Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.37% | — | Gnome GlibAI | 27/1/2026 | 17/6/2026 | A flaw was found in GLib. An integer overflow vulnerability in its Unicode case conversion implementation can lead to memory corruption. By processing specially crafted and extremely large Unicode strings, an attacker could trigger an undersized memory allocation, resulting in out-of-bounds writes. This could cause… | |
| Aplazada | Baja (2.8) | 0.16% | — | Gnome GlibAI | 27/1/2026 | 17/6/2026 | A flaw was found in Glib's content type parsing logic. This buffer underflow vulnerability occurs because the length of a header line is stored in a signed integer, which can lead to integer wraparound for very large inputs. This results in pointer underflow and out-of-bounds memory access. Exploitation requires a… | |
| Aplazada | Media (4.2) | 0.35% | — | Gnome GlibAI | 27/1/2026 | 17/6/2026 | A flaw was found in the GLib Base64 encoding routine when processing very large input data. Due to incorrect use of integer types during length calculation, the library may miscalculate buffer boundaries. This can cause memory writes outside the allocated buffer. Applications that process untrusted or extremely large… | |
| Aplazada | Baja (3.7) | 0.44% | — | Gnome GlibAI | 21/1/2026 | 17/6/2026 | A flaw was found in glib. Missing validation of offset and count parameters in the g_buffered_input_stream_peek() function can lead to an integer overflow during length calculation. When specially crafted values are provided, this overflow results in an incorrect size being passed to memcpy(), triggering a buffer… | |
| Analizada | Alta (7.5) | 0.50% | — | GNU Glibc | 20/1/2026 | 17/6/2026 | Calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND in the GNU C Library version 2.0 to version 2.42 may cause the interface to return uninitialized memory in the we_wordv member, which on subsequent calls to wordfree may abort the process. | |
| Analizada | Alta (7.5) | 0.63% | — | GNU Glibc | 15/1/2026 | 17/6/2026 | Calling getnetbyaddr or getnetbyaddr_r with a configured nsswitch.conf that specifies the library's DNS backend for networks and queries for a zero-valued network in the GNU C Library version 2.0 to version 2.42 can leak stack contents to the configured DNS resolver. | |
| Analizada | Alta (8.4) | 0.39% | — | GNU Glibc | 14/1/2026 | 17/6/2026 | Passing too large an alignment to the memalign suite of functions (memalign, posix_memalign, aligned_alloc) in the GNU C Library version 2.30 to 2.42 may result in an integer overflow, which could consequently result in a heap corruption. Note that the attacker must have control over both, the size as well as the… | |
| Modificada | Media (6.5) | 0.58% | — | Gnome GlibRedhat OpenshiftRedhat Enterprise Linux | 11/12/2025 | 2/10/2026 | A flaw was found in glib. This vulnerability allows a heap buffer overflow and denial-of-service (DoS) via an integer overflow in GLib's GIO (GLib Input/Output) escape_byte_string() function when processing malicious file or remote filesystem attribute values. | |
| Modificada | Crítica (9.8) | 0.83% | — | Gnome GlibRedhat Enterprise Linux | 10/12/2025 | 2/10/2026 | A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a denial of service or potential code execution via a buffer-underflow in the GVariant parser when processing maliciously crafted input strings. | |
| Modificada | Alta (7.7) | 0.32% | — | Redhat Codeready Linux BuilderRedhat Codeready Linux Builder FOR IBM Z SystemsRedhat Codeready Linux Builder FOR Power Little EndianRedhat Codeready Linux Builder FOR X86 64+25 | 26/11/2025 | 31/8/2026 | A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_uri_string() function. If the string to escape contains a very large number of unacceptable characters (which would need escaping), the calculation of the length of the escaped string could overflow,… | |
| Aplazada | Baja (3.7) | 0.36% | — | OpensslAIGnome Glib-networkingAI | 25/9/2025 | 30/6/2026 | glib-networking's OpenSSL backend fails to properly check the return value of memory allocation routines. An out of memory condition could potentially result in writing to an invalid memory location. | |
| Aplazada | Media (4.8) | 0.31% | — | OpensslAIGlib-networking Glib NetworkingAI | 25/9/2025 | 30/6/2026 | glib-networking's OpenSSL backend fails to properly check the return value of a call to BIO_write(), resulting in an out of bounds read. | |
| Aplazada | Baja (3.7) | 0.40% | — | Gnome GlibAI | 3/9/2025 | 17/6/2026 | A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and… | |
| Modificada | Alta (7.5) | 0.45% | — | Gnome Glib | 28/7/2025 | 30/6/2026 | A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long command lines. | |
| Aplazada | Alta (7.5) | 1.2% | — | Gnome Gdk-pixbufAIGnome GlibAI | 8/7/2025 | 30/6/2026 | A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially… | |
| Modificada | Alta (7.5) | 0.52% | — | Gnome Glib | 13/6/2025 | 17/6/2026 | A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation. This makes the system think it has enough memory when it doesn’t. As a result, data may be written past the end of the… | |
| Analizada | Media (5.6) | 0.25% | — | GNU Glibc | 5/6/2025 | 17/6/2026 | The strncmp implementation optimized for the Power10 processor in the GNU C Library version 2.40 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and… | |
| Analizada | Media (5.6) | 0.31% | — | GNU Glibc | 5/6/2025 | 17/6/2026 | The strcmp implementation optimized for the Power10 processor in the GNU C Library version 2.39 and later writes to vector registers v20 to v31 without saving contents from the caller (those registers are defined as non-volatile registers by the powerpc64le ABI), resulting in overwriting of its contents and… | |
| Modificada | Alta (7.1) | 0.31% | — | Taglib | 22/5/2025 | 17/6/2026 | TagLib before 2.0 allows a segmentation violation and application crash during tag writing via a crafted WAV file in which an id3 chunk is the only valid chunk. | |
| Modificada | Alta (7.8) | 0.59% | — | GNU Glibc | 16/5/2025 | 17/6/2026 | Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo). | |
| Aplazada | Media (4.8) | 0.64% | — | Gnome GlibAI | 6/5/2025 | 21/9/2026 | A flaw was found in GLib, which is vulnerable to an integer overflow in the g_string_insert_unichar() function. When the position at which to insert the character is large, the position will overflow, leading to a buffer underwrite. | |
| Aplazada | Baja (3.7) | 0.47% | — | Gnome GlibAI | 7/4/2025 | 30/6/2026 | A flaw was found in GLib. An integer overflow and buffer under-read occur when parsing a long invalid ISO 8601 timestamp with the g_date_time_new_from_iso8601() function. | |
| Analizada | Crítica (9.8) | 1.3% | — | Gnome GlibDebian LinuxNetapp Active IQ Unified ManagerNetapp Ontap Tools | 11/11/2024 | 17/6/2026 | gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character. | |
| Modificada | Media (5.2) | 0.76% | — | Gnome GlibDebian LinuxFedoraproject FedoraNetapp Ontap Tools | 7/5/2024 | 17/6/2026 | An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly… | |
| Modificada | Alta (7.4) | 0.40% | — | GNU GlibcDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+7 | 6/5/2024 | 17/6/2026 | nscd: netgroup cache assumes NSS callback uses in-buffer strings The Name Service Cache Daemon's (nscd) netgroup cache can corrupt memory when the NSS callback does not store all strings in the provided buffer. The flaw was introduced in glibc 2.15 when the cache was added to nscd. This vulnerability is only present… |