Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.3% | — | Oracle JDKOracle JREDebian LinuxRedhat Satellite+22 | 8/8/2017 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require… | |
| Modificada | Media (5.3) | 3.5% | — | Oracle JDKOracle JREOracle JrockitDebian Linux+24 | 8/8/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple… | |
| Modificada | Crítica (9.8) | 82% | — | NTPDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+3 | 7/8/2017 | 17/6/2026 | Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. | |
| Modificada | Media (6.5) | 31% | 💥 Exploit | NTPDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+5 | 7/8/2017 | 17/6/2026 | The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value. | |
| Modificada | Alta (8.8) | 15% | — | NTPNetapp Oncommand BalanceNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+2 | 7/8/2017 | 17/6/2026 | Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted key file. | |
| Modificada | Crítica (9.8) | 12% | — | NTPNetapp Oncommand BalanceNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+2 | 7/8/2017 | 17/6/2026 | The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative input value. | |
| Modificada | Media (5.9) | 12% | — | NTPDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+10 | 7/8/2017 | 17/6/2026 | ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets. | |
| Modificada | Media (6.5) | 5.6% | — | NTPDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+3 | 7/8/2017 | 17/6/2026 | ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by pointing the key file at the log file. | |
| Modificada | Alta (8.8) | 17% | — | NTPNetapp Oncommand BalanceNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+2 | 7/8/2017 | 17/6/2026 | Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets. | |
| Modificada | Crítica (9.8) | 12% | — | NTPNetapp Oncommand Performance ManagerNetapp Oncommand Unified ManagerNetapp Clustered Data Ontap+4 | 7/8/2017 | 17/6/2026 | The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests. | |
| Modificada | Alta (7.5) | 11% | — | NTPDebian LinuxNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+10 | 7/8/2017 | 17/6/2026 | The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages. | |
| Modificada | Media (6.5) | 5.2% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 7/8/2017 | 17/6/2026 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750. | |
| Modificada | Alta (7.5) | 6.5% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 7/8/2017 | 17/6/2026 | Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (memory consumption). | |
| Modificada | Alta (7.5) | 6.5% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 7/8/2017 | 17/6/2026 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750. | |
| Modificada | Alta (7.5) | 7.1% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 7/8/2017 | 17/6/2026 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750. | |
| Modificada | Alta (7.5) | 13% | — | Apache Http ServerNetapp Clustered Data OntapNetapp Oncommand Unified ManagerDebian Linux+7 | 27/7/2017 | 17/6/2026 | Apache HTTP Server, in all releases prior to 2.2.32 and 2.4.25, was liberal in the whitespace accepted from requests and sent in response lines and headers. Accepting these different behaviors represented a security concern when httpd participates in any chain of proxies or interacts with back-end application servers,… | |
| Modificada | Alta (7.5) | 3.8% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 24/7/2017 | 17/6/2026 | The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to… | |
| Modificada | Media (6.5) | 1.3% | — | Netapp Clustered Data Ontap | 17/7/2017 | 17/6/2026 | NetApp Clustered Data ONTAP before 8.3.2P11, 9.0 before P4, and 9.1 before P5 allow attackers to obtain sensitive password information by leveraging logging of passwords entered non-interactively on the command line. | |
| Modificada | Crítica (9.1) | 4.7% | — | PHPNetapp Clustered Data Ontap | 10/7/2017 | 17/6/2026 | In PHP before 5.6.30 and 7.x before 7.0.15, the PHAR archive handler could be used by attackers supplying malicious archive files to crash the PHP interpreter or potentially disclose information due to a buffer over-read in the phar_parse_pharfile function in ext/phar/phar.c. | |
| Modificada | Alta (7.5) | 0.84% | — | Netapp Clustered Data Ontap | 3/7/2017 | 17/6/2026 | NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state. | |
| Modificada | Alta (7.5) | 1.5% | — | Netapp Data Ontap | 3/7/2017 | 17/6/2026 | NetApp Data ONTAP 8.1 and 8.2, when operating in 7-Mode, allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service via vectors related to the SMB protocol. | |
| Modificada | Alta (7.5) | 57% | — | Apache Http ServerNetapp Clustered Data OntapNetapp Oncommand Unified ManagerNetapp Storagegrid+9 | 20/6/2017 | 17/6/2026 | The HTTP strict parsing changes added in Apache httpd 2.2.32 and 2.4.24 introduced a bug in token list parsing, which allows ap_find_token() to search past the end of its input string. By maliciously crafting a sequence of request headers, an attacker may be able to cause a segmentation fault, or to force… | |
| Modificada | Crítica (9.8) | 20% | — | Apache Http ServerNetapp Clustered Data OntapNetapp Oncommand Unified ManagerNetapp Storagegrid+10 | 20/6/2017 | 17/6/2026 | In Apache httpd 2.2.x before 2.2.33 and 2.4.x before 2.4.26, use of the ap_get_basic_auth_pw() by third-party modules outside of the authentication phase may lead to authentication requirements being bypassed. | |
| Modificada | Crítica (9.8) | 7.5% | — | ZlibOpensuse LeapOpensuseDebian Linux+35 | 23/5/2017 | 14/7/2026 | inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | |
| Modificada | Crítica (9.8) | 3.6% | — | PHPNetapp Clustered Data OntapNetapp Storage Automation Store | 21/5/2017 | 17/6/2026 | The i_zval_ptr_dtor function in Zend/zend_variables.h in PHP 7.1.5 allows attackers to cause a denial of service (memory consumption and application crash) or possibly have unspecified other impact by triggering crafted operations on array data structures. |