Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.19% | — | Nothings STB TruetypeAI | 7/8/2026 | 8/9/2026 | A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the nothings stb_truetype.h library when parsing malformed TTF (TrueType Font) files. The… | |
| Analizada | Baja (2.1) | 0.85% | — | Nothings STB Truetype.h | 2/4/2026 | 17/6/2026 | A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the library stb_truetype.h of the component TTF File Handler. Executing a manipulation can lead to out-of-bounds read. The attack can be executed remotely. The exploit has been publicly disclosed and may… | |
| Analizada | Baja (2.1) | 0.85% | — | Nothings STB Truetype.h | 1/4/2026 | 17/6/2026 | A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be… | |
| Modificada | Media (6.5) | 0.94% | — | Nothings STB Truetype.h | 17/3/2022 | 17/6/2026 | stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function stbtt__find_table at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input. | |
| Modificada | Media (6.5) | 0.94% | — | Nothings STB Truetype.h | 17/3/2022 | 17/6/2026 | stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input. | |
| Modificada | Alta (7.5) | 1.0% | — | Nothings STB Truetype.h | 17/3/2022 | 17/6/2026 | stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input. | |
| Modificada | Alta (8.8) | 1.5% | — | Nothings STB Truetype.h | 8/1/2020 | 17/6/2026 | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index. | |
| Modificada | Alta (8.8) | 1.4% | — | Nothings STB Truetype.h | 8/1/2020 | 17/6/2026 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8. | |
| Modificada | Alta (8.8) | 1.1% | — | Nothings STB Truetype.h | 8/1/2020 | 17/6/2026 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT. | |
| Modificada | Alta (8.8) | 1.1% | — | Nothings STB Truetype.h | 8/1/2020 | 17/6/2026 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8. | |
| Modificada | Alta (8.8) | 1.1% | — | Nothings STB Truetype.h | 8/1/2020 | 17/6/2026 | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek. | |
| Modificada | Alta (8.8) | 1.1% | — | Nothings STB Truetype.h | 8/1/2020 | 17/6/2026 | stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table. | |
| Modificada | Alta (8.8) | 1.1% | — | Nothings STB Truetype.h | 8/1/2020 | 17/6/2026 | stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int. |