Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.29%—MinttyAI12/11/202517/6/2026
Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can cause the mintty process to access a file in a specific path. It is triggered by simply printing them out on bash. An attacker can specify an arbitrary network path, negotiate an ntlm hash out of the…
AnalizadaAlta (8.8)0.97%—Mintty Project Mintty11/2/202517/6/2026
Mintty Sixel Image Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mintty. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a…
ModificadaCrítica (9.8)1.0%—Mintty Project Mintty26/10/202317/6/2026
An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal.
ModificadaCrítica (9.8)1.1%—Mintty Project Mintty19/10/202317/6/2026
Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal.
ModificadaAlta (7.5)0.91%—Mintty Project Mintty6/6/202117/6/2026
Mintty before 3.4.7 mishandles Bracketed Paste Mode.
ModificadaAlta (7.5)1.6%—Mintty Project Mintty3/6/202117/6/2026
Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. In other words, it does not implement a usleep or similar delay upon processing a title…