Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.19%—Nothings STB TruetypeAI7/8/20268/9/2026
A heap-buffer-overflow vulnerability exists in the nothings stb TrueType library, up to version 1.26, that is used for parsing TrueType font files. The vulnerability exists in the stbtt__GetGlyphShapeTT() function within the nothings stb_truetype.h library when parsing malformed TTF (TrueType Font) files. The…
AnalizadaBaja (2.1)0.85%—Nothings STB Truetype.h2/4/202617/6/2026
A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the library stb_truetype.h of the component TTF File Handler. Executing a manipulation can lead to out-of-bounds read. The attack can be executed remotely. The exploit has been publicly disclosed and may…
AnalizadaBaja (2.1)0.85%—Nothings STB Truetype.h1/4/202617/6/2026
A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be…
ModificadaMedia (6.5)0.94%—Nothings STB Truetype.h17/3/202217/6/2026
stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function stbtt__find_table at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
ModificadaMedia (6.5)0.94%—Nothings STB Truetype.h17/3/202217/6/2026
stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
ModificadaAlta (7.5)1.0%—Nothings STB Truetype.h17/3/202217/6/2026
stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
ModificadaAlta (8.8)1.5%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.
ModificadaAlta (8.8)1.4%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8.
ModificadaAlta (8.8)1.1%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT.
ModificadaAlta (8.8)1.1%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.
ModificadaAlta (8.8)1.1%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.
ModificadaAlta (8.8)1.1%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.
ModificadaAlta (8.8)1.1%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.
Orbitaley — Vulnerabilidades