Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.1)0.85%—Nothings STB Truetype.h2/4/202617/6/2026
A vulnerability was determined in Nothings stb up to 1.26. The affected element is the function stbtt__buf_get8 in the library stb_truetype.h of the component TTF File Handler. Executing a manipulation can lead to out-of-bounds read. The attack can be executed remotely. The exploit has been publicly disclosed and may…
AnalizadaBaja (2.1)0.85%—Nothings STB Truetype.h1/4/202617/6/2026
A vulnerability was found in Nothings stb up to 1.26. Impacted is the function stbtt_InitFont_internal in the library stb_truetype.h of the component TTF File Handler. Performing a manipulation results in out-of-bounds read. Remote exploitation of the attack is possible. The exploit has been made public and could be…
ModificadaMedia (6.5)0.94%—Nothings STB Truetype.h17/3/202217/6/2026
stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function stbtt__find_table at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
ModificadaMedia (6.5)0.94%—Nothings STB Truetype.h17/3/202217/6/2026
stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
ModificadaAlta (7.5)1.0%—Nothings STB Truetype.h17/3/202217/6/2026
stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
ModificadaAlta (8.8)1.5%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.
ModificadaAlta (8.8)1.4%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8.
ModificadaAlta (8.8)1.1%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT.
ModificadaAlta (8.8)1.1%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.
ModificadaAlta (8.8)1.1%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.
ModificadaAlta (8.8)1.1%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.
ModificadaAlta (8.8)1.1%—Nothings STB Truetype.h8/1/202017/6/2026
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.
Orbitaley — Vulnerabilidades