Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.4) | 0.57% | — | LibslirpAI | 22/9/2026 | 22/9/2026 | A heap-based buffer overflow was found in the DHCPv6 and TFTP response builders of libslirp. When the host is configured with a small interface MTU, a guest-supplied DHCPv6 CLIENTID option or TFTP blksize option can overflow the reply buffer with attacker-controlled content and length, resulting in denial of service… | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | Freedesktop.org LibslirpAI | 24/6/2026 | 25/6/2026 | An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environments (e.g., QEMU) allows a privileged guest VM attacker (root or CAP_NET_RAW) to leak gigabytes of sensitive host-process heap memory via sending… | |
| Modificada | Baja (3.8) | 0.33% | — | Libslirp Project LibslirpRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora | 15/6/2021 | 17/6/2026 | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the tftp_input() function and could occur while processing a udp packet that is smaller than the size of the 'tftp_t' structure. This issue may lead to out-of-bounds read access or indirect host memory… | |
| Modificada | Baja (3.8) | 0.33% | — | Libslirp Project LibslirpRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora | 15/6/2021 | 17/6/2026 | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory… | |
| Modificada | Baja (3.8) | 0.33% | — | Libslirp Project LibslirpRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 15/6/2021 | 17/6/2026 | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the udp6_input() function and could occur while processing a udp packet that is smaller than the size of the 'udphdr' structure. This issue may lead to out-of-bounds read access or indirect host memory… | |
| Modificada | Baja (3.8) | 0.33% | — | Libslirp Project LibslirpRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora | 15/6/2021 | 17/6/2026 | An invalid pointer initialization issue was found in the SLiRP networking implementation of QEMU. The flaw exists in the bootp_input() function and could occur while processing a udp packet that is smaller than the size of the 'bootp_t' structure. A malicious guest could use this flaw to leak 10 bytes of uninitialized… | |
| Modificada | Media (4.3) | 1.9% | — | Libslirp Project LibslirpDebian LinuxFedoraproject Fedora | 26/11/2020 | 17/6/2026 | slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. | |
| Modificada | Media (4.3) | 1.5% | — | Libslirp Project LibslirpFedoraproject FedoraDebian Linux | 26/11/2020 | 17/6/2026 | ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. | |
| Modificada | Media (6.5) | 0.51% | — | Libslirp Project LibslirpRedhat OpenstackRedhat Enterprise LinuxCanonical Ubuntu Linux+2 | 9/7/2020 | 17/6/2026 | An out-of-bounds read vulnerability was found in the SLiRP networking implementation of the QEMU emulator. This flaw occurs in the icmp6_send_echoreply() routine while replying to an ICMP echo request, also known as ping. This flaw allows a malicious guest to leak the contents of the host memory, resulting in possible… | |
| Modificada | Media (6.5) | 2.4% | — | Libslirp Project LibslirpFedoraproject FedoraDebian LinuxOpensuse Leap+1 | 22/4/2020 | 17/6/2026 | A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service. | |
| Modificada | Media (5.6) | 2.5% | — | Libslirp Project LibslirpDebian LinuxOpensuse Leap | 6/2/2020 | 17/6/2026 | In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code. | |
| Modificada | Alta (7.5) | 4.3% | — | Libslirp Project LibslirpQemu | 21/1/2020 | 17/6/2026 | tftp.c in libslirp 4.1.0, as used in QEMU 4.2.0, does not prevent ..\ directory traversal on Windows. | |
| Modificada | Media (5.6) | 3.6% | — | Libslirp Project LibslirpQemuDebian LinuxOpensuse Leap | 16/1/2020 | 17/6/2026 | tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead to a DoS or potential execute arbitrary code. | |
| Modificada | Alta (7.5) | 4.0% | — | Libslirp Project LibslirpQemu | 6/9/2019 | 17/6/2026 | libslirp 4.0.0, as used in QEMU 4.1.0, has a use-after-free in ip_reass in ip_input.c. | |
| Modificada | Alta (8.8) | 17% | — | Libslirp Project Libslirp | 29/7/2019 | 17/6/2026 | ip_reass in ip_input.c in libslirp 4.0.0 has a heap-based buffer overflow via a large packet because it mishandles a case involving the first fragment. |