Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.8%—Feep LibtarOpenatom OpeneulerFedoraproject Fedora10/8/202217/6/2026
The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.
ModificadaAlta (7.5)1.8%—Feep LibtarOpenatom OpeneulerFedoraproject Fedora10/8/202217/6/2026
The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.
ModificadaAlta (8.1)1.4%—Feep LibtarOpenatom OpeneulerFedoraproject Fedora10/8/202217/6/2026
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read.
ModificadaCrítica (9.1)1.7%—Feep LibtarOpenatom OpeneulerFedoraproject Fedora10/8/202223/6/2026
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.
ModificadaMedia (5.8)3.3%—Feep Libtar20/2/201416/6/2026
Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.
ModificadaMedia (6.8)5.5%—Redhat Enterprise LinuxFeep Libtar17/10/201316/6/2026
Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in an archive, which triggers a heap-based buffer overflow.