Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 307 respecto a la semana anterior
Críticas / altas1348▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)0.52%—Owntone ServerAI22/4/202614/7/2026
OwnTone Server versions 28.4 through 29.0 contain a race condition vulnerability in the DAAP login handler that allows unauthenticated attackers to crash the server by exploiting unsynchronized access to the global DAAP session list. Attackers can flood the DAAP /login endpoint with concurrent requests to trigger a…
AplazadaMedia (6.9)0.43%—Owntone ServerAI22/4/202614/7/2026
OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions by supplying malicious values through the query= and filter= parameters for integer-mapped DAAP fields. Attackers can exploit insufficient…
AplazadaCrítica (9.8)0.34%—Owntone-serverAI10/4/202617/6/2026
owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.
AplazadaAlta (7.5)1.6%—Owntone-serverAI23/3/202617/6/2026
A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allows attackers to cause a Denial of Service (DoS) via sending a series of crafted HTTP requests to the server.
AplazadaAlta (7.5)0.61%—Owntone-serverAI23/3/202617/6/2026
A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652d allows attackers to cause a Denial of Service (DoS) via sending a crafted DAAP request to the server
AnalizadaAlta (7.5)0.38%—Owntone Server20/1/202617/6/2026
A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e385f allows attackers to cause a Denial of Service (DoS) via sending a crafted DACP request to the server.
AnalizadaAlta (7.5)0.41%—Owntone Server20/1/202617/6/2026
A NULL pointer dereference in the parse_meta function (src/httpd_daap.c) of owntone-server commit 334beb allows attackers to cause a Denial of Service (DoS) via sending a crafted DAAP request to the server.
AnalizadaAlta (7.5)0.50%—Owntone Server20/1/202617/6/2026
NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through commit 6d604a1 (newer commit after version 28.12) allows remote attackers to cause a Denial of Service (crash).
AnalizadaAlta (7.5)0.39%—Owntone Server20/1/202617/6/2026
NULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a (newer commit after version 28.2) allows remote attackers to cause a Denial of Service.
ModificadaCrítica (9.8)1.2%—Owntone Server10/8/202117/6/2026
OwnTone (aka owntone-server) through 28.1 has a use-after-free in net_bind() in misc.c.