Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

326 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)2.2%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+517/4/201917/6/2026
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and…
ModificadaBaja (3.7)3.5%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+517/4/201917/6/2026
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access…
ModificadaMedia (5.9)3.9%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+417/4/201917/6/2026
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE…
ModificadaAlta (8.8)3.8%—GraphicsmagickOpensuse Backports SLEOpensuse LeapDebian Linux+18/4/201917/6/2026
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.
ModificadaAlta (8.1)2.0%—GraphicsmagickOpensuse Backports SLEOpensuse LeapDebian Linux+18/4/201917/6/2026
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
ModificadaMedia (4.3)0.77%—Roundcube WebmailFedoraproject FedoraOpensuse Backports SLEOpensuse Leap7/4/201917/6/2026
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the…
ModificadaAlta (7.8)0.76%💥 PoCPuttyOpensuse Backports SLEOpensuse Leap21/3/201917/6/2026
In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the same directory as the executable.
ModificadaAlta (7.5)2.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (earlier than CVE-2019-9776).
ModificadaAlta (7.5)2.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at dwg.spec.
ModificadaAlta (7.5)2.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write at header_variables_dxf.spec.
ModificadaAlta (7.5)2.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg.spec (later than CVE-2019-9779).
ModificadaCrítica (9.1)3.0%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_CONTROL at dwg.spec.
ModificadaCrítica (9.1)3.0%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at bits.c.
ModificadaAlta (7.5)2.9%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the z dimension.
ModificadaAlta (7.5)2.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dwg.spec.
ModificadaAlta (7.5)2.8%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bits.c.
ModificadaAlta (7.5)2.9%—GNU LibredwgOpensuse Backports SLEOpensuse Leap14/3/201917/6/2026
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_data at decode.c for the y dimension.
ModificadaMedia (5.4)1.1%—OtrsOpensuse Backports SLEOpensuse Leap13/3/201917/6/2026
An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attacker who is logged into OTRS as an agent or a customer user may upload a carefully crafted resource in order to cause execution of JavaScript in the context of OTRS. This is related to…
ModificadaCrítica (9.8)2.2%—Live555 Streaming MediaOpensuse Backports SLEOpensuse LeapDebian Linux28/2/201917/6/2026
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
ModificadaCrítica (9.8)3.5%—SqlalchemyDebian LinuxOpensuse Backports SLEOpensuse Leap+520/2/201917/6/2026
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
ModificadaAlta (8.6)98%💥 ExploitDockerLinuxfoundation RuncRedhat Container Development KITRedhat Openshift+1511/2/201917/6/2026
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image,…
ModificadaAlta (8.1)3.5%—Libsdl Simple Directmedia LayerOpensuse Backports SLEOpensuse LeapDebian Linux+28/2/201917/6/2026
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_blit_1.c.
ModificadaAlta (7.8)1.8%—SqlalchemyDebian LinuxOpensuse Backports SLEOpensuse Leap+56/2/201917/6/2026
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
ModificadaAlta (8.1)5.0%—Golang GOOpensuse Backports SLEOpensuse LeapSuse Linux Enterprise Server+114/12/201817/6/2026
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is…
ModificadaAlta (8.1)66%—Golang GOOpensuse Backports SLEOpensuse LeapSuse Linux Enterprise Server+114/12/201817/6/2026
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the…
Orbitaley — Vulnerabilidades