Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2731▲ 24 respecto a la semana anterior
Críticas / altas1467▲ 357 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 458 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Baja (3.7) | 0.29% | — | GNU GlibcAI | 28/9/2026 | 29/9/2026 | The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable. This condition may happen when the input strings to the strncasecmp function are attacker controlled in an… | |
| Aplazada | Media (5.3) | 0.29% | — | LibconfiniAI | 24/9/2026 | 25/9/2026 | libconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and strip_ini_cache(). The bundled utility allocates exactly ini_length bytes, while strip_ini_cache() unconditionally writes a NUL terminator at ini_source[ini_length], requiring an additional writable… | |
| Pendiente de análisis | Baja (3.6) | 0.13% | — | GNU GlibcAI | 22/9/2026 | 22/9/2026 | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs. When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader… | |
| Pendiente de análisis | Media (6.3) | 0.12% | — | GNU GlibcAI | 22/9/2026 | 23/9/2026 | A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path… | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | GNU GlibcAI | 17/9/2026 | 18/9/2026 | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process. The resolver truncates the search list when… | |
| Pendiente de análisis | Media (4.2) | 0.27% | — | GNU GlibcAI | 11/9/2026 | 11/9/2026 | The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitation of this bug needs a system that has nscd enabled and using an untrusted DNS server for name… | |
| Aplazada | Alta (7.5) | 0.63% | — | RelibcAI | 28/8/2026 | 9/9/2026 | An issue in the with_argv function (/unistd/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (7.5) | 0.63% | — | RelibcAI | 28/8/2026 | 9/9/2026 | An issue in the seekdir() function (/dirent/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Alta (8.7) | 0.31% | — | Libcrux EcdhAILibcrux Ed25519AILibcrux PSQAI | 19/8/2026 | 24/9/2026 | libcrux-ecdh and libcrux-ed25519 before 0.0.6, and libcrux-psq before 0.0.7, contain cryptographic implementation bugs. libcrux-ecdh did not properly check length and clamping during X25519 secret validation (and had a broken clamping check for imported X25519 secret keys); libcrux-ed25519 performed a duplicated… | |
| Pendiente de análisis | Media (6.6) | 0.33% | — | Glibc WordexpAI | 10/8/2026 | 3/9/2026 | When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was… | |
| Pendiente de análisis | Alta (7.5) | 0.63% | — | Openprinting LibcupsfiltersAI | 23/7/2026 | 19/8/2026 | A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer… | |
| Pendiente de análisis | Alta (7.5) | 0.70% | — | LibcupsfiltersAICups-filtersAI | 20/7/2026 | 24/8/2026 | A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted… | |
| Aplazada | Alta (7.5) | 0.63% | — | RelibcAI | 26/6/2026 | 29/6/2026 | An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via loading a crafted shared library. | |
| Aplazada | Alta (7.5) | 0.63% | — | RelibcAI | 26/6/2026 | 29/6/2026 | An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of Service (DoS) via parsing a crafted input. | |
| Aplazada | Alta (7.5) | 0.63% | — | RelibcAI | 25/6/2026 | 26/6/2026 | A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted string. | |
| Aplazada | Alta (7.5) | 0.63% | — | RelibcAI | 25/6/2026 | 26/6/2026 | An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Aplazada | Media (6.9) | 0.48% | — | LibcurlAIMusicpd Music Player DaemonAI | 28/5/2026 | 14/7/2026 | Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION is set without CURLOPT_REDIR_PROTOCOLS_STR, allowing unauthenticated attackers to bypass the http/https scheme restriction by causing a malicious HTTP server to redirect… | |
| Aplazada | Alta (7.8) | 0.33% | — | LibcacaAI | 11/5/2026 | 17/6/2026 | libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-bounds write (heap overflow) by supplying a crafted file in the "caca" format. Depending on the build configuration and… | |
| Modificada | Media (6.5) | 0.44% | — | GNU Glibc | 28/4/2026 | 14/7/2026 | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target… | |
| Modificada | Alta (7.3) | 0.39% | — | GNU Glibc | 28/4/2026 | 14/7/2026 | The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records. | |
| Modificada | Alta (7.5) | 0.49% | — | GNU Glibc | 20/4/2026 | 14/7/2026 | Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in… | |
| Modificada | Crítica (9.8) | 0.72% | — | GNU Glibc | 20/4/2026 | 14/7/2026 | Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow. | |
| Analizada | Alta (8.8) | 0.52% | — | Libcoap | 17/4/2026 | 17/6/2026 | libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bounds checking, which is removed in release builds compiled with NDEBUG. Attackers can send crafted CoAP requests with malformed OSCORE options… | |
| Aplazada | Alta (8.1) | 0.17% | — | Musl LibcAI | 10/4/2026 | 17/6/2026 | An issue was discovered in musl libc 0.7.10 through 1.2.6. Stack-based memory corruption can occur during qsort of very large arrays, due to incorrectly implemented double-word primitives. The number of elements must exceed about seven million, i.e., the 32nd Leonardo number on 32-bit platforms (or the 64th Leonardo… | |
| Aplazada | Media (4.8) | 0.16% | — | Musl LibcAI | 10/4/2026 | 17/6/2026 | A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is… |