Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2587▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
216 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.10% | — | Tcpdump LibpcapAI | 5/9/2026 | 8/9/2026 | libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations. In particular uncommon use cases a crafted filter program can cause the interpreter to loop infinitely. | |
| Pendiente de análisis | Media (5.5) | 0.15% | — | Tcpdump LibpcapAI | 5/9/2026 | 8/9/2026 | libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero. | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | Tcpdump LibpcapAI | 5/9/2026 | 8/9/2026 | libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter program can cause the interpreter to try… | |
| Pendiente de análisis | Media (5.5) | 0.10% | — | Tcpdump LibpcapAI | 5/9/2026 | 8/9/2026 | libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process. | |
| Pendiente de análisis | Media (5) | 0.18% | — | Tcpdump LibpcapAI | 5/9/2026 | 8/9/2026 | The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet. | |
| Pendiente de análisis | Alta (8.7) | 0.11% | — | Tcpdump LibpcapAI | 5/9/2026 | 8/9/2026 | In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing… | |
| Analizada | Alta (8.8) | 1.3% | — | Rapid7 Insightconnect Tcpdump | 25/6/2026 | 29/6/2026 | OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters due to insufficient input sanitization in shell command construction. | |
| Aplazada | Alta (8.6) | 0.18% | — | Tinycontrol TcpduAITinycontrol Lk3.5AITinycontrol Lk3.9AITinycontrol LK4AI | 16/3/2026 | 17/6/2026 | Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an administrator's password by directly accessing a specific resource inaccessible via a graphical interface. This issue has been fixed in firmware versions: 1.36 (for tcPDU), 1.67 (for LK3.5 - hardware… | |
| Aplazada | Alta (8.7) | 0.27% | — | Tinycontrol TcpduAITinycontrol LK3 5AITinycontrol LK3 9AITinycontrol LK4AI | 16/3/2026 | 17/6/2026 | Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms - one solely for interface management and one for protecting all other server resources. When the latter is turned off (which is a default setting), an unauthenticated attacker on the local network… | |
| Aplazada | Baja (1.9) | 0.12% | — | Tcpdump LibpcapAI | 31/12/2025 | 17/6/2026 | On Windows only, if libpcap needs to convert a Windows error message to UTF-8 and the message includes characters that UTF-8 represents using 4 bytes, utf_16le_to_utf_8_truncated() can write data beyond the end of the provided buffer. | |
| Aplazada | Baja (1.9) | 0.12% | — | Tcpdump LibpcapAI | 31/12/2025 | 17/6/2026 | pcap_ether_aton() is an auxiliary function in libpcap, it takes a string argument and returns a fixed-size allocated buffer. The string argument must be a well-formed MAC-48 address in one of the supported formats, but this requirement has been poorly documented. If an application calls the function with an argument… | |
| Aplazada | Alta (8.6) | 1.0% | — | Moxa TcpdumpAIMoxa ProductsAI | 2/4/2025 | 17/6/2026 | This vulnerability involves command injection in tcpdump within Moxa products, enabling an authenticated attacker with console access to exploit improper input validation to inject and execute systems commands. Successful exploitation could result in privilege escalation, allowing the attacker to gain root shell… | |
| Analizada | Media (4.4) | 0.24% | — | Tcpdump Libpcap | 31/8/2024 | 17/6/2026 | Remote packet capture support is disabled by default in libpcap. When a user builds libpcap with remote packet capture support enabled, one of the functions that become available is pcap_findalldevs_ex(). One of the function arguments can be a filesystem path, which normally means a directory with input data files.… | |
| Analizada | Media (4.4) | 0.24% | — | Tcpdump Libpcap | 31/8/2024 | 17/6/2026 | In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the caller function whether freeaddrinfo() still remains to be called after the function returns. This makes it possible in… | |
| Aplazada | Media (6.2) | 0.29% | — | TcpdumpAI | 12/4/2024 | 17/6/2026 | Due to a bug in packet data buffers management, the PPP printer in tcpdump can enter an infinite loop when reading a crafted DLT_PPP_SERIAL .pcap savefile. This problem does not affect any tcpdump release, but it affected the git master branch from 2023-06-05 to 2024-03-21. | |
| Modificada | Media (6.5) | 0.84% | — | Tcpdump | 7/4/2023 | 17/6/2026 | The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet. | |
| Modificada | Crítica (9.1) | 1.0% | — | Tcpdump | 27/8/2022 | 17/6/2026 | The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 3, a different vulnerability than CVE-2018-14463. | |
| Modificada | Media (5.5) | 0.87% | — | Tcpdump Tcpslice | 5/1/2022 | 17/6/2026 | Use after free in tcpslice triggers AddressSanitizer, no other confirmed impact. | |
| Modificada | Alta (7.5) | 3.1% | — | TcpdumpDebian LinuxFedoraproject FedoraApple MAC OS X+1 | 4/11/2020 | 17/6/2026 | The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory. | |
| Modificada | Alta (7.5) | 1.5% | — | Tcpdump | 4/11/2020 | 17/6/2026 | The tok2strbuf() function in tcpdump 4.10.0-PRE-GIT was used by the SOME/IP dissector in an unsafe way. | |
| Modificada | Media (5.3) | 2.8% | — | Tcpdump LibpcapDebian LinuxOpensuse LeapOracle Communications Operations Monitor+7 | 3/10/2019 | 17/6/2026 | sf-pcapng.c in libpcap before 1.9.1 does not properly validate the PHB header length before allocating memory. | |
| Modificada | Media (5.3) | 2.9% | — | Tcpdump Libpcap | 3/10/2019 | 17/6/2026 | rpcapd/daemon.c in libpcap before 1.9.1 allows SSRF because a URL may be provided as a capture source. | |
| Modificada | Alta (7.5) | 4.4% | — | Tcpdump Libpcap | 3/10/2019 | 17/6/2026 | rpcapd/daemon.c in libpcap before 1.9.1 allows attackers to cause a denial of service (NULL pointer dereference and daemon crash) if a crypt() call fails. | |
| Modificada | Media (5.3) | 1.8% | — | Tcpdump Libpcap | 3/10/2019 | 17/6/2026 | rpcapd/daemon.c in libpcap before 1.9.1 on non-Windows platforms provides details about why authentication failed, which might make it easier for attackers to enumerate valid usernames. | |
| Modificada | Media (5.3) | 2.8% | — | Tcpdump Libpcap | 3/10/2019 | 17/6/2026 | rpcapd/daemon.c in libpcap before 1.9.1 mishandles certain length values because of reuse of a variable. This may open up an attack vector involving extra data at the end of a request. |