Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▲ 8 respecto a la semana anterior
Críticas / altas1461▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.3) | 0.14% | — | Uutils CoreutilsAI | 18/9/2026 | 22/9/2026 | uutils coreutils versions before 0.10.0 apply setuid or setgid mode to install destinations before finalizing ownership changes, allowing privileged users to leave setuid executables owned by the privileged invoker when ownership changes fail. Attackers can execute leftover setuid files with elevated privileges when… | |
| Analizada | Baja (1.9) | 0.18% | — | GNU Binutils | 15/9/2026 | 17/9/2026 | A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public… | |
| Analizada | Baja (1.9) | 0.18% | — | GNU Binutils | 15/9/2026 | 16/9/2026 | A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed… | |
| Analizada | Baja (1.9) | 0.17% | — | GNU Binutils | 15/9/2026 | 16/9/2026 | A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks.… | |
| Analizada | Baja (1.9) | 0.17% | — | GNU Binutils | 15/9/2026 | 16/9/2026 | A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been… | |
| Analizada | Baja (1.9) | 0.17% | — | GNU Binutils | 14/9/2026 | 16/9/2026 | A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was… | |
| Analizada | Baja (1.9) | 0.17% | — | GNU Binutils | 14/9/2026 | 16/9/2026 | A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be… | |
| Analizada | Baja (1.9) | 0.17% | — | GNU Binutils | 14/9/2026 | 16/9/2026 | A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available… | |
| Analizada | Baja (1.9) | 0.19% | — | GNU Binutils | 14/9/2026 | 21/9/2026 | A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has… | |
| Analizada | Baja (0.9) | 0.20% | — | GNU Binutils | 14/9/2026 | 18/9/2026 | A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer… | |
| Analizada | Baja (1.9) | 0.20% | — | GNU Binutils | 14/9/2026 | 18/9/2026 | A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been… | |
| Analizada | Baja (1.9) | 0.18% | — | GNU Binutils | 14/9/2026 | 18/9/2026 | A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was… | |
| Analizada | Baja (1.9) | 0.21% | — | GNU Binutils | 14/9/2026 | 18/9/2026 | A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for… | |
| Aplazada | Media (5.5) | 0.70% | — | Java-json-tools Jackson-coreutilsAI | 8/9/2026 | 28/9/2026 | A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/com/github/fge/jackson/jsonpointer/TreePointer.java of the component JSON Pointer parser. The manipulation results in allocation of resources. The… | |
| Aplazada | Media (5.5) | 0.70% | — | Java-json-tools Jackson-coreutilsAI | 8/9/2026 | 28/9/2026 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/github/fge/jackson/JacksonUtils.java. Performing a manipulation results in resource consumption. The attack may be initiated remotely. The exploit… | |
| Aplazada | Media (5.5) | 0.66% | — | Java-json-tools Jackson-coreutilsAI | 7/9/2026 | 8/9/2026 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this issue is the function JsonLoader.fromURL of the file src/main/java/com/github/fge/jackson/JsonLoader.java of the component URL Validation. The manipulation results in server-side request forgery. It is possible to launch the attack… | |
| Aplazada | Baja (1.9) | 0.16% | — | LatencyutilsAI | 31/8/2026 | 31/8/2026 | A vulnerability was determined in LatencyUtils up to 2.0.3. Affected by this issue is the function LatencyStats.recordDetectedPause of the file src/main/java/org/LatencyUtils/LatencyStats.java of the component PauseDetector. Executing a manipulation can lead to memory corruption. The attack needs to be launched… | |
| Pendiente de análisis | Media (4.4) | 0.11% | — | PolicycoreutilsAI | 7/8/2026 | 1/9/2026 | A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files under /tmp and other directories. A local attacker could exploit a race… | |
| Pendiente de análisis | Alta (7.8) | 0.19% | — | GNU BinutilsAI | 29/7/2026 | 30/7/2026 | An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via… | |
| Pendiente de análisis | Alta (7.6) | 0.35% | — | SG3 UtilsAI | 28/7/2026 | 1/10/2026 | A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing control characters in SCSI name string fields. A newline character embedded in a device-supplied name string can inject arbitrary properties into the udev device database.… | |
| Pendiente de análisis | Media (5.6) | 0.15% | — | GNU BinutilsAI | 27/7/2026 | 1/9/2026 | A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an… | |
| Analizada | Media (4.6) | 0.17% | — | GNU Coreutils | 24/7/2026 | 26/8/2026 | GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an… | |
| Analizada | Baja (1.8) | 0.19% | — | GNU Coreutils | 24/7/2026 | 2/10/2026 | GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent… | |
| Aplazada | Media (6.8) | 0.14% | — | Selinux PolicycoreutilsAI | 23/7/2026 | 23/7/2026 | A Missing Authorization vulnerability in selinux policycoreutils seunshares allows a user that is running in unconfined context to kill e.g. root-owned processes running also in unconfined context This issue affects policycoreutils through 3.10. | |
| Aplazada | Media (5.8) | 0.10% | — | Selinux PolicycoreutilsAI | 23/7/2026 | 23/7/2026 | A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in seunshare of selinux policycoreutils allows a user calling seunshare that is running in the unconfined SELinux domain to delete arbitrary root-owned files, This issue affects policycoreutils through 3.10. |