Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.41%—Ecryptfs-utilsDebian Linux20/12/201916/6/2026
ecryptfs-utils: suid helper does not restrict mounting filesystems with nosuid,nodev which creates a possible privilege escalation
ModificadaAlta (7.8)1.2%💥 ExploitGNU Mailutils11/11/201917/6/2026
maidag in GNU Mailutils before 3.8 is installed setuid and allows local privilege escalation in the url mode.
ModificadaAlta (7.8)2.2%—Icoutils Project IcoutilsRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server AUS+74/11/201917/6/2026
Integer overflow in the extract_group_icon_cursor_resource function in b/wrestool/extract.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) or execute arbitrary code via a crafted executable file.
ModificadaAlta (7.8)2.1%—Icoutils Project IcoutilsRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server AUS+74/11/201917/6/2026
The extract_group_icon_cursor_resource in wrestool/extract.c in icoutils before 0.31.1 can access unallocated memory, which allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
ModificadaAlta (7.8)0.46%—Icoutils Project IcoutilsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+14/11/201917/6/2026
Integer overflow in the check_offset function in b/wrestool/fileread.c in icoutils before 0.31.1 allows local users to cause a denial of service (process crash) and execute arbitrary code via a crafted executable.
ModificadaCrítica (9.1)1.4%—Python-docutils Project Python-docutilsDebian Linux31/10/201916/6/2026
python-docutils allows insecure usage of temporary files
ModificadaMedia (6.5)2.4%—GNU BinutilsOpensuse LeapCanonical Ubuntu Linux10/10/201917/6/2026
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. It is an integer overflow leading to a SEGV in _bfd_dwarf2_find_nearest_line in dwarf2.c, as demonstrated by nm.
ModificadaMedia (6.5)2.8%—GNU BinutilsOpensuse LeapCanonical Ubuntu Linux10/10/201917/6/2026
find_abstract_instance in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32, allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted ELF file.
ModificadaCrítica (9.8)1.5%—Linux-nfs Nfs-utils19/9/201917/6/2026
The nfs-utils package in SUSE Linux Enterprise Server 12 before and including version 1.3.0-34.18.1 and in SUSE Linux Enterprise Server 15 before and including version 2.1.1-6.10.2 the directory /var/lib/nfs is owned by statd:nogroup. This directory contains files owned and managed by root. If statd is compromised, it…
ModificadaCrítica (9.8)2.3%—Eslint-utils Project Eslint-utils26/8/201917/6/2026
In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.
ModificadaCrítica (9.8)1.4%—Xm-online Xm^online 2 - Common Utils AND Endpoints26/8/201917/6/2026
XM^online 2 Common Utils and Endpoints 0.2.1 allows SQL injection, related to Constants.java, DropSchemaResolver.java, and SchemaChangeResolver.java.
ModificadaAlta (7.3)28%—Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+5620/8/201925/8/2026
In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean.
ModificadaMedia (5.5)1.5%—GNU BinutilsOpensuse LeapCanonical Ubuntu LinuxNetapp HCI Management Node+130/7/201917/6/2026
apply_relocations in readelf.c in GNU Binutils 2.32 contains an integer overflow that allows attackers to trigger a write access violation (in byte_put_little_endian function in elfcomm.c) via an ELF file, as demonstrated by readelf.
ModificadaMedia (5.5)2.3%—GNU BinutilsCanonical Ubuntu LinuxOpensuse Leap24/7/201917/6/2026
An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. simple_object_elf_match in simple-object-elf.c does not check for a zero shstrndx value, leading to an integer overflow and resultant heap-based buffer overflow.
ModificadaMedia (5.5)1.1%—GNU BinutilsGNU Binutils GoldNetapp HCI Management NodeNetapp Solidfire23/7/201917/6/2026
GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input Validation, Signed/Unsigned Comparison, Out-of-bounds Read. The impact is: Denial of service. The component is: gold/fileread.cc:497, elfcpp/elfcpp_file.h:644. The attack vector is: An ELF file with an invalid e_shoff header…
ModificadaMedia (5.5)1.8%—GNU BinutilsOpensuse LeapCanonical Ubuntu Linux26/6/201917/6/2026
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.32. There is a heap-based buffer over-read in _bfd_doprnt in bfd.c because elf_object_p in elfcode.h mishandles an e_shstrndx section of type SHT_GROUP by omitting a trailing '\0' character.
ModificadaAlta (7.8)1.7%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+1418/6/201917/6/2026
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will…
ModificadaAlta (8.8)1.9%—GNU Recutils1/5/201917/6/2026
An issue was discovered in GNU recutils 1.8. There is a heap-based buffer overflow in the function rec_fex_parse_str_simple at rec-fex.c in librec.a.
ModificadaAlta (8.8)1.9%—GNU Recutils1/5/201917/6/2026
An issue was discovered in GNU recutils 1.8. There is a stack-based buffer overflow in the function rec_type_check_enum at rec-types.c in librec.a.
ModificadaMedia (6.5)1.4%—GNU Recutils1/5/201917/6/2026
An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_field_name_equal_p at rec-field-name.c in librec.a, leading to a crash.
ModificadaMedia (6.5)1.4%—GNU Recutils1/5/201917/6/2026
An issue was discovered in GNU recutils 1.8. There is a NULL pointer dereference in the function rec_rset_get_props at rec-rset.c in librec.a, leading to a crash.
ModificadaMedia (5.5)0.30%—Opensuse Supportutils5/3/201917/6/2026
If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine.
ModificadaAlta (7.8)0.50%—Opensuse Supportutils5/3/201917/6/2026
If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands as root.
ModificadaMedia (4.7)0.40%—Opensuse Supportutils5/3/201917/6/2026
In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.
ModificadaMedia (5.5)0.46%—Opensuse Supportutils5/3/201917/6/2026
Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection
Orbitaley — Vulnerabilidades