Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3043▲ 582 respecto a la semana anterior
Críticas / altas1452▲ 283 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.27%—GpsdAIGnuplotAI23/7/202630/7/2026
gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who controls GPS input data to execute arbitrary OS commands by injecting malicious content into the SKY.satellites[].used field, which is inserted unsanitized into a gnuplot…
ModificadaMedia (5.5)0.20%—Gnuplot7/5/202526/6/2026
gnuplot is affected by a heap buffer overflow at function utf8_copy_one.
AplazadaMedia (6.2)0.20%—GnuplotAI7/4/202517/6/2026
A flaw was found in GNUPlot. A segmentation fault via IO_str_init_static_internal may jeopardize the environment.
ModificadaMedia (6.2)0.19%—Gnuplot27/3/202526/6/2026
A flaw was found in gnuplot. The X11_graphics() function may lead to a segmentation fault and cause a system crash.
ModificadaMedia (6.2)0.19%—Gnuplot27/3/202526/6/2026
A flaw was found in gnuplot. The CANVAS_text() function may lead to a segmentation fault and cause a system crash.
ModificadaMedia (6.2)0.19%—Gnuplot27/3/202526/6/2026
A flaw was found in gnuplot. The xstrftime() function may lead to a segmentation fault, causing a system crash.
ModificadaMedia (6.2)0.19%—Gnuplot27/3/202526/6/2026
A flaw was found in gnuplot. The GetAnnotateString() function may lead to a segmentation fault and cause a system crash.
ModificadaMedia (6.2)0.19%—Gnuplot27/3/202526/6/2026
A flaw was found in gnuplot. The plot3d_points() function may lead to a segmentation fault and cause a system crash.
ModificadaCrítica (9.8)1.0%—Gnuplot5/7/202317/6/2026
gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest().
ModificadaCrítica (9.8)1.1%—Stoqey Gnuplot10/3/202317/6/2026
An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s).
ModificadaMedia (5.5)0.70%—Gnuplot21/12/202117/6/2026
A Divide by Zero vulnerability exists in gnuplot 5.4 in the boundary3d function in graph3d.c, which could cause a Arithmetic exception and application crash.
ModificadaCrítica (9.8)1.8%—Gnuplot Project Gnuplot3/5/202117/6/2026
The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands.
ModificadaCrítica (9.8)2.6%—Gnuplot16/9/202017/6/2026
com_line() in command.c in gnuplot 5.4 leads to an out-of-bounds-write from strncpy() that may lead to arbitrary code execution.
ModificadaAlta (7.8)1.6%—Gnuplot16/9/202017/6/2026
gnuplot 5.5 is affected by double free when executing print_set_output. This may result in context-dependent arbitrary code execution.
ModificadaAlta (7.8)1.8%—GnuplotDebian LinuxOpensuse Leap23/11/201817/6/2026
An issue was discovered in cairo.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the cairotrm_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot pngcairo…
ModificadaAlta (7.8)1.8%—GnuplotDebian LinuxOpensuse Leap23/11/201817/6/2026
An issue was discovered in post.trm in Gnuplot 5.2.5. This issue allows an attacker to conduct a buffer overflow with an arbitrary amount of data in the PS_options function. This flaw is caused by a missing size check of an argument passed to the "set font" function. This issue occurs when the Gnuplot postscript…
ModificadaAlta (7.8)1.8%—GnuplotDebian LinuxOpensuse Leap23/11/201817/6/2026
An issue was discovered in datafile.c in Gnuplot 5.2.5. This issue allows an attacker to conduct a heap-based buffer overflow with an arbitrary amount of data in df_generate_ascii_array_entry. To exploit this vulnerability, an attacker must pass an overlong string as the right bound of the range argument that is…
ModificadaAlta (7.8)0.87%—Gnuplot15/6/201717/6/2026
An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a specially crafted file.
ModificadaAlta (7.2)0.47%—Gnuplot31/12/200216/6/2026
Buffer overflow in the French documentation patch for Gnuplot 3.7 in SuSE Linux before 8.0 allows local users to execute arbitrary code as root via unknown attack vectors.