Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

4007 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.4%—WiresharkFedoraproject FedoraOpensuse LeapDebian Linux+16/10/202017/6/2026
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.
ModificadaAlta (7.2)3.3%—Linux KernelRedhat Enterprise LinuxOpensuse LeapDebian Linux+26/10/202017/6/2026
A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data…
ModificadaMedia (5.5)0.39%—Linux KernelRedhat Enterprise LinuxOpensuse LeapDebian Linux+16/10/202017/6/2026
A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block…
ModificadaMedia (6.7)0.53%💥 PoCRedhat LibvirtOpensuse Leap6/10/202017/6/2026
A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access control driver. Specifically, clients connecting to the read-write socket with limited ACL…
ModificadaMedia (5.3)1.9%—Nextcloud Preferred ProvidersOpensuse Backports SLEOpensuse Leap5/10/202017/6/2026
A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
ModificadaMedia (5.3)5.0%—PHPFedoraproject FedoraDebian LinuxOpensuse Leap+32/10/202017/6/2026
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host confused with cookies that decode to such prefix, thus leading to an attacker being able to forge…
ModificadaMedia (6.5)2.1%—PHPFedoraproject FedoraDebian LinuxOpensuse Leap+42/10/202017/6/2026
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.
ModificadaAlta (8.8)1.9%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdOpensuse Leap+11/10/202017/6/2026
When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClippedCompositionBounds did not follow iterator invalidation rules. This vulnerability affects Firefox < 81, Thunderbird <…
ModificadaMedia (6.1)1.7%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux+11/10/202017/6/2026
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than the site the file was actually downloaded from. This vulnerability affects Firefox < 81, Thunderbird…
ModificadaMedia (6.1)1.6%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux+11/10/202017/6/2026
Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and Firefox ESR < 78.3.
ModificadaAlta (8.8)2.0%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux+11/10/202017/6/2026
Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81, Thunderbird < 78.3, and…
ModificadaAlta (8.8)0.43%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap30/9/202017/6/2026
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a virtual machine to write arbitrary data to any address in the vhost_crypto application. The highest threat from this vulnerability is to data…
ModificadaBaja (3.3)0.40%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap30/9/202017/6/2026
An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used…
ModificadaAlta (7.1)0.41%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap30/9/202017/6/2026
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to a buffer over read. The results of the over read are then written back to the guest virtual machine memory. This vulnerability can be used by an attacker in a virtual…
ModificadaAlta (7.8)0.40%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap30/9/202017/6/2026
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a large buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
ModificadaAlta (7.8)0.25%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap30/9/202017/6/2026
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the virtual machine and the host. An attacker in a VM can change the contents of the memory after vhost_crypto has validated it. The highest…
ModificadaCrítica (9.8)3.6%—Libproxy Project LibproxyFedoraproject FedoraDebian LinuxOpensuse Leap30/9/202017/6/2026
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
ModificadaAlta (8.1)3.1%—TigervncDebian LinuxOpensuse Leap27/9/202017/6/2026
In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.
ModificadaAlta (7.2)6.4%—PythonFedoraproject FedoraCanonical Ubuntu LinuxNetapp Solidfire+427/9/202017/6/2026
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
ModificadaMedia (4.8)0.92%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/output tensors. The flatbuffer format uses indices for the tensors,…
ModificadaMedia (6.5)0.74%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and will release patch…
ModificadaMedia (5.9)0.80%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to convert a read-only tensor to a read-write one. The runtime…
ModificadaCrítica (9.8)0.91%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation modes. Since the function always returns the dimension of the first tensor, malicious attackers can craft cases where…
ModificadaCrítica (9)1.2%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing with negative values, TFLite uses `ResolveAxis` to convert negative values to positive indices. However, the only check that the converted index is now valid is only present in debug builds. If the `DCHECK` does not…
ModificadaAlta (7.5)0.96%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of required keys results in segfaults and data corruption while loading the model. This can cause a denial of service in products using `tensorflow-serving` or other…