Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.6) | 0.18% | — | GNU Bison | 29/7/2026 | 24/8/2026 | GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this behavior allows directing generated files to… | |
| Analizada | Media (6.8) | 0.22% | — | GNU Bison | 29/7/2026 | 24/8/2026 | GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and… | |
| Modificada | Media (5.5) | 1.3% | — | GNU Bison | 25/8/2020 | 17/6/2026 | GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/obstack.c (called from gram_lex) when a '\0' byte is encountered. NOTE: there is a risk only if Bison is used with untrusted input, and the observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug report was… | |
| Modificada | Media (5.5) | 0.39% | — | GNU Bison | 15/6/2020 | 17/6/2026 | GNU Bison before 3.5.4 allows attackers to cause a denial of service (application crash). NOTE: there is a risk only if Bison is used with untrusted input, and an observed bug happens to cause unsafe behavior with a specific compiler/architecture. The bug reports were intended to show that a crash may occur in Bison… | |
| Modificada | Alta (7.8) | 62% | — | Bisonware Bisonftp | 29/9/2015 | 17/6/2026 | Directory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in a RETR command. | |
| Modificada | Baja (2.1) | 1.7% | — | Sofotex Bisonftp | 29/6/2005 | 16/6/2026 | BisonFTP Server V4R1 allows remote authenticated users to cause a denial of service via an invalid command with a long argument. | |
| Modificada | Media (4.3) | 1.2% | — | Bisonftp Server 4 | 31/12/2003 | 16/6/2026 | BisonFTP Server 4 release 2 allows remote attackers to cause a denial of service (CPU consumption) via a long (1) ls or (2) cwd command. | |
| Modificada | Alta (7.5) | 1.6% | — | Bisonftp Server 4 | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in BisonFTP Server 4 release 2 allows remote attackers to (1) list directories above the root via an 'ls @../' command, or (2) list files above the root via a "mget @../FILE" command. | |
| Modificada | Media (4.6) | 0.44% | — | Bisonware Bison FTP Server | 18/10/2001 | 16/6/2026 | BisonFTP V4R1 allows local users to access directories outside of their home directory by uploading .bdl files, which can then be linked to other directories. | |
| Modificada | Alta (7.5) | 67% | — | Bisonware FTP Server | 17/5/1999 | 16/6/2026 | Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands. | |
| Modificada | Media (5) | 1.3% | — | Bisonware FTP Server | 17/5/1999 | 16/6/2026 | BisonWare FTP Server 4.1 and earlier allows remote attackers to cause a denial of service via a malformed PORT command that contains a non-numeric character and a large number of carriage returns. | |
| Modificada | Media (5) | 2.2% | — | Bisonware FTP Server | 12/9/1997 | 16/6/2026 | Remote attackers can cause a denial of service in FTP by issuing multiple PASV commands, causing the server to run out of available ports. |