Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.7% | — | Netapp Clustered Data Ontap | 10/4/2017 | 17/6/2026 | NetApp OnCommand Performance Manager and OnCommand Unified Manager for Clustered Data ONTAP before 7.1P1 improperly bind the Java Management Extension Remote Method Invocation (aka JMX RMI) service to the network, which allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.7% | — | Netapp Clustered Data Ontap | 10/4/2017 | 17/6/2026 | NetApp Clustered Data ONTAP 8.1 through 9.1P1, when NFS or SMB is enabled, allows remote attackers to cause a denial of service via unspecified vectors. | |
| Modificada | Alta (8.8) | 2.1% | — | Netapp Data Ontap | 1/3/2017 | 17/6/2026 | NetApp Data ONTAP 9.0 and 9.1 before 9.1P1 allows remote authenticated users that own SMB-hosted data to bypass intended sharing restrictions by leveraging improper handling of the owner_rights ACL entry. | |
| Modificada | Crítica (9.8) | 2.9% | — | Netapp Oncommand Unified Manager FOR Clustered Data Ontap | 7/2/2017 | 17/6/2026 | NetApp OnCommand Unified Manager for Clustered Data ONTAP 6.3 through 6.4P1 contain a default privileged account, which allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5.9) | 1.5% | — | Netapp Data Ontap | 7/2/2017 | 17/6/2026 | NetApp Data ONTAP before 8.2.4P5, when operating in 7-Mode, allows remote attackers to obtain information about the volumes configured for HTTP access. | |
| Modificada | Alta (7.5) | 1.9% | — | Netapp Clustered Data Ontap | 7/2/2017 | 17/6/2026 | NetApp Clustered Data ONTAP before 8.3.2P7 allows remote attackers to obtain SMB share information via unspecified vectors. | |
| Modificada | Alta (8.8) | 2.5% | — | Netapp Data Ontap | 7/2/2017 | 17/6/2026 | NetApp OnCommand System Manager 8.3.x before 8.3.2 allows remote authenticated users to execute arbitrary code via unspecified vectors. | |
| Modificada | Media (5.3) | 15% | — | NTPDebian LinuxNetapp Clustered Data OntapNetapp Data Ontap+13 | 30/1/2017 | 17/6/2026 | The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value. | |
| Modificada | Media (5.9) | 6.3% | — | NTPOracle LinuxSiemens TIM 4r-ie FirmwareSiemens TIM 4r-ie Dnp3 Firmware+6 | 30/1/2017 | 17/6/2026 | ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command. | |
| Modificada | Media (6.5) | 3.4% | — | NTPSiemens TIM 4r-ie FirmwareSiemens TIM 4r-ie Dnp3 FirmwareFreebsd+3 | 30/1/2017 | 17/6/2026 | NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network. | |
| Modificada | Crítica (9.8) | 7.4% | — | PHPNetapp Clustered Data OntapDebian Linux | 24/1/2017 | 17/6/2026 | Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP before 5.6.30 and 7.0.x before 7.0.15 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archive with an alias mismatch. | |
| Modificada | Alta (7.5) | 41% | — | ISC BindDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+8 | 12/1/2017 | 17/6/2026 | named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query. | |
| Modificada | Baja (3.7) | 1.4% | — | Netapp Clustered Data Ontap | 11/1/2017 | 17/6/2026 | Clustered Data ONTAP versions 8.0, 8.3.1, and 8.3.2 contain a default privileged account which under certain conditions can be used for unauthorized information disclosure. | |
| Modificada | Crítica (9.8) | 42% | — | PHPNetapp Clustered Data Ontap | 11/1/2017 | 17/6/2026 | The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data. | |
| Modificada | Crítica (9.8) | 17% | — | PHPNetapp Clustered Data Ontap | 11/1/2017 | 17/6/2026 | Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted… | |
| Analizada | Alta (7.5) | 6.1% | — | Netapp Clustered Data OntapNetapp Data Ontap Operating IN 7-modeNetapp Oncommand BalanceNetapp Oncommand Performance Manager+2 | 6/1/2017 | 17/6/2026 | An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authentication code and a valid timestamp. When processed by the NTP daemon, it leads to an immediate crash. | |
| Analizada | Alta (7) | 84% | ⚠ Explotación activa💥 Exploit | Canonical Ubuntu LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux AUS+14 | 10/11/2016 | 17/6/2026 | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW." | |
| Modificada | Alta (7.5) | 39% | — | ISC BindNetapp Data Ontap EdgeNetapp SolidfireNetapp Steelstore Cloud Integrated Storage+7 | 2/11/2016 | 17/6/2026 | named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c. | |
| Modificada | Alta (8.1) | 1.9% | — | Ietf Transport Layer SecurityNetapp Clustered Data Ontap Antivirus ConnectorNetapp Data Ontap EdgeNetapp Host Agent+9 | 21/9/2016 | 17/6/2026 | The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which… | |
| Modificada | Media (6.5) | 1.8% | — | Netapp Clustered Data Ontap | 1/9/2016 | 17/6/2026 | NetApp Clustered Data ONTAP before 8.2.4P4 and 8.3.x before 8.3.2P2 allows remote authenticated users to obtain sensitive cluster and tenant information via unspecified vectors. | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa | Oracle JDKOracle JREOracle JrockitOracle Linux+34 | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. | |
| Modificada | Media (6.8) | 0.58% | — | Netapp Clustered Data Ontap | 7/4/2016 | 17/6/2026 | NetApp Clustered Data ONTAP 8.3.1 does not properly verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.7) | 5.7% | — | NTPSiemens TIM 4r-ie FirmwareSiemens TIM 4r-ie Dnp3 FirmwareNetapp Clustered Data Ontap+2 | 26/1/2016 | 17/6/2026 | NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key." | |
| Modificada | Baja (3.7) | 1.2% | — | Netapp Data Ontap | 18/1/2016 | 17/6/2026 | NetApp Data ONTAP before 8.2.4P1, when 7-Mode and HTTP access are enabled, allows remote attackers to obtain sensitive volume information via unspecified vectors. | |
| Modificada | Alta (10) | 3.4% | — | Netapp Data Ontap | 28/7/2008 | 16/6/2026 | Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may… |