Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
334 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 2.7% | 💥 PoC | Google AndroidApple Iphone OSApple MAC OS XApple Tvos+143 | 14/8/2019 | 17/6/2026 | The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the… | |
| Modificada | Alta (7.5) | 95% | — | Linux KernelF5 Big-ip Advanced Firewall ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Application Acceleration Manager+20 | 19/6/2019 | 17/6/2026 | Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182,… | |
| Modificada | Alta (7.5) | 99% | 💥 PoC | Linux KernelF5 Big-ip Advanced Firewall ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Application Acceleration Manager+20 | 19/6/2019 | 17/6/2026 | Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127,… | |
| Modificada | Alta (7.8) | 0.57% | — | Projectatomic Bubblewrap | 29/5/2019 | 17/6/2026 | bubblewrap.c in Bubblewrap before 0.3.3 misuses temporary directories in /tmp as a mount point. In some particular configurations (related to XDG_RUNTIME_DIR), a local attacker may abuse this flaw to prevent other users from executing bubblewrap or potentially execute code. | |
| Modificada | Media (4.3) | 1.2% | — | Matomo | 20/5/2019 | 17/6/2026 | A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path of Matomo on the disk, because lastError.file is used in plugins/CorePluginsAdmin/templates/safemode.twig. NOTE: the vendor disputes the significance of this issue, stating "avoid… | |
| Modificada | Media (4.4) | 0.35% | — | Intel J5005 FirmwareIntel J4205 FirmwareIntel J3710 FirmwareIntel N3540 Firmware+24 | 17/5/2019 | 17/6/2026 | Insufficient key protection vulnerability in silicon reference firmware for Intel(R) Pentium(R) Processor J Series, Intel(R) Pentium(R) Processor N Series, Intel(R) Celeron(R) J Series, Intel(R) Celeron(R) N Series, Intel(R) Atom(R) Processor A Series, Intel(R) Atom(R) Processor E3900 Series, Intel(R) Pentium(R)… | |
| Modificada | Media (5.6) | 8.6% | — | Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+221 | 10/7/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis. | |
| Modificada | Alta (7.6) | 0.37% | — | Intel Xeon E3Intel Xeon E3 1220 V5Intel Xeon E3 1220 V6Intel Xeon E3 1225 V5+30 | 10/7/2018 | 17/6/2026 | Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces. | |
| Modificada | Alta (8.1) | 1.7% | — | Atom-node-module-installer Project Atom-node-module-installer | 1/6/2018 | 17/6/2026 | atom-node-module-installer installs node modules for atom-shell applications. atom-node-module-installer binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the… | |
| Modificada | Media (5.6) | 7.5% | — | Intel Atom CIntel Atom EIntel Atom ZIntel Celeron J+195 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a. | |
| Modificada | Media (5.5) | 61% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… | |
| Modificada | Alta (8.8) | 34% | 💥 Exploit | Cognitect DatomicH2database H2 | 11/4/2018 | 17/6/2026 | H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment." | |
| Modificada | Media (6) | 0.34% | — | Intel Core I7-8550uIntel Core I7-8559uIntel Core I7-8650uIntel Core I7-8700+304 | 3/4/2018 | 17/6/2026 | Configuration of SPI Flash in platforms based on multiple Intel platforms allow a local attacker to alter the behavior of the SPI flash potentially leading to a Denial of Service. | |
| Modificada | Media (5.6) | 0.67% | — | Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+205 | 27/3/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (PHT), aka BranchScope. | |
| Modificada | Alta (8.8) | 84% | 💥 Exploit | Atom Electron | 24/1/2018 | 17/6/2026 | GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially… | |
| Modificada | Media (5.6) | 84% | 💥 PoC | Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+205 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache. | |
| Modificada | Media (5.6) | 94% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Media (5.6) | 74% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+216 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Media (4.3) | 0.98% | — | Atom Electron | 2/1/2018 | 17/6/2026 | Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control. | |
| Modificada | Crítica (10) | 3.2% | — | Projectatomic Bubblewrap | 29/3/2017 | 17/6/2026 | When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox. | |
| Modificada | Baja (3.3) | 0.40% | — | Projectatomic Oci-register-machine | 29/3/2017 | 17/6/2026 | The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Alta (7.8) | 0.43% | — | Atom Electron | 25/4/2016 | 17/6/2026 | Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line. |