Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.29% | — | MinttyAI | 12/11/2025 | 17/6/2026 | Mintty is a terminal emulator for Cygwin, MSYS, and WSL. In versions 2.3.6 through 3.7.4, several escape sequences can cause the mintty process to access a file in a specific path. It is triggered by simply printing them out on bash. An attacker can specify an arbitrary network path, negotiate an ntlm hash out of the… | |
| Analizada | Alta (8.8) | 0.97% | — | Mintty Project Mintty | 11/2/2025 | 17/6/2026 | Mintty Sixel Image Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Mintty. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Modificada | Crítica (9.8) | 1.0% | — | Mintty Project Mintty | 26/10/2023 | 17/6/2026 | An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via crafted commands to the terminal. | |
| Modificada | Crítica (9.8) | 1.1% | — | Mintty Project Mintty | 19/10/2023 | 17/6/2026 | Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to the terminal. | |
| Modificada | Alta (7.5) | 0.91% | — | Mintty Project Mintty | 6/6/2021 | 17/6/2026 | Mintty before 3.4.7 mishandles Bracketed Paste Mode. | |
| Modificada | Alta (7.5) | 1.6% | — | Mintty Project Mintty | 3/6/2021 | 17/6/2026 | Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. In other words, it does not implement a usleep or similar delay upon processing a title… |