Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
354 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 8.3% | — | Haxx CurlHaxx LibcurlHP System Management HomepageOracle Enterprise Manager OPS Center+1 | 22/6/2015 | 17/6/2026 | The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values. | |
| Modificada | Media (5) | 7.2% | — | Haxx CurlHaxx Libcurl | 22/6/2015 | 17/6/2026 | cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same host name, which allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.60% | — | Docker LibcontainerOpensuse | 18/5/2015 | 17/6/2026 | Libcontainer 1.6.0, as used in Docker Engine, allows local users to escape containerization ("mount namespace breakout") and write to arbitrary file on the host system via a symlink attack in an image when respawning a container. | |
| Modificada | Alta (7.2) | 0.61% | — | DockerDocker Libcontainer | 18/5/2015 | 17/6/2026 | Libcontainer and Docker Engine before 1.6.1 opens the file-descriptor passed to the pid-1 process before performing the chroot, which allows local users to gain privileges via a symlink attack in an image. | |
| Modificada | Media (5) | 7.3% | — | Oracle Enterprise Manager OPS CenterHaxx CurlHaxx LibcurlCanonical Ubuntu Linux+2 | 1/5/2015 | 17/6/2026 | The default configuration for cURL and libcurl before 7.42.1 sends custom HTTP headers to both the proxy and destination server, which might allow remote proxy servers to obtain sensitive information by reading the header contents. | |
| Modificada | Media (5) | 14% | — | Fedoraproject FedoraCanonical Ubuntu LinuxDebian LinuxApple MAC OS X+4 | 24/4/2015 | 17/6/2026 | cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request. | |
| Modificada | Alta (7.5) | 37% | — | Fedoraproject FedoraCanonical Ubuntu LinuxDebian LinuxHaxx Curl+5 | 24/4/2015 | 17/6/2026 | The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character. | |
| Modificada | Alta (9) | 11% | — | Oracle Mysql Enterprise MonitorHaxx CurlHaxx LibcurlCanonical Ubuntu Linux+1 | 24/4/2015 | 17/6/2026 | The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80." | |
| Modificada | Media (5) | 13% | — | Haxx CurlCanonical Ubuntu LinuxDebian LinuxHaxx Libcurl+2 | 24/4/2015 | 17/6/2026 | cURL and libcurl 7.10.6 through 7.41.0 does not properly re-use NTLM connections, which allows remote attackers to connect as other users via an unauthenticated request, a similar issue to CVE-2014-0015. | |
| Modificada | Media (6.4) | 2.1% | — | Canonical Ubuntu LinuxGNU Glibc | 8/4/2015 | 17/6/2026 | The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during a risk-management decision for use of the alloca function, which might allow context-dependent attackers to cause a denial of service (segmentation violation) or overwrite… | |
| Modificada | Alta (7.5) | 4.7% | — | Canonical Ubuntu LinuxGNU Glibc | 8/4/2015 | 17/6/2026 | The ADDW macro in stdio-common/vfscanf.c in the GNU C Library (aka glibc or libc6) before 2.21 does not properly consider data-type size during memory allocation, which allows context-dependent attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a long line containing… | |
| Modificada | Media (5) | 5.6% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerGNU GlibcCanonical Ubuntu Linux | 27/3/2015 | 17/6/2026 | DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up on a database while iterating over it, which triggers… | |
| Modificada | Alta (7.8) | 7.8% | — | GNU GlibcCanonical Ubuntu LinuxOpensuse | 24/2/2015 | 17/6/2026 | The nss_dns implementation of getnetbyname in GNU C Library (aka glibc) before 2.21, when the DNS backend in the Name Service Switch configuration is enabled, allows remote attackers to cause a denial of service (infinite loop) by sending a positive answer while a network name is being process. | |
