Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
248 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 7.8% | — | Xmlsoft Libxml2Fedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+20 | 21/1/2020 | 17/6/2026 | xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. | |
| Analizada | Alta (7.8) | 72% | ⚠ Explotación activa💥 Exploit | Google AndroidDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+73 | 11/10/2019 | 17/6/2026 | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing… | |
| Modificada | Alta (7.5) | 3.5% | — | Linux KernelOpensuse LeapNetapp AFF A700s FirmwareNetapp H300s Firmware+13 | 30/9/2019 | 17/6/2026 | In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d. | |
| Modificada | Alta (7.8) | 0.87% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Real Time+30 | 20/9/2019 | 17/6/2026 | There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | |
| Modificada | Alta (8.8) | 0.76% | — | Linux KernelRedhat Virtualization HostRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+24 | 19/9/2019 | 17/6/2026 | An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be… | |
| Modificada | Alta (7.8) | 0.62% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+30 | 17/9/2019 | 17/6/2026 | A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could… | |
| Modificada | Alta (7.5) | 3.9% | — | Linux KernelCanonical Ubuntu LinuxNetapp Data Availability ServicesNetapp HCI Management Node+14 | 25/8/2019 | 17/6/2026 | An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack… | |
| Modificada | Media (4.6) | 0.60% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+3 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/driver.c driver. | |
| Modificada | Media (4.6) | 0.60% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+3 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.2.8. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/helper.c (motu_microbookii) driver. | |
| Modificada | Media (4.6) | 0.71% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+5 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.1.17. There is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c driver. | |
| Modificada | Media (4.6) | 0.76% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+5 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c driver. | |
| Modificada | Media (4.6) | 0.71% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+5 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/sisusbvga/sisusb.c driver. | |
| Modificada | Media (4.6) | 0.84% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+6 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.1.8. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c driver. | |
| Modificada | Media (4.6) | 0.68% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+5 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.2.3. There is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c driver. | |
| Modificada | Media (4.6) | 0.69% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+5 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.0.14. There is a NULL pointer dereference caused by a malicious USB device in the drivers/usb/misc/yurex.c driver. | |
| Modificada | Media (4.6) | 0.76% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+5 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c driver. | |
| Modificada | Media (4.6) | 0.66% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+3 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.2.3. There is a use-after-free caused by a malicious USB device in the drivers/media/usb/dvb-usb/dvb-usb-init.c driver. | |
| Modificada | Media (4.6) | 0.77% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+5 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.1.8. There is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c driver. | |
| Modificada | Media (4.6) | 0.76% | — | Linux KernelNetapp H410c FirmwareNetapp Active IQ Unified ManagerNetapp Data Availability Services+5 | 19/8/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.2.6. There is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c does not properly allocate memory. | |
| Modificada | Media (5.5) | 0.76% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+6 | 16/8/2019 | 17/6/2026 | check_input_term in sound/usb/mixer.c in the Linux kernel through 5.2.9 mishandles recursion, leading to kernel stack exhaustion. | |
| Modificada | Alta (7.5) | 2.7% | — | Linux KernelRedhat Developer ToolsRedhat MRG RealtimeRedhat Enterprise Linux+16 | 30/7/2019 | 17/6/2026 | A flaw was found in the Linux kernel's NFS implementation, all versions 3.x and all versions 4.x up to 4.20. An attacker, who is able to mount an exported NFS filesystem, is able to trigger a null pointer dereference by using an invalid NFS sequence. This can panic the machine and deny access to the NFS server. Any… | |
| Analizada | Alta (7.8) | 52% | ⚠ Explotación activa💥 Exploit | Linux KernelDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+18 | 17/7/2019 | 17/6/2026 | In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges… | |
| Modificada | Alta (8.8) | 5.7% | — | Dropbear SSH Project Dropbear SSHDebian LinuxNetapp H410c Firmware | 19/5/2017 | 17/6/2026 | The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled. |