Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2630▼ 215 respecto a la semana anterior
Críticas / altas1379▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.36% | — | Libjpeg-turboAI | 26/8/2026 | 9/9/2026 | libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexed-color PNG image with a non-gray palette through tj3LoadImage12() or tj3LoadImage16() using the default pixel format, the application may trigger a division-by-zero in alloc_sarray(), causing a… | |
| Aplazada | Media (6.9) | 0.36% | — | Libjpeg-turboAINeka-nat CupochAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in neka-nat cupoch (third_party/libjpeg-turbo/libjpeg-turbo modules). This vulnerability is associated with program files tjbench.C. This issue affects cupoch. | |
| Modificada | Alta (7.1) | 0.82% | — | Libjpeg-turboFedoraproject Fedora | 22/8/2023 | 17/6/2026 | libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c. | |
| Modificada | Media (6.5) | 0.59% | — | Libjpeg | 13/7/2023 | 17/6/2026 | libjpeg commit db33a6e was discovered to contain a heap buffer overflow via LineBitmapRequester::EncodeRegion at linebitmaprequester.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (6.5) | 0.59% | — | Libjpeg | 13/7/2023 | 17/6/2026 | libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (6.5) | 1.2% | — | Libjpeg-turbo | 25/5/2023 | 17/6/2026 | A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision for which the range of the sample data type exceeds the valid sample range, hence, an attacker could craft a 12-bit… | |
| Modificada | Media (5.5) | 0.28% | — | Libjpeg-turbo | 31/8/2022 | 17/6/2026 | A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo. | |
| Modificada | Media (6.5) | 0.73% | — | Libjpeg | 18/8/2022 | 17/6/2026 | libjpeg commit 281daa9 was discovered to contain a segmentation fault via LineMerger::GetNextLowpassLine at linemerger.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Media (6.5) | 0.73% | — | Libjpeg | 18/8/2022 | 17/6/2026 | libjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file. | |
| Modificada | Alta (7.5) | 1.0% | — | Libjpeg | 18/8/2022 | 17/6/2026 | libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer. | |
| Modificada | Media (5.5) | 0.29% | — | Libjpeg | 18/8/2022 | 17/6/2026 | libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal. | |
| Modificada | Media (5.5) | 1.1% | — | Libjpeg-turbo | 18/6/2022 | 17/6/2026 | The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c. | |
| Modificada | Media (6.5) | 0.88% | — | Libjpeg | 10/6/2022 | 17/6/2026 | There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan. | |
| Modificada | Media (5.5) | 0.70% | — | Libjpeg Project Libjpeg | 2/6/2022 | 17/6/2026 | In libjpeg 1.63, there is a NULL pointer dereference in LineBuffer::FetchRegion in linebuffer.cpp. | |
| Modificada | Media (5.5) | 0.71% | — | Libjpeg Project Libjpeg | 2/6/2022 | 17/6/2026 | In libjpeg 1.63, there is a NULL pointer dereference in Component::SubXOf in component.hpp. | |
| Modificada | Media (6.5) | 0.92% | — | Libjpeg | 2/6/2022 | 17/6/2026 | libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use. | |
| Modificada | Media (6.5) | 1.4% | — | Libjpeg Project Libjpeg | 25/5/2022 | 17/6/2026 | In libjpeg before 1.64, BitStream<false>::Get in bitstream.hpp has an assertion failure that may cause denial of service. This is related to out-of-bounds array access during arithmetically coded lossless scan or arithmetically coded sequential scan. | |
| Modificada | Media (6.5) | 0.86% | — | Libjpeg | 20/9/2021 | 17/6/2026 | An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PushReconstructedData() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service. | |
| Modificada | Media (6.5) | 0.87% | — | Libjpeg | 20/9/2021 | 17/6/2026 | An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PullQData() located in blockbitmaprequester.cpp It allows an attacker to cause Denial of Service. | |
| Modificada | Media (6.5) | 0.87% | — | Libjpeg | 20/9/2021 | 17/6/2026 | An issue was discovered in libjpeg through 2020021. LineBuffer::FetchRegion() in linebuffer.cpp has a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 0.86% | — | Libjpeg | 20/9/2021 | 17/6/2026 | An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::ReconstructUnsampled() located in blockbitmaprequester.cpp. It allows an attacker to cause Denial of Service. | |
| Modificada | Media (6.5) | 0.85% | — | Libjpeg | 20/9/2021 | 17/6/2026 | An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function HuffmanDecoder::Get() located in huffmandecoder.hpp. It allows an attacker to cause Denial of Service. | |
| Modificada | Media (6.5) | 0.86% | — | Libjpeg | 20/9/2021 | 17/6/2026 | An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function SampleInterleavedLSScan::ParseMCU() located in sampleinterleavedlsscan.cpp. It allows an attacker to cause Denial of Service. | |
| Modificada | Media (6.5) | 0.85% | — | Libjpeg | 20/9/2021 | 17/6/2026 | An issue was discovered in libjpeg through 2020021. An uncaught floating point exception in the function ACLosslessScan::ParseMCU() located in aclosslessscan.cpp. It allows an attacker to cause Denial of Service. | |
| Modificada | Alta (8.8) | 2.7% | — | Libjpeg-turbo | 1/6/2021 | 17/6/2026 | Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service. |