Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.35% | — | Nothings STB Image WriteAI | 29/9/2026 | 1/10/2026 | A flaw has been found in Nothings stb up to 1.16. This affects the function stbi_write_png_to_mem/stbi_write_jpg_core/stbi_write_tga_core in the library stb_image_write.h of the component Image Encoding. Executing a manipulation can lead to integer overflow. The attack can be executed remotely. The exploit has been… | |
| Aplazada | Media (5.5) | 0.35% | — | Nothings STBAI | 29/9/2026 | 2/10/2026 | A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit… | |
| Aplazada | Media (4) | 0.13% | — | Nothings STBAI | 9/9/2026 | 14/9/2026 | An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input. | |
| Aplazada | Media (4.3) | 0.40% | — | Nothings STBAI | 9/9/2026 | 14/9/2026 | An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted TTF file. | |
| Aplazada | Alta (7.1) | 0.19% | — | Nothings STB TruetypeAI | 7/8/2026 | 8/9/2026 | A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the nothings stb_truetype.h library when parsing malformed TTF (TrueType Font) files. The… | |
| Analizada | Baja (2.1) | 0.59% | — | Nothings STB Vorbis.c | 2/4/2026 | 17/6/2026 | A security flaw has been discovered in Nothings stb up to 1.22. This affects the function start_decoder of the file stb_vorbis.c. The manipulation results in out-of-bounds write. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The vendor was contacted… | |
| Analizada | Baja (2.1) | 0.72% | — | Nothings STB Vorbis.c | 2/4/2026 | 17/6/2026 | A vulnerability was identified in Nothings stb up to 1.22. The impacted element is the function setup_free of the file stb_vorbis.c. The manipulation leads to allocation of resources. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. The vendor was contacted early… | |
| Analizada | Baja (2.1) | 0.85% | — | Nothings STB Truetype.h | 2/4/2026 | 17/6/2026 | A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the library stb_truetype.h of the component TTF File Handler. Executing a manipulation can lead to out-of-bounds read. The attack can be executed remotely. The exploit has been publicly disclosed and may… | |
| Analizada | Baja (2.1) | 0.85% | — | Nothings STB Truetype.h | 1/4/2026 | 17/6/2026 | A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be… | |
| Aplazada | Baja (2.1) | 0.49% | — | Nothings STBAINothings STB ImageAI | 1/4/2026 | 17/6/2026 | A vulnerability has been found in Nothings stb up to 2.30. This issue affects the function stbi__gif_load_next in the library stb_image.h of the component GIF Decoder. Such manipulation leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The… | |
| Aplazada | Baja (1.9) | 0.16% | — | Nothings STBAI | 31/3/2026 | 17/6/2026 | A weakness has been identified in Nothings stb up to 2.30. This impacts the function stbi__load_gif_main of the file stb_image.h of the component Multi-frame GIF File Handler. This manipulation causes double free. The attack requires local access. The exploit has been made available to the public and could be used for… | |
| Aplazada | Baja (1.9) | 0.17% | — | Nothings STB ImageAI | 31/3/2026 | 17/6/2026 | A security flaw has been discovered in Nothings stb_image up to 2.30. This affects the function stbi__gif_load_next of the file stb_image.h of the component Multi-frame GIF File Handler. The manipulation results in heap-based buffer overflow. The attack requires a local approach. The exploit has been released to the… | |
| Analizada | Media (5.3) | 0.52% | — | Nothings STB Image.h | 8/4/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_include_string. The manipulation of the argument path_to_includes leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This product does not use versioning. This is why… | |
| Analizada | Media (5.3) | 0.50% | — | Nothings STB Image.h | 8/4/2025 | 17/6/2026 | A vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The manipulation leads to integer overflow. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version… | |
| Analizada | Media (5.3) | 0.47% | — | Nothings STB Image.h | 8/4/2025 | 17/6/2026 | A vulnerability was found in Nothings stb up to f056911. It has been declared as critical. Affected by this vulnerability is the function stbhw_build_tileset_from_image. The manipulation of the argument h_count/v_count leads to out-of-bounds read. The attack can be launched remotely. This product takes the approach of… | |
| Analizada | Media (5.3) | 0.58% | — | Nothings STB Image.h | 8/4/2025 | 17/6/2026 | A vulnerability was found in Nothings stb up to f056911. It has been classified as problematic. Affected is the function stbhw_build_tileset_from_image of the component Header Array Handler. The manipulation of the argument w leads to out-of-bounds read. It is possible to launch the attack remotely. This product is… | |
| Modificada | Crítica (9.8) | 1.4% | — | Nothings STB Vorbis.cFedoraproject Fedora | 1/5/2024 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability. | |
| Modificada | Media (6.5) | 1.0% | — | Nothings STB Image.h | 25/10/2023 | 17/6/2026 | Double Free vulnerability in Nothings Stb Image.h v.2.28 allows a remote attacker to cause a denial of service via a crafted file to the stbi_load_gif_main function. | |
| Modificada | Alta (7.1) | 0.56% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds read in `DECODE` macro when `var` is negative. As it can be seen in the definition of `DECODE_RAW` a negative `var` is a valid value. This issue may be used to leak internal memory allocation… | |
| Modificada | Alta (7.8) | 0.52% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory write past an allocated heap buffer in `start_decoder`. The root cause is a potential integer overflow in `sizeof(char*) * (f->comment_list_length)` which may make `setup_malloc` allocate less memory… | |
| Modificada | Media (5.5) | 0.53% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the function returns early, the `f->comment_list` is set to `NULL`, but `f->comment_list_length` is not reset. Later in `vorbis_deinit` it tries to… | |
| Modificada | Alta (7.8) | 0.52% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the function returns early, but some of the pointers in `f->comment_list` are left initialized and later `setup_free` is called on these pointers in… | |
| Modificada | Alta (7.8) | 0.73% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of buffer write in `start_decoder` because at maximum `m->submaps` can be 16 but `submap_floor` and `submap_residue` are declared as arrays of 15 elements. This issue may lead to code execution. | |
| Modificada | Alta (7.8) | 0.54% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in `f->vendor[len] = (char)'\0';`. The root cause is that if `len` read in `start_decoder` is a negative number and `setup_malloc` successfully allocates memory in that case, but memory… | |
| Modificada | Alta (7.8) | 0.52% | — | Nothings STB Vorbis.c | 21/10/2023 | 17/6/2026 | stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in `f->vendor[i] = get8_packet(f);`. The root cause is an integer overflow in `setup_malloc`. A sufficiently large value in the variable `sz` overflows with `sz+7` in and the negative value… |