Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2493▼ 464 respecto a la semana anterior
Críticas / altas1281▼ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Polipo Project Polipo | 12/8/2021 | 17/6/2026 | Polipo through 1.1.1, when NDEBUG is used, allows a heap-based buffer overflow during parsing of a Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Alta (7.5) | 1.9% | — | Polipo Project Polipo | 15/7/2021 | 17/6/2026 | Polipo through 1.1.1, when NDEBUG is omitted, allows denial of service via a reachable assertion during parsing of a malformed Range header. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Alta (7.5) | 11% | — | Polipo Project PolipoDebian Linux | 26/11/2019 | 16/6/2026 | Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request. | |
| Modificada | Media (5) | 8.7% | — | Pps.jussieu Polipo | 24/12/2009 | 16/6/2026 | The httpClientDiscardBody function in client.c in Polipo 0.9.8, 0.9.12, 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a large Content-Length value, which triggers an integer overflow, a signed-to-unsigned conversion error with a negative value, and… | |
| Modificada | Media (5) | 10% | — | Pps.jussieu Polipo | 24/12/2009 | 16/6/2026 | Polipo 1.0.4, and possibly other versions, allows remote attackers to cause a denial of service (crash) via a request with a Cache-Control header that lacks a value for the max-age field, which triggers a segmentation fault in the httpParseHeaders function in http_parse.c, and possibly other unspecified vectors. | |
| Modificada | Media (5) | 1.2% | — | Pps.jussieu Polipo | 9/9/2009 | 16/6/2026 | Unspecified vulnerability in Polipo before 1.0.4 allows remote attackers to cause a denial of service (crash) via a long request URL. | |
| Modificada | Media (4.3) | 1.1% | — | Polipo | 31/8/2007 | 16/6/2026 | Polipo before 1.0.2 allows remote HTTP servers to cause a denial of service (daemon crash) by aborting the response to a POST request. | |
| Modificada | Media (5) | 1.2% | — | Polipo | 31/8/2007 | 16/6/2026 | Unspecified vulnerability in Polipo before 1.0.2 allows remote attackers to cause a denial of service (daemon crash) via certain network traffic associated with entities larger than 2 Gb. | |
| Modificada | Media (5) | 1.3% | — | Polipo | 6/10/2005 | 16/6/2026 | Unspecified vulnerability in Polipo 0.9.8 and earlier allows attackers to read files outside of the web root. |