Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
368 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 9.7% | — | QemuJuniper Junos SpaceCanonical Ubuntu LinuxDebian Linux+14 | 15/6/2015 | 17/6/2026 | Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set. | |
| Modificada | Alta (7.8) | 20% | — | Apache TomcatOracle Virtualization | 7/6/2015 | 17/6/2026 | Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts. | |
| Modificada | Alta (7.8) | 2.8% | — | HP Network Virtualization | 25/5/2015 | 17/6/2026 | HP Network Virtualization for LoadRunner and Performance Center 8.61 and 11.52 allows remote attackers to read arbitrary files via a crafted filename in a URL to the (1) HttpServlet or (2) NetworkEditorController component, aka ZDI-CAN-2569. | |
| Modificada | Alta (7.7) | 15% | 💥 Exploit | QemuRedhat Enterprise VirtualizationRedhat OpenstackRedhat Enterprise Linux+1 | 13/5/2015 | 17/6/2026 | The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the (1) FD_CMD_READ_ID, (2) FD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands, aka VENOM. | |
| Modificada | Baja (2.1) | 0.38% | — | Redhat Enterprise Virtualization Manager | 1/5/2015 | 17/6/2026 | Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 uses weak permissions on the directories shared by the ovirt-engine-dwhd service and a plugin during service startup, which allows local users to obtain sensitive information by reading files in the directory. | |
| Modificada | Media (6.8) | 1.6% | — | Redhat Enterprise Virtualization Manager | 1/5/2015 | 17/6/2026 | Red Hat Enterprise Virtualization (RHEV) Manager before 3.5.1 ignores the permission to deny snapshot creation during live storage migration between domains, which allows remote authenticated users to cause a denial of service (prevent host start) by creating a long snapshot chain. | |
| Modificada | Alta (10) | 95% | 💥 Exploit | GNU GlibcOracle Communications Application Session ControllerOracle Communications Eagle Application ProcessorOracle Communications Eagle LNP Application Processor+14 | 28/1/2015 | 17/6/2026 | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST." | |
| Modificada | Media (5) | 2.1% | — | Redhat Jboss Data VirtualizationOdata4j Project Odata4j | 15/1/2015 | 17/6/2026 | XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, allows remote attackers to read arbitrary files via a crafted request to a REST endpoint. | |
| Modificada | Alta (7.5) | 4.1% | — | QemuRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+3 | 12/12/2014 | 17/6/2026 | The host_from_stream_offset function in arch_init.c in QEMU, when loading RAM during migration, allows remote attackers to execute arbitrary code via a crafted (1) offset or (2) length value in savevm data. | |
| Modificada | Baja (2.1) | 0.38% | — | Redhat Enterprise Virtualization | 5/12/2014 | 17/6/2026 | The rhevm-log-collector package in Red Hat Enterprise Virtualization 3.4 uses the PostgreSQL database password on the command line when calling sosreport, which allows local users to obtain sensitive information by listing the processes. | |
| Modificada | Media (5) | 3.7% | — | QemuDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+7 | 14/11/2014 | 17/6/2026 | The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value. | |
| Modificada | Baja (2.1) | 0.45% | — | QemuDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+8 | 1/11/2014 | 17/6/2026 | The VGA emulator in QEMU allows local guest users to read host memory by setting the display to a high resolution. | |
| Modificada | Media (6.5) | 1.8% | — | Redhat Enterprise Virtualization Manager | 18/10/2014 | 17/6/2026 | The oVirt Engine backend module, as used in Red Hat Enterprise Virtualization Manager before 3.4.2, uses an "insecure DocumentBuilderFactory," which allows remote attackers to read arbitrary files or possibly have other unspecified impact via a crafted XML/RSDL document, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (5) | 1.6% | — | Oracle Virtualization | 15/10/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.0 and 5.1 allows remote attackers to affect availability via vectors related to SGD Proxy Server (ttaauxserv), a different vulnerability than CVE-2014-2472, CVE-2014-2474, and CVE-2014-2476. | |
| Modificada | Media (5) | 1.3% | — | Oracle Virtualization | 15/10/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.0 and 5.1 allows remote attackers to affect availability via vectors related to SGD Proxy Server (ttaauxserv), a different vulnerability than CVE-2014-2472, CVE-2014-2474, and CVE-2014-6459. | |
| Modificada | Media (5) | 1.8% | — | Oracle Virtualization | 15/10/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 4.63, 4.71, 5.0, and 5.1 allows remote attackers to affect availability via vectors related to SGD Proxy Server (ttaauxserv). | |
| Modificada | Media (5) | 1.3% | — | Oracle Virtualization | 15/10/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.0 and 5.1 allows remote attackers to affect availability via vectors related to SGD Proxy Server (ttaauxserv), a different vulnerability than CVE-2014-2472, CVE-2014-2476, and CVE-2014-6459. | |
| Modificada | Media (5) | 1.3% | — | Oracle Virtualization | 15/10/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.0 and 5.1 allows remote attackers to affect availability via vectors related to SGD Proxy Server (ttaauxserv) and SGD SSL Daemon (ttassl). | |
| Modificada | Media (5) | 1.3% | — | Oracle Virtualization | 15/10/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5.0 and 5.1 allows remote attackers to affect availability via vectors related to SGD Proxy Server (ttaauxserv), a different vulnerability than CVE-2014-2474, CVE-2014-2476, and CVE-2014-6459. | |
| Modificada | Media (4.3) | 2.0% | — | Redhat Jboss Data VirtualizationJboss Teiid | 30/9/2014 | 17/6/2026 | Teiid before 8.4.3 and before 8.7 and Red Hat JBoss Data Virtualization 6.0.0 before patch 3 allows remote attackers to read arbitrary files via a crafted request to a REST endpoint, related to an XML External Entity (XXE) issue. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | GNU BashArista EOSOracle LinuxQnap QTS+70 | 25/9/2014 | 17/6/2026 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | GNU BashArista EOSOracle LinuxQnap QTS+70 | 24/9/2014 | 17/6/2026 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the… | |
| Modificada | Baja (3.5) | 1.4% | — | Redhat Enterprise Virtualization | 6/8/2014 | 17/6/2026 | The oVirt storage backend in Red Hat Enterprise Virtualization 3.4 does not wipe memory snapshots when deleting a VM, even when wipe-after-delete (WAD) is configured for the VM's disk, which allows remote authenticated users with certain credentials to read portions of the deleted VM's memory and obtain sensitive… | |
| Modificada | Baja (1.2) | 0.53% | — | Redhat Enterprise VirtualizationOpensuseRedhat Enterprise LinuxRedhat Libvirt | 3/8/2014 | 17/6/2026 | libvirt 1.0.0 through 1.2.x before 1.2.5, when fine grained access control is enabled, allows local users to read arbitrary files via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virDomainDefineXML, (2) virNetworkCreateXML, (3)… | |
| Modificada | Baja (1.9) | 0.56% | — | Redhat LibvirtRedhat Enterprise VirtualizationOpensuseRedhat Enterprise Linux | 3/8/2014 | 17/6/2026 | libvirt 0.7.5 through 1.2.x before 1.2.5 allows local users to cause a denial of service (read block and hang) via a crafted XML document containing an XML external entity declaration in conjunction with an entity reference to the (1) virConnectCompareCPU or (2) virConnectBaselineCPU API method, related to an XML… |