| Modificada | Media (5) | 5.8% | — | Redhat Enterprise Linux Server AUSCanonical Ubuntu LinuxOpensuseGNU Glibc | 24/2/2015 | 17/6/2026 | The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function. | |
| Modificada | Alta (10) | 95% | 💥 Exploit | GNU GlibcOracle Communications Application Session ControllerOracle Communications Eagle Application ProcessorOracle Communications Eagle LNP Application Processor+14 | 28/1/2015 | 17/6/2026 | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST." | |
| Modificada | Media (5.8) | 1.1% | — | Apple MAC OS XHaxx Libcurl | 15/1/2015 | 17/6/2026 | The darwinssl_connect_step1 function in lib/vtls/curl_darwinssl.c in libcurl 7.31.0 through 7.39.0, when using the DarwinSSL (aka SecureTransport) back-end for TLS, does not check if a cached TLS session validated the certificate when reusing the session, which allows man-in-the-middle attackers to spoof servers via a… | |
| Modificada | Media (4.3) | 6.8% | — | Debian LinuxHaxx LibcurlCanonical Ubuntu Linux | 15/1/2015 | 17/6/2026 | CRLF injection vulnerability in libcurl 6.0 through 7.x before 7.40.0, when using an HTTP proxy, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in a URL. | |
| Modificada | Media (5) | 6.6% | — | GNU Glibc | 5/12/2014 | 17/6/2026 | GNU C Library (aka glibc) before 2.20 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a multibyte character value of "0xffff" to the iconv function when converting (1) IBM933, (2) IBM935, (3) IBM937, (4) IBM939, or (5) IBM1364 encoded data to UTF-8. | |
| Modificada | Media (5) | 3.4% | — | Debian LinuxCanonical Ubuntu LinuxGNU Glibc | 5/12/2014 | 16/6/2026 | iconvdata/ibm930.c in GNU C Library (aka glibc) before 2.16 allows context-dependent attackers to cause a denial of service (out-of-bounds read) via a multibyte character value of "0xffff" to the iconv function when converting IBM930 encoded data to UTF-8. | |
| Modificada | Media (4.3) | 1.1% | — | Springshare Libcal | 1/12/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in api_events.php in Springshare LibCal 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) m or (2) cid parameter. | |
| Modificada | Media (4.6) | 0.58% | — | Canonical Ubuntu LinuxDebian LinuxGNU GlibcOpensuse | 24/11/2014 | 17/6/2026 | The wordexp function in GNU C Library (aka glibc) 2.21 does not enforce the WRDE_NOCMD flag, which allows context-dependent attackers to execute arbitrary commands, as demonstrated by input containing "$((`...`))". | |
| Modificada | Media (5) | 4.2% | — | Haxx CurlHaxx LibcurlApple MAC OS X | 18/11/2014 | 17/6/2026 | cURL and libcurl before 7.38.0 allow remote attackers to bypass the Same Origin Policy and set cookies for arbitrary sites by setting a cookie for a top-level domain. | |
| Modificada | Media (5) | 7.1% | — | Haxx CurlHaxx LibcurlApple MAC OS X | 18/11/2014 | 17/6/2026 | cURL and libcurl before 7.38.0 does not properly handle IP addresses in cookie domain names, which allows remote attackers to set cookies for or send arbitrary cookies to certain sites, as demonstrated by a site at 192.168.0.1 setting cookies for a site at 127.168.0.1. | |
| Modificada | Media (4.3) | 5.1% | — | Canonical Ubuntu LinuxApple MAC OS XOpensuseOracle Hyperion+2 | 15/11/2014 | 17/6/2026 | The curl_easy_duphandle function in libcurl 7.17.1 through 7.38.0, when running with the CURLOPT_COPYPOSTFIELDS option, does not properly copy HTTP POST data for an easy handle, which triggers an out-of-bounds read that allows remote web servers to read sensitive memory information. | |
| Modificada | Media (6.8) | 8.5% | 💥 Exploit | GNU GlibcGNU Eglibc | 27/10/2014 | 16/6/2026 | Integer signedness error in Glibc before 2.13 and eglibc before 2.13, when using Supplemental Streaming SIMD Extensions 3 (SSSE3) optimization, allows context-dependent attackers to execute arbitrary code via a negative length parameter to (1) memcpy-ssse3-rep.S, (2) memcpy-ssse3.S, or (3) memset-sse2.S in… |