Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

368 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6)0.44%—QemuDebian LinuxOpensuse LeapRedhat Openstack+14/11/201617/6/2026
The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position.
ModificadaMedia (6)0.36%—QemuOpensuse LeapRedhat OpenstackRedhat Virtualization+14/11/201617/6/2026
The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider greater than baud base.
ModificadaMedia (6)0.40%—QemuOpensuse LeapRedhat OpenstackRedhat Virtualization+14/11/201617/6/2026
The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process.
ModificadaBaja (3.3)0.35%—Redhat Enterprise Virtualization3/10/201617/6/2026
The ovirt-engine-provisiondb utility in Red Hat Enterprise Virtualization (RHEV) Engine 4.0 allows local users to obtain sensitive database provisioning information by reading log files.
ModificadaAlta (8.1)7.2%—HP Converged Infrastructure Solution Sizer SuiteHP Insight Management SizerHP Power AdvisorHP SAP Sizing Tool+1122/8/201617/6/2026
HPE Smart Update in Storage Sizing Tool before 13.0, Converged Infrastructure Solution Sizer Suite (CISSS) before 2.13.1, Power Advisor before 7.8.2, Insight Management Sizer before 16.12.1, Synergy Planning Tool before 3.3, SAP Sizing Tool before 16.12.1, Sizing Tool for SAP Business Suite powered by HANA before…
ModificadaMedia (5.5)0.52%—Canonical Ubuntu LinuxOracle LinuxOracle VM ServerQemu+92/8/201617/6/2026
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
ModificadaMedia (5.7)1.0%—Symantec Workspace StreamingSymantec Workspace Virtualization12/7/201617/6/2026
The management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to read arbitrary files by modifying the file-download configuration file.
ModificadaMedia (5.7)1.8%—Symantec Workspace StreamingSymantec Workspace Virtualization12/7/201617/6/2026
Directory traversal vulnerability in the file-download configuration file in the management console in Symantec Workspace Streaming (SWS) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 and Symantec Workspace Virtualization (SWV) 7.5.x before 7.5 SP1 HF9 and 7.6.0 before 7.6 HF5 allows remote authenticated users to…
ModificadaMedia (4.7)1.4%—Solarwinds Virtualization Manager24/6/201617/6/2026
SolarWinds Virtualization Manager 6.3.1 and earlier uses weak encryption to store passwords in /etc/shadow, which allows local users with superuser privileges to obtain user passwords via a brute force attack.
AnalizadaAlta (7.8)3.7%⚠ Explotación activa💥 ExploitSolarwinds Virtualization Manager17/6/201617/6/2026
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguration of sudo, as demonstrated by "sudo cat /etc/passwd."
ModificadaCrítica (9.8)13%—Solarwinds Virtualization Manager17/6/201617/6/2026
The RMI service in SolarWinds Virtualization Manager 6.3.1 and earlier allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
ModificadaAlta (7.8)0.70%—QemuCanonical Ubuntu LinuxOracle LinuxDebian Linux+81/6/201617/6/2026
Heap-based buffer overflow in the iscsi_aio_ioctl function in block/iscsi.c in QEMU allows local guest OS users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code via a crafted iSCSI asynchronous I/O ioctl call.
ModificadaMedia (6.5)0.37%—QemuCanonical Ubuntu LinuxDebian LinuxRedhat Openstack+725/5/201617/6/2026
The patch_instruction function in hw/i386/kvmvapic.c in QEMU does not initialize the imm32 variable, which allows local guest OS administrators to obtain sensitive information from host stack memory by accessing the Task Priority Register (TPR).
ModificadaAlta (8.8)0.92%—Debian LinuxHP Helion OpenstackCanonical Ubuntu LinuxQemu+1111/5/201617/6/2026
The VGA module in QEMU improperly performs bounds checking on banked access to video memory, which allows local guest OS administrators to execute arbitrary code on the host by changing access modes after setting the bank register, aka the "Dark Portal" issue.
ModificadaAlta (8.4)0.56%—QemuCanonical Ubuntu LinuxDebian LinuxRedhat Openstack+712/4/201617/6/2026
The net_checksum_calculate function in net/checksum.c in QEMU allows local guest OS users to cause a denial of service (out-of-bounds heap read and crash) via the payload length in a crafted packet.
ModificadaAlta (8.8)0.53%—QemuRedhat OpenstackRedhat VirtualizationDebian Linux12/4/201617/6/2026
Use-after-free vulnerability in hw/ide/ahci.c in QEMU, when built with IDE AHCI Emulation support, allows guest OS users to cause a denial of service (instance crash) or possibly execute arbitrary code via an invalid AHCI Native Command Queuing (NCQ) AIO command.
ModificadaAlta (8.6)6.6%—QemuCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+712/1/201617/6/2026
The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
ModificadaCrítica (9)7.7%—QemuRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+58/1/201617/6/2026
Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet.
ModificadaBaja (3.7)0.33%—Redhat Enterprise Virtualization8/9/201517/6/2026
The Web Admin interface in Red Hat Enterprise Virtualization Manager (RHEV-M) allows local users to bypass the timeout function by selecting a VM in the VM grid view.
ModificadaMedia (6.9)1.6%💥 ExploitQemuLinux KernelArista EOSDebian Linux+1531/8/201517/6/2026
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
ModificadaAlta (9.3)13%—XENFedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise Server+2012/8/201517/6/2026
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
ModificadaAlta (7.5)2.1%—Oracle Virtualization SUN RAY16/7/201517/6/2026
Unspecified vulnerability in Oracle Virtualization Sun Ray Software before 5.4.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Web Console.
ModificadaMedia (6.4)2.2%—Oracle Virtualization16/7/201517/6/2026
Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.1 and 5.2 allows remote attackers to affect confidentiality and availability via unknown vectors related to JServer.
ModificadaMedia (5)1.3%—IBM Rational Test Virtualization ServerIBM Rational Test Workbench30/6/201517/6/2026
Rational Test Control Panel in IBM Rational Test Workbench and Rational Test Virtualization Server 8.0.0.x before 8.0.0.5, 8.0.1.x before 8.0.1.6, 8.5.0.x before 8.5.0.4, 8.5.1.x before 8.5.1.5, 8.6.0.x before 8.6.0.4, and 8.7.0.x before 8.7.0.2 uses the MD5 algorithm for password hashing, which makes it easier for…
ModificadaAlta (7.2)0.58%—Cisco Virtualization Experience Client 6000 Series Firmware17/6/201517/6/2026
The diagnostics subsystem in the administrative web interface on Cisco Virtualization Experience (aka VXC) Client 6215 devices with firmware 11.2(27.4) allows local users to gain privileges for OS command execution via a crafted option value, aka Bug ID CSCug54412.
Orbitaley — Vulnerabilidades