Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
29 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.3) | 0.59% | — | ZlibAI | 3/9/2026 | 9/9/2026 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove()… | |
| Analizada | Baja (1.7) | 0.75% | — | Ruby-lang Zlib | 16/4/2026 | 17/6/2026 | zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee… | |
| Pendiente de análisis | Crítica (9.1) | 0.76% | — | Python LzmaAIPython BZ2AIPython GzipAIPython ZlibAI | 13/4/2026 | 13/8/2026 | Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The fix cleans up the dangling pointer in… | |
| Analizada | Media (5.5) | 0.19% | — | Zlib | 18/2/2026 | 17/6/2026 | zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition. | |
| Aplazada | Crítica (10) | 0.30% | — | Tildearrow FurnaceAIZlibAI | 27/1/2026 | 17/6/2026 | Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in tildearrow furnace (extern/zlib modules). This vulnerability is associated with program files inflate.C. | |
| Modificada | Media (4.6) | 0.42% | — | Zlib | 7/1/2026 | 1/9/2026 | zlib versions up to and including 1.3.1.2 include a global buffer overflow in the untgz utility located under contrib/untgz. The vulnerability is limited to the standalone demonstration utility and does not affect the core zlib compression library. The flaw occurs when a user executes the untgz command with an… | |
| Aplazada | Alta (8.3) | 0.40% | — | Pointcloudlibrary PCLAIZlibAI | 14/5/2025 | 17/6/2026 | Out-of-bounds Write vulnerability in PointCloudLibrary pcl allows Overflow Buffers. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user… | |
| Aplazada | Alta (7.1) | 0.25% | — | BizlibraryAI | 21/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matthew BizLibrary bizlibrary allows Reflected XSS.This issue affects BizLibrary: from n/a through <= 1.1. | |
| Modificada | Media (5.5) | 0.24% | — | Cloudflare Zlib | 4/1/2024 | 17/6/2026 | Cloudflare version of zlib library was found to be vulnerable to memory corruption issues affecting the deflation algorithm implementation (deflate.c). The issues resulted from improper input validation and heap-based buffer overflow. A local attacker could exploit the problem during compression using a crafted… | |
| Modificada | Alta (8.8) | 1.3% | — | Zlib-ng Minizip-ng | 22/11/2023 | 17/6/2026 | Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_has_slash function in the mz_os.c file. | |
| Modificada | Alta (8.8) | 0.93% | — | Zlib-ng Minizip-ng | 22/11/2023 | 17/6/2026 | Buffer Overflow vulnerability in zlib-ng minizip-ng v.4.0.2 allows an attacker to execute arbitrary code via a crafted file to the mz_path_resolve function in the mz_os.c file. | |
| Modificada | Crítica (9.8) | 3.2% | — | ZlibSmihica Pyminizip | 14/10/2023 | 14/7/2026 | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version,… | |
| Modificada | Media (4.8) | 0.49% | — | Bizlibrary | 15/5/2023 | 17/6/2026 | The BizLibrary WordPress plugin through 1.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 19% | — | ZlibFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+14 | 5/8/2022 | 14/7/2026 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the… | |
| Modificada | Alta (7.5) | 52% | — | NokogiriPythonZlibDebian Linux+23 | 25/3/2022 | 14/7/2026 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. | |
| Modificada | Media (5.5) | 4.1% | — | Zlib-ng Minizip-ng | 16/1/2018 | 17/6/2026 | Directory traversal vulnerability in the do_extract_currentfile function in miniunz.c in miniunzip in minizip before 1.1-5 might allow remote attackers to write to arbitrary files via a crafted entry in a ZIP archive. | |
| Modificada | Crítica (9.8) | 5.8% | — | ZlibOpensuse LeapOpensuseDebian Linux+20 | 23/5/2017 | 17/6/2026 | The crc32_big function in crc32.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving big-endian CRC calculation. | |
| Modificada | Alta (8.8) | 5.2% | — | ZlibOpensuse LeapOpensuseDebian Linux+15 | 23/5/2017 | 14/7/2026 | The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers. | |
| Modificada | Crítica (9.8) | 7.5% | — | ZlibOpensuse LeapOpensuseDebian Linux+35 | 23/5/2017 | 14/7/2026 | inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | |
| Modificada | Alta (8.8) | 4.8% | — | BoostZlibOpensuse LeapOpensuse+16 | 23/5/2017 | 14/7/2026 | inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | |
| Modificada | Media (5) | 3.0% | — | Zlib Pigz | 21/1/2015 | 17/6/2026 | Multiple directory traversal vulnerabilities in pigz 2.3.1 allow remote attackers to write to arbitrary files via a (1) full pathname or (2) .. (dot dot) in an archive. | |
| Modificada | Media (4.4) | 0.34% | — | Zlib Pigz | 27/4/2014 | 16/6/2026 | Race condition in pigz before 2.2.5 uses permissions derived from the umask when compressing a file before setting that file's permissions to match those of the original file, which might allow local users to bypass intended access permissions while compression is occurring. | |
| Modificada | Media (6.8) | 7.4% | — | Paul Marquess Compress-raw-zlib Perl Module | 16/6/2009 | 16/6/2026 | Off-by-one error in the inflate function in Zlib.xs in Compress::Raw::Zlib Perl module before 2.017, as used in AMaViS, SpamAssassin, and possibly other products, allows context-dependent attackers to cause a denial of service (hang or crash) via a crafted zlib compressed stream that triggers a heap-based buffer… | |
| Modificada | Media (5) | 4.1% | — | Zlib | 26/7/2005 | 16/6/2026 | inftrees.h in zlib 1.2.2 allows remote attackers to cause a denial of service (application crash) via an invalid file that causes a large dynamic tree to be produced. | |
| Modificada | Alta (7.5) | 5.6% | — | Zlib | 6/7/2005 | 14/7/2026 | zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file. |