Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (2.1) | 0.59% | — | Artifex MupdfAI | 16/9/2026 | 18/9/2026 | A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation can lead to null pointer dereference. The attack can be launched remotely. The… | |
| Pendiente de análisis | Alta (7.1) | 0.32% | — | PymupdfAI | 14/9/2026 | 24/9/2026 | PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_objects() in src/__main__.py, where the output filename is constructed by joining a document-controlled BaseFont name directly onto the user-supplied output directory without stripping path separators… | |
| Analizada | Alta (7.1) | 0.58% | — | Artifex Mupdf | 23/6/2026 | 30/9/2026 | MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in… | |
| Modificada | Baja (1.9) | 0.19% | — | Artifex Mupdf | 28/4/2026 | 17/6/2026 | A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be… | |
| Analizada | Media (4.8) | 0.19% | — | Artifex Mupdf | 16/4/2026 | 17/6/2026 | MuPDF before 1.27 contains an ANSI injection vulnerability in mutool that allows attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata fields. Attackers can embed malicious ANSI escape codes in PDF metadata that are passed unsanitized to terminal output when running mutool info, enabling… | |
| Pendiente de análisis | Alta (7.8) | 0.20% | — | Artifex MupdfAI | 31/3/2026 | 25/7/2026 | An integer overflow vulnerability in 'pdf-image.c' in Artifex's MuPDF version 1.27.0 allows an attacker to maliciously craft a PDF that can trigger an integer overflow within the 'pdf_load_image_imp' function. This allows a heap out-of-bounds write that could be exploited for arbitrary code execution. | |
| Pendiente de análisis | Alta (7.5) | 0.41% | — | PymupdfAI | 19/3/2026 | 15/7/2026 | A path traversal and arbitrary file write vulnerability exist in the embedded get function in '_main_.py' in PyMuPDF version, 1.26.5. | |
| Aplazada | Alta (7.3) | 0.12% | — | Artifex MupdfAI | 10/2/2026 | 17/6/2026 | A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path. The attack requires local access. The attack is considered to have high complexity. The exploitability is regarded… | |
| Analizada | Media (5.9) | 0.70% | — | Artifex Mupdf | 6/2/2026 | 14/7/2026 | MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly drops the pixmap in its error handling path before rethrowing the exception.… | |
| Analizada | Alta (7.5) | 0.43% | — | Artifex Mupdf | 23/9/2025 | 17/6/2026 | A null pointer dereference occurs in the function break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a malformed EPUB document. Specifically, the function calls fz_html_split_flow() to split a FLOW_WORD node, but does not check if node->next is valid before accessing node->next->overflow_wrap, resulting in… | |
| Modificada | Media (6.5) | 0.41% | — | Artifex Mupdf | 4/8/2025 | 5/7/2026 | An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion | |
| Analizada | Media (5.5) | 0.32% | — | Artifex Mupdf | 10/12/2024 | 17/6/2026 | Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. | |
| Modificada | Alta (7.5) | 1.1% | — | Artifex Mupdf | 5/2/2024 | 17/6/2026 | freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function. | |
| Modificada | Alta (7.5) | 1.1% | — | Artifex Mupdf | 5/2/2024 | 17/6/2026 | freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function. | |
| Modificada | Alta (7.5) | 0.71% | — | Artifex Mupdf | 26/12/2023 | 17/6/2026 | A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in functon compute_color() of jquant2.c. NOTE: this is disputed by the supplier because there was not reasonable evidence to determine the existence of a vulnerability or identify the affected product. | |
| Modificada | Alta (7.5) | 0.71% | — | Artifex Mupdf | 26/12/2023 | 17/6/2026 | A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function pnm_binary_read_image() of load-pnm.c when fz_colorspace_n returns zero. | |
| Modificada | Alta (7.5) | 0.91% | — | Artifex Mupdf | 26/12/2023 | 17/6/2026 | A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function bmp_decompress_rle4() of load-bmp.c. | |
| Modificada | Alta (7.5) | 0.91% | — | Artifex Mupdf | 26/12/2023 | 17/6/2026 | A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnm_binary_read_image() of load-pnm.c when span equals zero. | |
| Modificada | Alta (7.5) | 0.91% | — | Artifex Mupdf | 26/12/2023 | 17/6/2026 | A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_pixmap_from_float_data() of pixmap.c. | |
| Modificada | Media (5.5) | 0.23% | — | Artifex Mupdf | 31/10/2023 | 17/6/2026 | MuPDF v1.21.1 was discovered to contain an infinite recursion in the component pdf_mark_list_push. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. | |
| Modificada | Media (5.5) | 0.31% | — | Artifex Mupdf | 22/8/2023 | 17/6/2026 | A memory leak issue discovered in /pdf/pdf-font-add.c in Artifex Software MuPDF 1.17.0 allows attackers to obtain sensitive information. | |
| Modificada | Media (5.5) | 0.51% | — | Artifex Mupdf | 22/8/2023 | 17/6/2026 | A Use After Free vulnerability in svg_dev_text_span_as_paths_defs function in source/fitz/svg-device.c in Artifex Software MuPDF 1.16.0 allows remote attackers to cause a denial of service via opening of a crafted PDF file. | |
| Modificada | Media (5.5) | 0.24% | — | Artifex Mupdf | 26/8/2022 | 17/6/2026 | A Floating point exception (division-by-zero) flaw was found in Mupdf for zero width pages in muraster.c. It is fixed in Mupdf-1.20.0-rc1 upstream. | |
| Modificada | Media (5.5) | 1.3% | — | Artifex MupdfFedoraproject Fedora | 21/7/2021 | 17/6/2026 | MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input. | |
| Modificada | Media (5.5) | 1.0% | — | Artifex MupdfDebian Linux | 21/7/2021 | 17/6/2026 | Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service. |