Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4)0.16%—Aria2AI25/8/20268/9/2026
aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.
AplazadaMedia (6.2)0.16%—Aria2AI24/8/20268/9/2026
Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service
AnalizadaMedia (5.3)0.19%—Aria2 Project Aria213/5/202619/8/2026
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.
ModificadaAlta (7.5)3.4%—Ziahamza Webui-aria222/8/202317/6/2026
webui-aria2 commit 4fe2e was discovered to contain a path traversal vulnerability.
ModificadaAlta (7.8)0.35%—Aria2 Project Aria2Debian LinuxFedoraproject FedoraCanonical Ubuntu Linux2/1/201917/6/2026
aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.
ModificadaMedia (4.3)3.2%—Tatsuhiro Tsujikawa Aria217/5/201016/6/2026
Directory traversal vulnerability in aria2 before 1.9.3 allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file.
ModificadaAlta (7.6)4.9%—Tatsuhiro Tsujikawa Aria220/10/200916/6/2026
Format string vulnerability in the AbstractCommand::onAbort function in src/AbstractCommand.cc in aria2 before 1.6.2, when logging is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a download URI. NOTE: some of these details…
ModificadaAlta (10)5.8%—Tatsuhiro Tsujikawa Aria27/10/200916/6/2026
Buffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3, 1.2.0, and other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.