Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.41% | — | Ecryptfs-utilsDebian Linux | 20/12/2019 | 16/6/2026 | ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation | |
| Modificada | Alta (7.8) | 1.2% | 💥 Exploit | GNU Mailutils | 11/11/2019 | 17/6/2026 | maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode. | |
| Modificada | Alta (7.8) | 2.2% | — | Icoutils Project IcoutilsRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server AUS+7 | 4/11/2019 | 17/6/2026 | Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file. | |
| Modificada | Alta (7.8) | 2.1% | — | Icoutils Project IcoutilsRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server AUS+7 | 4/11/2019 | 17/6/2026 | The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable. | |
| Modificada | Alta (7.8) | 0.46% | — | Icoutils Project IcoutilsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+1 | 4/11/2019 | 17/6/2026 | Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable. | |
| Modificada | Crítica (9.1) | 1.4% | — | Python-docutils Project Python-docutilsDebian Linux | 31/10/2019 | 16/6/2026 | python-docutils allows insecure usage of temporary files | |
| Modificada | Media (6.5) | 2.4% | — | GNU BinutilsOpensuse LeapCanonical Ubuntu Linux | 10/10/2019 | 17/6/2026 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm. | |
| Modificada | Media (6.5) | 2.8% | — | GNU BinutilsOpensuse LeapCanonical Ubuntu Linux | 10/10/2019 | 17/6/2026 | find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file. | |
| Modificada | Crítica (9.8) | 1.5% | — | Linux-nfs Nfs-utils | 19/9/2019 | 17/6/2026 | The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it… | |
| Modificada | Crítica (9.8) | 2.3% | — | Eslint-utils Project Eslint-utils | 26/8/2019 | 17/6/2026 | In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.4% | — | Xm-online Xm^online 2 - Common Utils AND Endpoints | 26/8/2019 | 17/6/2026 | XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java. | |
| Modificada | Alta (7.3) | 28% | — | Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+56 | 20/8/2019 | 25/8/2026 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | |
| Modificada | Media (5.5) | 1.5% | — | GNU BinutilsOpensuse LeapCanonical Ubuntu LinuxNetapp HCI Management Node+1 | 30/7/2019 | 17/6/2026 | apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf. | |
| Modificada | Media (5.5) | 2.3% | — | GNU BinutilsCanonical Ubuntu LinuxOpensuse Leap | 24/7/2019 | 17/6/2026 | An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow. | |
| Modificada | Media (5.5) | 1.1% | — | GNU BinutilsGNU Binutils GoldNetapp HCI Management NodeNetapp Solidfire | 23/7/2019 | 17/6/2026 | GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header… | |
| Modificada | Media (5.5) | 1.8% | — | GNU BinutilsOpensuse LeapCanonical Ubuntu Linux | 26/6/2019 | 17/6/2026 | An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. There is a heap-based buffer over-read in _bfd_doprnt in bfd.c because elf_object_p in elfcode.h mishandles an e_shstrndx section of type SHT_GROUP by omitting a trailing '\0' character. | |
| Modificada | Alta (7.8) | 1.7% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+14 | 18/6/2019 | 17/6/2026 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will… | |
| Modificada | Alta (8.8) | 1.9% | — | GNU Recutils | 1/5/2019 | 17/6/2026 | An issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_simple at rec-fex.c in librec.a. | |
| Modificada | Alta (8.8) | 1.9% | — | GNU Recutils | 1/5/2019 | 17/6/2026 | An issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum at rec-types.c in librec.a. | |
| Modificada | Media (6.5) | 1.4% | — | GNU Recutils | 1/5/2019 | 17/6/2026 | An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec.a, leading to a crash. | |
| Modificada | Media (6.5) | 1.4% | — | GNU Recutils | 1/5/2019 | 17/6/2026 | An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leading to a crash. | |
| Modificada | Media (5.5) | 0.30% | — | Opensuse Supportutils | 5/3/2019 | 17/6/2026 | If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine. | |
| Modificada | Alta (7.8) | 0.50% | — | Opensuse Supportutils | 5/3/2019 | 17/6/2026 | If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands as root. | |
| Modificada | Media (4.7) | 0.40% | — | Opensuse Supportutils | 5/3/2019 | 17/6/2026 | In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files. | |
| Modificada | Media (5.5) | 0.46% | — | Opensuse Supportutils | 5/3/2019 | 17/6/2026 | Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection |