Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2493▼ 464 respecto a la semana anterior
Críticas / altas1281▼ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.2%—Polipo Project Polipo12/8/202117/6/2026
Polipo through 1.1.1, when NDEBUG is used, allows a heap-based buffer overflow during parsing of a Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaAlta (7.5)1.9%—Polipo Project Polipo15/7/202117/6/2026
Polipo through 1.1.1, when NDEBUG is omitted, allows denial of service via a reachable assertion during parsing of a malformed Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaAlta (7.5)11%—Polipo Project PolipoDebian Linux26/11/201916/6/2026
Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.
ModificadaMedia (5)8.7%—Pps.jussieu Polipo24/12/200916/6/2026
The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a large Content-Length value, which triggers an integer overflow, a signed-to-unsigned conversion error with a negative value, and…
ModificadaMedia (5)10%—Pps.jussieu Polipo24/12/200916/6/2026
Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors.
ModificadaMedia (5)1.2%—Pps.jussieu Polipo9/9/200916/6/2026
Unspecified vulnerability in Polipo before 1.0.4 allows remote attackers to cause a denial of service (crash) via a long request URL.
ModificadaMedia (4.3)1.1%—Polipo31/8/200716/6/2026
Polipo before 1.0.2 allows remote HTTP servers to cause a denial of service (daemon crash) by aborting the response to a POST request.
ModificadaMedia (5)1.2%—Polipo31/8/200716/6/2026
Unspecified vulnerability in Polipo before 1.0.2 allows remote attackers to cause a denial of service (daemon crash) via certain network traffic associated with entities larger than 2 Gb.
ModificadaMedia (5)1.3%—Polipo6/10/200516/6/2026
Unspecified vulnerability in Polipo 0.9.8 and earlier allows attackers to read files outside of the web root.