Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.9) | 0.56% | — | GNU Gzip | 29/6/2026 | 27/8/2026 | GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not… | |
| Analizada | Baja (2) | 0.14% | — | GNU Gzip | 29/6/2026 | 1/7/2026 | GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or… | |
| Pendiente de análisis | Crítica (9.1) | 0.76% | — | Python LzmaAIPython BZ2AIPython GzipAIPython ZlibAI | 13/4/2026 | 13/8/2026 | Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in… | |
| Modificada | Alta (8.8) | 5.1% | — | GNU GzipRedhat Jboss Data GridDebian LinuxTukaani XZ | 31/8/2022 | 17/6/2026 | An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insufficient validation when processing… | |
| Modificada | Media (6.8) | 4.8% | — | GNU Gzip | 29/1/2010 | 16/6/2026 | Integer underflow in the unlzw function in unlzw.c in gzip before 1.4 on 64-bit platforms, as used in ncompress and probably others, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted archive that uses LZW compression, leading to an array index… | |
| Modificada | Media (6.8) | 4.2% | — | GNU Gzip | 29/1/2010 | 16/6/2026 | The huft_build function in inflate.c in gzip before 1.3.13 creates a hufts (aka huffman) table that is too small, which allows remote attackers to cause a denial of service (application crash or infinite loop) or possibly execute arbitrary code via a crafted archive. NOTE: this issue is caused by a CVE-2006-4334… | |
| Modificada | Alta (7.5) | 6.0% | — | Gzip | 19/9/2006 | 16/6/2026 | Buffer overflow in the make_table function in the LHZ component in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted decoding table in a GZIP archive. | |
| Modificada | Media (5) | 3.8% | — | Gzip | 19/9/2006 | 16/6/2026 | unlzh.c in the LHZ component in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (infinite loop) via a crafted GZIP archive. | |
| Modificada | Alta (7.5) | 5.8% | — | Gzip | 19/9/2006 | 16/6/2026 | Array index error in the make_table function in unlzh.c in the LZH decompression component in gzip 1.3.5, when running on certain platforms, allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GZIP archive that triggers an out-of-bounds write, aka a… | |
| Modificada | Alta (7.5) | 5.9% | — | Gzip | 19/9/2006 | 16/6/2026 | Buffer underflow in the build_tree function in unpack.c in gzip 1.3.5 allows context-dependent attackers to execute arbitrary code via a crafted leaf count table that causes a write to a negative index. | |
| Modificada | Media (5) | 4.1% | — | Gzip | 19/9/2006 | 16/6/2026 | Unspecified vulnerability in gzip 1.3.5 allows context-dependent attackers to cause a denial of service (crash) via a crafted GZIP (gz) archive, which results in a NULL dereference. | |
| Modificada | Media (5) | 1.4% | — | Tugzip | 11/4/2006 | 16/6/2026 | Multiple directory traversal vulnerabilities in Christian Kindahl TUGZip 3.4.0.0, 3.3.0.0, and 3.1.0.2 allow user-assisted attackers to create files in arbitrary directories via a .. (dot dot) in an archive pack with a crafted (1) .gz, (2) .jar, (3) .rar, or (4) .zip file. | |
| Modificada | Alta (7.5) | 4.5% | — | Tugzip | 31/12/2005 | 16/6/2026 | Stack-based buffer overflow in TUGZip 3.4.0.0 allows remote attackers to execute arbitrary code via a long filename in an ARJ archive. | |
| Modificada | Media (4.6) | 0.53% | — | GNU GzipCanonical Ubuntu Linux | 13/5/2005 | 16/6/2026 | zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script. | |
| Modificada | Media (5) | 3.6% | — | GNU Gzip | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file. | |
| Modificada | Baja (3.7) | 0.66% | — | GNU GzipFreebsdGentoo LinuxRedhat Enterprise Linux+9 | 2/5/2005 | 16/6/2026 | Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete. | |
| Modificada | Baja (2.1) | 0.36% | — | GNU Gzip | 9/2/2005 | 16/6/2026 | The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367. | |
| Modificada | Alta (10) | 3.1% | — | GNU Gzip | 6/12/2004 | 16/6/2026 | gzexe in gzip 1.3.3 and earlier will execute an argument when the creation of a temp file fails instead of exiting the program, which could allow remote attackers or local users to execute arbitrary commands, a different vulnerability than CVE-1999-1332. | |
| Modificada | Baja (2.1) | 0.59% | — | GNU GzipOracle Solaris | 4/10/2004 | 16/6/2026 | gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files. | |
| Modificada | Alta (7.5) | 2.3% | — | DAG APT Repository MOD Gzip | 17/11/2003 | 16/6/2026 | Format string vulnerability in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode and using the Apache log, allows remote attackers to execute arbitrary code via format string characters in an HTTP GET request with an "Accept-Encoding: gzip" header. | |
| Modificada | Alta (7.1) | 0.32% | — | Schroepl MOD Gzip | 17/11/2003 | 16/6/2026 | mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode without the Apache log, allows local users to overwrite arbitrary files via (1) a symlink attack on predictable temporary filenames on Unix systems, or (2) an NTFS hard link on Windows systems when the "Strengthen default… | |
| Modificada | Alta (7.5) | 3.6% | — | DAG APT Repository MOD Gzip | 17/11/2003 | 16/6/2026 | Stack-based buffer overflow in mod_gzip_printf for mod_gzip 1.3.26.1a and earlier, and possibly later official versions, when running in debug mode, allows remote attackers to execute arbitrary code via a long filename in a GET request with an "Accept-Encoding: gzip" header. | |
| Modificada | Baja (2.1) | 0.44% | — | GNU GzipDebian Linux | 2/7/2003 | 16/6/2026 | znew in the gzip package allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 3.1% | — | GNU Gzip | 18/11/2001 | 16/6/2026 | Buffer overflows in gzip 1.3x, 1.2.4, and other versions might allow attackers to execute code via a long file name, possibly remotely if gzip is run on an FTP server. |