Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2965▲ 27 respecto a la semana anterior
Críticas / altas1456▲ 193 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.2) | 0.55% | — | Dest-unreach Socat | 25/6/2026 | 26/6/2026 | socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension flaw in the DOMAINNAME reply parser. During connection setup, the domain name length byte is read through a signed char… | |
| Aplazada | Crítica (9.8) | 0.80% | — | SocatAI | 4/12/2024 | 17/6/2026 | readline.sh in socat before1.8.0.2 relies on the /tmp/$USER/stderr2 file. | |
| Modificada | Alta (7.5) | 3.9% | — | Dest-unreach Socat | 8/6/2017 | 17/6/2026 | The signal handler implementations in socat before 1.7.3.0 and 2.0.0-b8 allow remote attackers to cause a denial of service (process freeze or crash). | |
| Modificada | Media (5.3) | 2.5% | — | Dest-unreach Socat | 30/1/2017 | 17/6/2026 | The OpenSSL address implementation in Socat 1.7.3.0 and 2.0.0-b8 does not use a prime number for the DH, which makes it easier for remote attackers to obtain the shared secret. | |
| Modificada | Baja (2.6) | 2.1% | — | Dest-unreach Socat | 8/5/2014 | 16/6/2026 | socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is enabled, allows remote attackers to cause a denial of service (file descriptor consumption) via multiple request that are refused based on the (1) sourceport, (2) lowport, (3) range, or (4) tcpwrap… | |
| Modificada | Baja (1.9) | 0.40% | — | Dest-unreach SocatFedoraproject FedoraOpensuse | 4/2/2014 | 17/6/2026 | Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line. | |
| Modificada | Media (6.2) | 0.46% | — | Dest-unreach Socat | 21/6/2012 | 16/6/2026 | Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0-b1 through 2.0.0-b4 allows local users to execute arbitrary code via the READLINE address. | |
| Modificada | Media (6.8) | 2.8% | — | Dest-unreach Socat | 14/9/2010 | 16/6/2026 | Stack-based buffer overflow in the nestlex function in nestlex.c in Socat 1.5.0.0 through 1.7.1.2 and 2.0.0-b1 through 2.0.0-b3, when bidirectional data relay is enabled, allows context-dependent attackers to execute arbitrary code via long command-line arguments. | |
| Modificada | Media (5) | 7.3% | — | Socat | 31/12/2004 | 16/6/2026 | Format string vulnerability in the _msg function in error.c in socat 1.4.0.3 and earlier, when used as an HTTP proxy client and run with the -ly option, allows remote attackers or local users to execute arbitrary code via format string specifiers in a syslog message. |