2008 | 16/6/2026 | gpsdrive (aka gpsdrive-scripts) 2.09 allows local users to overwrite arbitrary files via a symlink attack on an (a) /tmp/geo#####, a (b) /tmp/geocaching.loc, a (c) /tmp/geo#####.*, or a (d) /tmp/geo.* temporary file, related to the (1) geo-code and (2) geo-nearest scripts, different vectors than CVE-2008-4959. | |
| Modificada | Media (6.9) | 0.45% | — | Gpsdrive-scripts | 5/11/2008 | 16/6/2026 | geo-code in gpsdrive-scripts 2.10~pre4 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/geo.google, (2) /tmp/geo.yahoo, (3) /tmp/geo.coords, and (4) /tmp/geo#####.coords temporary files. | |
| Modificada | Alta (7.5) | 8.7% | — | Gpsdrive | 7/11/2005 | 16/6/2026 | Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field. |