Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2636▼ 212 respecto a la semana anterior
Críticas / altas1386▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

16 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.5)0.10%—Tcpdump LibpcapAI5/9/20268/9/2026
libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations. In particular uncommon use cases a crafted filter program can cause the interpreter to loop infinitely.
Pendiente de análisisMedia (5.5)0.15%—Tcpdump LibpcapAI5/9/20268/9/2026
libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero.
Pendiente de análisisMedia (5.5)0.10%—Tcpdump LibpcapAI5/9/20268/9/2026
libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter program can cause the interpreter to try…
Pendiente de análisisMedia (5.5)0.10%—Tcpdump LibpcapAI5/9/20268/9/2026
libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process.
Pendiente de análisisMedia (5)0.18%—Tcpdump LibpcapAI5/9/20268/9/2026
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet.
Pendiente de análisisAlta (8.7)0.11%—Tcpdump LibpcapAI5/9/20268/9/2026
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing…
AplazadaBaja (1.9)0.12%—Tcpdump LibpcapAI31/12/202517/6/2026
On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 bytes, utf_16le_to_utf_8_truncated() can write data beyond the end of the provided buffer.
AplazadaBaja (1.9)0.12%—Tcpdump LibpcapAI31/12/202517/6/2026
pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument…
AnalizadaMedia (4.4)0.24%—Tcpdump Libpcap31/8/202417/6/2026
Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions that become available is pcap_findalldevs_ex(). One of the function arguments can be a filesystem path, which normally means a directory with input data files.…
AnalizadaMedia (4.4)0.24%—Tcpdump Libpcap31/8/202417/6/2026
In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns. This makes it possible in…
ModificadaMedia (5.3)2.8%—Tcpdump LibpcapDebian LinuxOpensuse LeapOracle Communications Operations Monitor+73/10/201917/6/2026
sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory.
ModificadaMedia (5.3)2.9%—Tcpdump Libpcap3/10/201917/6/2026
rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source.
ModificadaAlta (7.5)4.4%—Tcpdump Libpcap3/10/201917/6/2026
rpcapd/daemon.c in libpcap before 1.9.1 allows attackers to cause a denial of service (NULL pointer dereference and daemon crash) if a crypt() call fails.
ModificadaMedia (5.3)1.8%—Tcpdump Libpcap3/10/201917/6/2026
rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames.
ModificadaMedia (5.3)2.8%—Tcpdump Libpcap3/10/201917/6/2026
rpcapd/daemon.c in libpcap before 1.9.1 mishandles certain length values because of reuse of a variable. This may open up an attack vector involving extra data at the end of a request.
ModificadaCrítica (9.8)3.6%—Tcpdump Libpcap20/10/201716/6/2026
pcap-linux.c in libpcap 1.1.1 before commit ea9432fabdf4b33cbc76d9437200e028f1c47c93 when snaplen is set may truncate packets, which might allow remote attackers to send arbitrary data while avoiding detection via crafted packets.