Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.48% | — | JV Harfbuzz\ | 19/1/2026 | 17/6/2026 | HarfBuzz::Shaper versions before 0.032 for Perl contains a bundled library with a null pointer dereference vulnerability. Versions before 0.032 contain HarfBuzz 8.4.0 or earlier bundled as hb_src.tar.gz in the source tarball, which is affected by CVE-2026-22693. | |
| Analizada | Media (5.3) | 0.44% | — | Harfbuzz Project Harfbuzz | 10/1/2026 | 17/6/2026 | HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer… | |
| Analizada | Crítica (9.3) | 0.66% | — | Harfbuzz Project Harfbuzz | 27/12/2024 | 25/6/2026 | HarfBuzz is a text shaping engine. Starting with 8.5.0 through 10.0.1, there is a heap-based buffer overflow in the hb_cairo_glyphs_from_buffer function. | |
| Modificada | Alta (7.5) | 1.8% | — | Harfbuzz Project HarfbuzzFedoraproject Fedora | 4/2/2023 | 17/6/2026 | hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks. | |
| Modificada | Media (5.5) | 1.2% | — | Harfbuzz Project HarfbuzzFedoraproject Fedora | 23/6/2022 | 17/6/2026 | An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors. | |
| Modificada | Media (6.5) | 1.8% | — | Harfbuzz Project HarfbuzzFedoraproject Fedora | 1/1/2022 | 17/6/2026 | HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy). | |
| Modificada | Media (6.5) | 1.5% | — | Harfbuzz Project Harfbuzz | 15/11/2018 | 17/6/2026 | HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-table.hh, hb-ot-layout-gsub-table.hh, and hb-ot-layout-gsubgpos-private.hh. | |
| Modificada | Alta (7.6) | 2.6% | — | Harfbuzz Project Harfbuzz | 19/7/2016 | 17/6/2026 | hb-ot-layout-gpos-table.hh in HarfBuzz before 1.0.5 allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted data, a different vulnerability than CVE-2016-2052. | |
| Modificada | Alta (7.6) | 0.96% | — | Harfbuzz Project HarfbuzzGoogle Chrome | 25/1/2016 | 17/6/2026 | Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from an inverted length check in hb-ot-font.cc, a different issue… |