Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2538▼ 400 respecto a la semana anterior
Críticas / altas1320▲ 39 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 1.0% | — | RpmuncompressAI | 2/9/2026 | 3/9/2026 | A flaw was found in rpmuncompress. This command injection vulnerability allows a local attacker to execute arbitrary commands. This occurs when rpmuncompress processes a specially crafted archive filename containing shell metacharacters, which are not properly escaped before being passed to shell command strings.… | |
| Aplazada | Alta (7.5) | 0.61% | — | Perl IO Uncompress UnzipAI | 27/5/2026 | 24/7/2026 | IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration. Extracting a named… | |
| Aplazada | Media (5.5) | 0.13% | — | Perl IO Uncompress UnzipAI | 27/5/2026 | 24/7/2026 | IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range… | |
| Modificada | Alta (7.5) | 5.8% | — | Ncompress | 14/8/2006 | 16/6/2026 | The decompress function in compress42.c in (1) ncompress 4.2.4 and (2) liblzw allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code, via crafted data that leads to a buffer underflow. | |
| Modificada | Baja (2.1) | 0.37% | — | Ncompress | 20/9/2005 | 16/6/2026 | ncompress 4.2.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files using (1) zdiff or (2) zcmp, a different vulnerability than CVE-2004-0970. | |
| Modificada | Alta (7.5) | 4.8% | — | Ncompress | 23/12/2004 | 16/6/2026 | Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument. |