Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.4)0.57%—LibslirpAI22/9/202622/9/2026
A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service…
Pendiente de análisisMedia (6.5)0.22%—Freedesktop.org LibslirpAI24/6/202625/6/2026
An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environments (e.g., QEMU) allows a privileged guest VM attacker (root or CAP_NET_RAW) to leak gigabytes of sensitive host-process heap memory via sending…
ModificadaBaja (3.8)0.33%—Libslirp Project LibslirpRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora15/6/202117/6/2026
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory…
ModificadaBaja (3.8)0.33%—Libslirp Project LibslirpRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora15/6/202117/6/2026
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory…
ModificadaBaja (3.8)0.33%—Libslirp Project LibslirpRedhat Enterprise LinuxFedoraproject FedoraDebian Linux15/6/202117/6/2026
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory…
ModificadaBaja (3.8)0.33%—Libslirp Project LibslirpRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora15/6/202117/6/2026
An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized…
ModificadaMedia (4.3)1.9%—Libslirp Project LibslirpDebian LinuxFedoraproject Fedora26/11/202017/6/2026
slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
ModificadaMedia (4.3)1.5%—Libslirp Project LibslirpFedoraproject FedoraDebian Linux26/11/202017/6/2026
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
ModificadaMedia (6.5)0.51%—Libslirp Project LibslirpRedhat OpenstackRedhat Enterprise LinuxCanonical Ubuntu Linux+29/7/202017/6/2026
An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible…
ModificadaMedia (6.5)2.4%—Libslirp Project LibslirpFedoraproject FedoraDebian LinuxOpensuse Leap+122/4/202017/6/2026
A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
ModificadaMedia (5.6)2.5%—Libslirp Project LibslirpDebian LinuxOpensuse Leap6/2/202017/6/2026
In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code.
ModificadaAlta (7.5)4.3%—Libslirp Project LibslirpQemu21/1/202017/6/2026
tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows.
ModificadaMedia (5.6)3.6%—Libslirp Project LibslirpQemuDebian LinuxOpensuse Leap16/1/202017/6/2026
tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code.
ModificadaAlta (7.5)4.0%—Libslirp Project LibslirpQemu6/9/201917/6/2026
libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c.
ModificadaAlta (8.8)17%—Libslirp Project Libslirp29/7/201917/6/2026
ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment.