Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2683▼ 54 respecto a la semana anterior
Críticas / altas1442▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.50%—Signalwire LibksAI11/9/202630/9/2026
libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization buffer can hold. The canonicalization step silently passes such URIs through with embedded ".."…
AplazadaAlta (7.1)0.55%—KDE LibksieveAI29/4/202417/6/2026
In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server logs because a username variable is accidentally given a password value.
ModificadaCrítica (9.8)1.6%—Gnupg LibksbaGpg4winGnupg Vs-desktopGnupg12/1/202317/6/2026
A vulnerability was found in the Libksba library due to an integer overflow within the CRL parser. The vulnerability can be exploited remotely for code execution on the target system by passing specially crafted data to the application, for example, a malicious S/MIME attachment.
ModificadaCrítica (9.8)1.6%—Gnupg LibksbaDebian Linux20/12/202217/6/2026
Libksba before 1.6.3 is prone to an integer overflow vulnerability in the CRL signature parser.
ModificadaAlta (7.5)3.2%—Gnupg LibksbaOpensuse LeapCanonical Ubuntu Linux13/6/201617/6/2026
Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via unspecified vectors, related to the "returned length of the object from _ksba_ber_parse_tl."
ModificadaAlta (7.5)2.8%—Gnupg LibksbaCanonical Ubuntu LinuxOpensuse LeapOpensuse13/6/201617/6/2026
Off-by-one error in the append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.4 allows remote attackers to cause a denial of service (out-of-bounds read) via invalid utf-8 encoded data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-4356.
ModificadaAlta (7.5)2.9%—Gnupg LibksbaCanonical Ubuntu Linux13/6/201617/6/2026
The append_utf8_value function in the DN decoder (dn.c) in Libksba before 1.3.3 allows remote attackers to cause a denial of service (out-of-bounds read) by clearing the high bit of the byte after invalid utf-8 encoded data.
ModificadaAlta (7.5)1.9%—Gnupg LibksbaCanonical Ubuntu Linux13/6/201617/6/2026
Multiple integer overflows in ber-decoder.c in Libksba before 1.3.3 allow remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
ModificadaAlta (7.5)1.9%—Canonical Ubuntu LinuxGnupg Libksba13/6/201617/6/2026
ber-decoder.c in Libksba before 1.3.3 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (crash) via crafted BER data, which leads to a buffer overflow.
ModificadaAlta (7.5)2.1%—Gnupg LibksbaCanonical Ubuntu Linux13/6/201617/6/2026
ber-decoder.c in Libksba before 1.3.3 does not properly handle decoder stack overflows, which allows remote attackers to cause a denial of service (abort) via crafted BER data.
ModificadaAlta (7.5)5.7%—MageiaDebian LinuxGnupg LibksbaCanonical Ubuntu Linux+11/12/201417/6/2026
Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow.
ModificadaMedia (5)1.9%—Libksba Library3/10/200616/6/2026
The libksba library 0.9.12 and possibly other versions, as used by gpgsm in the newpg package on SUSE LINUX, allows attackers to cause a denial of service (application crash) via a malformed X.509 certificate in a signature.