Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

4007 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.0%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap overflow errors and even leak contents of memory In the linked code snippet, all the binary strings after `ee ff` are…
ModificadaMedia (5.3)0.90%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In eager mode, TensorFlow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1 does not set the session state. Hence, calling `tf.raw_ops.GetSessionHandle` or `tf.raw_ops.GetSessionHandleV2` results in a null pointer dereference In linked snippet, in eager mode, `ctx->session_state()` returns `nullptr`. Since code…
ModificadaAlta (7.5)0.97%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, by controlling the `fill` argument of tf.strings.as_string, a malicious attacker is able to trigger a format string vulnerability due to the way the internal format use in a `printf` call is constructed. This may result in segmentation fault. The…
ModificadaCrítica (9)1.3%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking two `int64` (i.e., `long long`) arguments. However, there are several places in TensorFlow where a lambda taking `int` or `int32` arguments is being used. In these cases,…
ModificadaAlta (8.8)0.95%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the implementation of `SparseFillEmptyRowsGrad` uses a double indexing pattern. It is possible for `reverse_index_map(i)` to be an index outside of bounds of `grad_values`, thus resulting in a heap buffer overflow. The issue is patched in commit…
ModificadaMedia (5.3)1.0%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the shapes of its arguments. Although `reverse_index_map_t` and `grad_values_t` are accessed in a similar pattern, only `reverse_index_map_t` is validated to be of proper…
ModificadaAlta (7.1)0.83%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized memory resulting in further memory corruption. This is because the pybind11 glue code assumes that the argument is a tensor. However, there is nothing stopping users from passing in a Python object…
ModificadaMedia (4.3)0.83%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpack` there is a memory leak following an expected validation failure. The issue occurs because the `status` argument during validation failures is not properly checked. Since each of the above methods can return an error…
ModificadaMedia (5.3)0.90%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes an invalid argument to `dlpack.to_dlpack` the expected validations will cause variables to bind to `nullptr` while setting a `status` variable to the error condition. However, this `status` argument is not properly checked. Hence, code following these…
ModificadaMedia (5.3)0.94%—Google TensorflowOpensuse Leap25/9/202017/6/2026
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operation takes as input a tensor and a boolean and outputs two tensors. Depending on the boolean value, one of the tensors is exactly the input tensor whereas the other one should be an empty tensor. However, the eager…
ModificadaMedia (6.1)0.97%—Redhat PagureOpensuse Backports SLEOpensuse Leap25/9/202017/6/2026
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
ModificadaMedia (5.5)0.40%—Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux24/9/202017/6/2026
A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.
ModificadaMedia (4.7)0.26%—XENFedoraproject FedoraDebian LinuxOpensuse Leap23/9/202017/6/2026
An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. When migrating timers of x86 HVM guests between its vCPUs, the locking model used allows for a second vCPU of the same guest (also operating on the timers) to release a lock that it didn't acquire. The…
ModificadaAlta (7.8)0.41%—XENFedoraproject FedoraOpensuse LeapDebian Linux23/9/202017/6/2026
An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event channel. Event channels control structures can be accessed lockless as long as the port is considered to be valid. Such a sequence is missing an appropriate memory barrier (e.g., smp_*mb()) to prevent…
ModificadaMedia (6)0.32%—XENFedoraproject FedoraDebian LinuxOpensuse Leap23/9/202017/6/2026
An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to MSR_MISC_ENABLE. When a guest accesses certain Model Specific Registers, Xen first reads the value from hardware to use as the basis for auditing the guest access. For the MISC_ENABLE MSR, which is…
ModificadaMedia (5.5)0.42%—XENDebian LinuxFedoraproject FedoraOpensuse Leap23/9/202017/6/2026
An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In particular, the FIFO event channel model allows guests to have a large number of event channels active at a time. Closing all of these (when resetting all event channels or when cleaning up after the…
ModificadaMedia (5.5)0.43%—XENFedoraproject FedoraOpensuse LeapDebian Linux23/9/202017/6/2026
An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel model imposes different limits on the number of usable event channels for 32-bit x86 domains vs 64-bit or Arm (either bitness) ones. 32-bit x86 domains can use only 1023…
ModificadaAlta (7)0.29%—XENFedoraproject FedoraOpensuse LeapDebian Linux23/9/202017/6/2026
An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory accesses or…
ModificadaMedia (5.5)0.42%—XENFedoraproject FedoraOpensuse Leap23/9/202017/6/2026
An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Read, Copy, Update) mechanism is a synchronisation primitive. A buggy error path in the XENMEM_acquire_resource exits without releasing an RCU reference, which is conceptually similar to forgetting to…
ModificadaMedia (5.5)0.51%—XENFedoraproject FedoraDebian LinuxOpensuse Leap23/9/202017/6/2026
An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault, and incorrectly delivers it twice to the guest. This causes the…
ModificadaAlta (7.8)0.37%—XENFedoraproject FedoraDebian LinuxOpensuse Leap23/9/202017/6/2026
An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been identified that act on unsanitized values read back from device hardware registers. While devices strictly compliant with PCI specifications shouldn't be able to affect…
ModificadaAlta (8.8)1.6%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/9/202017/6/2026
Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.3)1.4%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/9/202017/6/2026
Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
ModificadaAlta (7.8)0.36%—Google ChromeOpensuse Backports SLEOpensuse LeapDebian Linux+121/9/202017/6/2026
Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privilege escalation via a crafted binary.
ModificadaCrítica (9.6)1.8%—Google ChromeOpensuse Backports SLEDebian LinuxFedoraproject Fedora+121/9/202017/6/2026
Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.