Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2769▲ 8 respecto a la semana anterior
Críticas / altas1461▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
–

10 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (2.5)0.14%—GNU Libidn23/6/202629/6/2026
GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
ModificadaAlta (7.5)3.0%—GNU Libidn222/10/201917/6/2026
GNU libidn2 before 2.2.0 fails to perform the roundtrip checks specified in RFC3490 Section 4.2 when converting A-labels to U-labels. This makes it possible in some circumstances for one domain to impersonate another. By creating a malicious domain that matches a target domain except for the inclusion of certain…
ModificadaCrítica (9.8)3.7%—GNU Libidn221/10/201917/6/2026
idn2_to_ascii_4i in lib/lookup.c in GNU libidn2 before 2.1.1 has a heap-based buffer overflow via a long domain string.
ModificadaCrítica (9.8)3.9%—GNU Libidn2Debian Linux31/8/201717/6/2026
Integer overflow in the decode_digit function in puny_decode.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
ModificadaCrítica (9.8)2.4%—GNU Libidn231/8/201717/6/2026
Integer overflow in the _isBidi function in bidi.c in Libidn2 before 2.0.4 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
ModificadaAlta (7.5)3.9%—GNU Libidn7/9/201617/6/2026
The stringprep_utf8_nfkc_normalize function in lib/nfkc.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted UTF-8 data.
ModificadaAlta (7.5)6.5%—GNU LibidnCanonical Ubuntu LinuxOpensuse LeapOpensuse7/9/201617/6/2026
idn in libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read, a different vulnerability than CVE-2015-8948.
ModificadaAlta (7.5)3.9%—Opensuse LeapGNU LibidnCanonical Ubuntu Linux7/9/201617/6/2026
The idna_to_ascii_4i function in lib/idna.c in libidn before 1.33 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via 64 bytes of input.
ModificadaAlta (7.5)6.7%—Opensuse LeapOpensuseCanonical Ubuntu LinuxGNU Libidn7/9/201617/6/2026
idn in GNU libidn before 1.33 might allow remote attackers to obtain sensitive memory information by reading a zero byte as input, which triggers an out-of-bounds read.
ModificadaAlta (7.5)3.2%—GNU LibidnOpensuseFedoraproject Fedora12/8/201517/6/2026
The stringprep_utf8_to_ucs4 function in libin before 1.31, as used in jabberd2, allows context-dependent attackers to read system memory and possibly have other unspecified impact via invalid UTF-8 characters in a string, which triggers an out-of-bounds read.