Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3302▲ 384 respecto a la semana anterior
Críticas / altas1464▲ 142 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)591▲ 117 respecto a la semana anterior
–

3731 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.47%—RsyslogRedhat Enterprise Linux12/8/202624/9/2026
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been…
En análisisMedia (6.1)0.15%—GstreamerRedhat Enterprise Linux12/8/202623/9/2026
A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc entries is calculated by dividing the remaining buffer size by the attacker-controlled vprp->fields value, rather than by sizeof(gst_riff_vprp_video_field_desc). This…
En análisisMedia (6.6)0.15%—GstreamerRedhat Enterprise Linux12/8/202623/9/2026
A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements a remaining-length counter by fixed offsets (98 and 10 bytes) without verifying sufficient data remains. For crafted strd payloads of exactly 106 or 107 bytes, the…
AnalizadaMedia (5.5)0.15%—Redhat Hardened ImagesRedhat Openshift Container PlatformRedhat Enterprise Linux12/8/20261/9/2026
Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the…
ModificadaAlta (8.2)0.29%—Redhat Enterprise LinuxFreeipa11/8/202628/9/2026
A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administration permission, allowing an authenticated, non-privileged IPA user to trigger a privileged Active Directory trust refresh using an attacker-supplied server and credentials,…
AnalizadaAlta (7.8)0.40%—GimpRedhat Enterprise Linux10/8/202624/8/2026
A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by tricking a user into opening a specially crafted image file. This could lead to unexpected application behavior or other potential security impacts without requiring further…
ModificadaCrítica (9.9)0.60%—GimpRedhat Enterprise Linux10/8/202630/9/2026
A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user opens a specially crafted `.psd` image file. The underflow leads to parser confusion, enabling an attacker to inject arbitrary data as layer resource blocks. This can…
AnalizadaMedia (5.5)0.33%—GimpRedhat Enterprise Linux10/8/202621/8/2026
A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to an incorrect calculation during memory allocation for image buffers, where the multiplication of image width and height can exceed the maximum integer value. A remote…
AnalizadaAlta (7.8)0.49%—GimpRedhat Enterprise Linux10/8/202624/8/2026
A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted Seattle Filmworks file. This could lead to a heap overflow, allowing the attacker to write several…
AnalizadaAlta (7.8)0.19%—Redhat Enterprise Linux8/8/20261/9/2026
A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel format but sets a lower bits-per-pixel (bpp) value in the header, the loader allocates an undersized heap buffer. Subsequent pixel data consumption at the real format's…
ModificadaMedia (5.1)0.17%—Redhat Hardened ImagesRedhat Openshift Container PlatformSmuellerdd LibkcapiRedhat Enterprise Linux5/8/202621/9/2026
A flaw was found in libkcapi. A local attacker can influence an application that uses the Asynchronous Input/Output (AIO) interface. By reusing an AIO-enabled handle after a prior completion error, the _kcapi_aio_read_all() function can enter a non-terminating wait loop. This can lead to a persistent denial of…
ModificadaAlta (7.3)0.18%—Redhat Hardened ImagesRedhat Openshift Container PlatformSmuellerdd LibkcapiRedhat Enterprise Linux5/8/202621/9/2026
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
ModificadaMedia (6.5)0.52%—Redhat Hardened ImagesRedhat Openshift Container PlatformSmuellerdd LibkcapiRedhat Enterprise Linux5/8/202621/9/2026
A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stateful modes such as Counter (CTR) or Cipher Block Chaining (CBC), the library improperly reuses the Initialization Vector (IV) for each internal data chunk. A remote attacker could potentially exploit…
AnalizadaAlta (7.1)0.13%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux4/8/202631/8/2026
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process…
AnalizadaBaja (3.3)0.13%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux4/8/202631/8/2026
A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function in the NSS responder pre-allocates reply space for all group entries but does not shrink the packet when groups are skipped, causing uninitialized heap bytes to be transmitted to the client. A local attacker can exploit this to disclose cached…
AnalizadaAlta (7.8)0.19%—Redhat Enterprise LinuxRedhat Enterprise Linux EUS4/8/202630/9/2026
A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR` width, leading to pixel data being written past the end of a heap allocation. Additionally, a heap-based buffer overflow exists in the DDS plug-in due to a BPP mismatch…
ModificadaMedia (4.4)0.08%—GNU TARRedhat Openshift Container PlatformRedhat Enterprise Linux3/8/202622/9/2026
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or…
AnalizadaMedia (5.4)0.28%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux3/8/20269/8/2026
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on…
ModificadaMedia (4.4)0.14%—GNU TARRedhat Openshift Container PlatformRedhat Enterprise Linux3/8/202622/9/2026
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with…
AnalizadaMedia (5.5)0.13%—Fedoraproject SssdRedhat Openshift Container PlatformRedhat Enterprise Linux3/8/202631/8/2026
A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash,…
AnalizadaMedia (5.5)0.34%—GimpRedhat Enterprise Linux3/8/202619/8/2026
A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended…
AnalizadaMedia (5.5)0.20%—Redhat Enterprise Linux3/8/20264/9/2026
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. This can lead to a stack-based buffer overflow (CWE-121), causing the file-png plugin to crash and resulting in a Denial of Service…
Pendiente de análisisAlta (7.5)0.52%—Gnome Remote DesktopAIRedhat Enterprise LinuxAI31/7/202613/8/2026
A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the incoming connection handler bypasses the connection throttler, allowing an unauthenticated remote attacker to open many parallel pre-authentication connections to the RDP…
ModificadaAlta (7.5)0.83%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux31/7/202618/8/2026
A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit characters from a network-supplied RUV berval into a fixed 16-byte stack buffer without bounds checking. A remote unauthenticated attacker can crash the LDAP server by…
ModificadaAlta (7.5)0.53%—Redhat Directory ServerRedhat 389 Directory ServerRedhat Enterprise Linux31/7/202618/8/2026
A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the…