Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

4419 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.39%—Canonical Apport12/6/202117/6/2026
It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.
ModificadaBaja (3.3)0.33%—Canonical Apport12/6/202117/6/2026
It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.32%—Canonical Ubuntu LinuxOracle Openjdk12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.30%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could expose private data to other local users.
ModificadaAlta (7.8)0.57%—Canonical Apport11/6/202117/6/2026
It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.
ModificadaAlta (7.8)0.43%—Canonical Apport11/6/202117/6/2026
It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.
ModificadaAlta (7.8)0.45%—Canonical Apport11/6/202117/6/2026
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
ModificadaAlta (8.8)0.64%—Linux KernelCanonical Ubuntu Linux4/6/202117/6/2026
The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc/<PID>/mem. This could be used to create a heap overflow leading to arbitrary code execution in the kernel. It was addressed via…
ModificadaAlta (7.8)27%💥 ExploitLinux KernelCanonical Ubuntu Linux4/6/202117/6/2026
The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue was fixed via commit 049c4e13714e ("bpf: Fix alu32 const subreg…
ModificadaAlta (7.8)0.55%—Linux KernelCanonical Ubuntu Linux4/6/202117/6/2026
The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue was fixed via commit 4b81ccebaeee ("bpf, ringbuf: Deny…
ModificadaAlta (7.5)4.9%—OpenvpnFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux26/4/202117/6/2026
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
AnalizadaAlta (7.8)49%⚠ Explotación activa💥 ExploitCanonical Ubuntu Linux17/4/202117/6/2026
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts,…
ModificadaAlta (7.8)1.5%💥 PoCCanonical Ubuntu Linux17/4/202117/6/2026
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory…
ModificadaMedia (4.3)1.3%—Canonical Unity-firefox-extensionCanonical Ubuntu Linux7/4/202116/6/2026
The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher and updating it with new callbacks until the libunity-webapps rate limit was hit. Fixed in…
ModificadaMedia (6.5)1.3%—Canonical Unity-firefox-extensionCanonical Ubuntu Linux7/4/202116/6/2026
The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the…
ModificadaAlta (7.8)0.61%—Linux KernelDebian LinuxCanonical Ubuntu Linux23/3/202117/6/2026
The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly…
ModificadaMedia (6)0.58%—Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux20/3/202117/6/2026
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory,…
ModificadaMedia (4.7)0.56%—Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux20/3/202117/6/2026
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types…