Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
593 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.37% | — | Freebsd | 15/2/2017 | 17/6/2026 | The Linux compatibility layer in the kernel in FreeBSD 9.3, 10.1, and 10.2 allows local users to read portions of kernel memory and potentially gain privilege via unspecified vectors, related to "handling of Linux futex robust lists." | |
| Modificada | Media (5.5) | 0.50% | — | Freebsd | 7/2/2017 | 17/6/2026 | bsnmpd, as used in FreeBSD 9.3, 10.1, and 10.2, uses world-readable permissions on the snmpd.config file, which allows local users to obtain the secret key for USM authentication by reading the file. | |
| Modificada | Media (5.3) | 15% | — | NTPDebian LinuxNetapp Clustered Data OntapNetapp Data Ontap+13 | 30/1/2017 | 17/6/2026 | The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value. | |
| Modificada | Media (5.9) | 6.3% | — | NTPOracle LinuxSiemens TIM 4r-ie FirmwareSiemens TIM 4r-ie Dnp3 Firmware+6 | 30/1/2017 | 17/6/2026 | ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command. | |
| Modificada | Media (6.5) | 3.4% | — | NTPSiemens TIM 4r-ie FirmwareSiemens TIM 4r-ie Dnp3 FirmwareFreebsd+3 | 30/1/2017 | 17/6/2026 | NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network. | |
| Modificada | Alta (8.8) | 7.5% | — | Redhat OpenshiftFreebsdRedhat Enterprise LinuxLibgd+2 | 7/8/2016 | 17/6/2026 | Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified… | |
| Modificada | Alta (7.8) | 1.1% | 💥 Exploit | Freebsd | 25/5/2016 | 17/6/2026 | Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to cause a denial of service (memory overwrite and kernel panic) or gain privileges via a negative buflen argument, which triggers a heap-based buffer… | |
| Modificada | Alta (7.8) | 1.1% | 💥 Exploit | Freebsd | 25/5/2016 | 17/6/2026 | Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before p34, 10.2 before p17, and 10.3 before p3 allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory overwrite and kernel crash), or gain privileges via a… | |
| Modificada | Media (6.2) | 1.3% | 💥 Exploit | Freebsd | 12/4/2016 | 17/6/2026 | Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1 before p31, and 10.2 before p14 allows local users to cause a denial of service (kernel panic) via an i386_set_ldt system call, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 1.9% | — | Freebsd | 29/1/2016 | 17/6/2026 | FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9 allow remote attackers to cause a denial of service (kernel crash) via vectors related to creating a TCP connection with the TCP_MD5SIG and TCP_NOOPT socket options. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Freebsd | 29/1/2016 | 17/6/2026 | The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, when the kernel is configured for IPv6, allows remote attackers to cause a denial of service (assertion failure or NULL pointer dereference and kernel panic) via a crafted ICMPv6 packet. | |
| Modificada | Media (6.9) | 0.49% | — | Apple Iphone OSFreebsdApple MAC OS X | 18/9/2015 | 17/6/2026 | The __sflush function in fflush.c in stdio in libc in FreeBSD 10.1 and the kernel in Apple iOS before 9 mishandles failures of the write system call, which allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via a crafted application. | |
| Modificada | Baja (2.1) | 0.35% | — | Freebsd | 10/4/2015 | 17/6/2026 | The bsdinstall installer in FreeBSD 10.x before 10.1 p9, when configuring full disk encrypted ZFS, uses world-readable permissions for the GELI keyfile (/boot/encryption.key), which allows local users to obtain sensitive key information by reading the file. | |
| Modificada | Alta (7.8) | 4.2% | — | Netgate PfsenseDebian LinuxFreebsd | 27/2/2015 | 17/6/2026 | Integer overflow in FreeBSD before 8.4 p24, 9.x before 9.3 p10. 10.0 before p18, and 10.1 before p6 allows remote attackers to cause a denial of service (crash) via a crafted IGMP packet, which triggers an incorrect size calculation and allocation of insufficient memory. | |
| Modificada | Alta (7.8) | 2.8% | — | Freebsd | 2/2/2015 | 17/6/2026 | The sctp module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allows remote attackers to cause a denial of service (NULL pointer dereference and kernel panic) via a crafted RE_CONFIG chunk. | |
| Modificada | Media (4.6) | 0.90% | 💥 Exploit | Freebsd | 2/2/2015 | 17/6/2026 | Multiple array index errors in the Stream Control Transmission Protocol (SCTP) module in FreeBSD 10.1 before p5, 10.0 before p17, 9.3 before p9, and 8.4 before p23 allow local users to (1) gain privileges via the stream id to the setsockopt function, when setting the SCTIP_SS_VALUE option, or (2) read arbitrary kernel… | |
| Modificada | Alta (7.2) | 0.92% | 💥 Exploit | Freebsd | 2/2/2015 | 17/6/2026 | Integer signedness error in the vt console driver (formerly Newcons) in FreeBSD 9.3 before p10 and 10.1 before p6 allows local users to cause a denial of service (crash) and possibly gain privileges via a negative value in a VT_WAITACTIVE ioctl call, which triggers an array index error and out-of-bounds kernel memory… | |
| Modificada | Media (5) | 5.9% | — | File Project FileFreebsdMageiaCanonical Ubuntu Linux | 17/12/2014 | 17/6/2026 | softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors. | |
| Modificada | Media (5) | 4.4% | — | File Project FileFreebsdMageiaCanonical Ubuntu Linux | 17/12/2014 | 17/6/2026 | The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities. | |
| Modificada | Media (5) | 4.7% | — | BSDFreebsdNetbsdOpenbsd | 12/12/2014 | 17/6/2026 | The TCP stack in 4.3BSD Net/2, as used in FreeBSD 5.4, NetBSD possibly 2.0, and OpenBSD possibly 3.6, does not properly implement the session timer, which allows remote attackers to cause a denial of service (resource consumption) via crafted packets. | |
| Modificada | Media (4.3) | 1.7% | — | Freebsd | 18/11/2014 | 17/6/2026 | FreeBSD 9.1, 9.2, and 10.0, when compiling OpenSSH with Kerberos support, uses incorrect library ordering when linking sshd, which causes symbols to be resolved incorrectly and allows remote attackers to cause a denial of service (sshd deadlock and prevention of new connections) by ending multiple connections before… | |
| Modificada | Baja (2.1) | 0.39% | — | Freebsd | 13/11/2014 | 17/6/2026 | The setlogin function in FreeBSD 8.4 through 10.1-RC4 does not initialize the buffer used to store the login name, which allows local users to obtain sensitive information from kernel memory via a call to getlogin, which returns the entire buffer. | |
| Modificada | Media (5) | 1.6% | — | Freebsd | 27/10/2014 | 17/6/2026 | routed in FreeBSD 8.4 through 10.1-RC2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an RIP request from a source not on a directly connected network. | |
| Modificada | Alta (10) | 3.9% | — | Freebsd | 27/10/2014 | 17/6/2026 | Stack-based buffer overflow in rtsold in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via crafted DNS parameters in a router advertisement message. | |
| Modificada | Media (5) | 1.6% | — | Freebsd | 27/10/2014 | 17/6/2026 | namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vectors that trigger a sandboxed process to look up a large number of nonexistent path names. |