Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
39 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.30% | — | UPX | 27/3/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in UPX up to 5.0.0. Affected is the function PackLinuxElf64::un_DT_INIT of the file src/p_lx_elf.cpp. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public… | |
| Analizada | Crítica (9.8) | 1.2% | — | UPXFedoraproject Fedora | 2/4/2024 | 17/6/2026 | A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259055.… | |
| Modificada | Media (6.5) | 0.53% | — | UPX | 22/8/2023 | 17/6/2026 | Reachable Assertion vulnerability in upx before 4.0.0 allows attackers to cause a denial of service via crafted file passed to the the readx function. | |
| Modificada | Alta (7.5) | 0.82% | — | UPX | 24/3/2023 | 17/6/2026 | A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf64::elf_lookup() at p_lx_elf.cpp:5404 | |
| Modificada | Alta (7.5) | 0.82% | — | UPX | 24/3/2023 | 17/6/2026 | A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le64(). | |
| Modificada | Alta (7.5) | 0.82% | — | UPX | 24/3/2023 | 17/6/2026 | A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5349 | |
| Modificada | Alta (7.5) | 0.82% | — | UPX | 24/3/2023 | 17/6/2026 | A heap-based buffer overflows was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5368 | |
| Modificada | Alta (7.5) | 0.82% | — | UPX | 24/3/2023 | 17/6/2026 | A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf32::invert_pt_dynamic at p_lx_elf.cpp:1688. | |
| Modificada | Alta (7.5) | 0.82% | — | UPX | 24/3/2023 | 17/6/2026 | A heap-based buffer overflow was discovered in upx, during the variable 'bucket' points to an inaccessible address. The issue is being triggered in the function PackLinuxElf64::invert_pt_dynamic at p_lx_elf.cpp:5239. | |
| Modificada | Alta (7.5) | 0.82% | — | UPX | 24/3/2023 | 17/6/2026 | A heap-based buffer overflow was discovered in upx, during the generic pointer 'p' points to an inaccessible address in func get_le32(). The problem is essentially caused in PackLinuxElf32::elf_lookup() at p_lx_elf.cpp:5382. | |
| Modificada | Media (5.5) | 0.35% | — | UPXFedoraproject Fedora | 12/1/2023 | 17/6/2026 | A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service. | |
| Modificada | Media (5.5) | 0.39% | — | UPXFedoraproject Fedora | 12/1/2023 | 17/6/2026 | A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file. | |
| Modificada | Media (5.5) | 0.29% | — | UPX | 25/8/2022 | 17/6/2026 | An floating point exception was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file. | |
| Modificada | Alta (7.8) | 0.38% | — | UPX | 25/8/2022 | 17/6/2026 | A heap-based buffer over-read was discovered in the get_le64 function in bele.h in UPX 4.0.0 via a crafted Mach-O file. | |
| Modificada | Alta (7.8) | 0.33% | — | UPX | 25/8/2022 | 17/6/2026 | A heap-based buffer over-read was discovered in the get_le32 function in bele.h in UPX 4.0.0 via a crafted Mach-O file. | |
| Modificada | Alta (7.8) | 0.33% | — | UPX | 25/8/2022 | 17/6/2026 | A heap-based buffer over-read was discovered in the acc_ua_get_be32 function in miniacc.h in UPX 4.0.0 via a crafted Mach-O file. | |
| Modificada | Media (5.5) | 0.29% | — | UPX | 25/8/2022 | 17/6/2026 | An invalid memory address reference was discovered in the adjABS function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file. | |
| Modificada | Media (5.5) | 0.29% | — | UPX | 25/8/2022 | 17/6/2026 | An invalid memory address reference was discovered in the elf_lookup function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file. | |
| Modificada | Alta (7.8) | 0.34% | — | UPX | 25/8/2022 | 17/6/2026 | A heap-based buffer over-read was discovered in the invert_pt_dynamic function in p_lx_elf.cpp in UPX 4.0.0 via a crafted Mach-O file. | |
| Modificada | Media (5.5) | 0.33% | — | UPX | 18/8/2022 | 17/6/2026 | An out-of-bounds read access vulnerability was discovered in UPX in PackLinuxElf64::canPack() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service. | |
| Modificada | Media (5.5) | 0.33% | — | UPX | 18/8/2022 | 17/6/2026 | A floating point exception issue was discovered in UPX in PackLinuxElf64::invert_pt_dynamic() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service. The highest impact is to Availability. | |
| Modificada | Media (5.5) | 0.41% | — | UPX | 18/8/2022 | 17/6/2026 | A Segmentaation fault was found in UPX in invert_pt_dynamic() function in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service. | |
| Modificada | Alta (7.8) | 0.28% | — | Realtek Rtsupx USB Utility Driver | 2/11/2021 | 17/6/2026 | RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve an arbitrary read or write operation from/to physical memory (leading to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted Device IO… | |
| Modificada | Alta (7.8) | 0.21% | — | Realtek Rtsupx USB Utility Driver | 2/11/2021 | 17/6/2026 | RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device. | |
| Modificada | Alta (7.8) | 0.28% | — | Realtek Rtsupx USB Utility Driver | 2/11/2021 | 17/6/2026 | RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve unauthorized access to USB device privileged IN and OUT instructions (leading to Escalation of Privileges, Denial of Service, Code Execution, and Information Disclosure) via a crafted… |