Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
426 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 11% | — | Fasterxml Jackson-databindDebian LinuxOracle Business Process Management SuiteOracle Primavera P6 Enterprise Project Portfolio Management+8 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization. | |
| Modificada | Crítica (10) | 10% | — | Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Communications Billing AND Revenue Management+8 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 7.5% | — | Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Communications Billing AND Revenue Management+8 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 9.7% | — | Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Business Process Management Suite+16 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 13% | — | Fasterxml Jackson-databindDebian LinuxOracle Banking PlatformOracle Business Process Management Suite+21 | 2/1/2019 | 17/6/2026 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization. | |
| Modificada | Crítica (9.8) | 20% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxOracle Communications Billing AND Revenue ManagementOracle Communications Instant Messaging Server+1 | 26/2/2018 | 17/6/2026 | FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper,… | |
| Modificada | Media (4.3) | 0.66% | — | Jenkins Credentials Binding | 9/2/2018 | 17/6/2026 | Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values different from but similar to configured passwords being provided to… | |
| Modificada | Crítica (9.8) | 38% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+17 | 6/2/2018 | 17/6/2026 | A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. | |
| Modificada | Crítica (9.8) | 8.4% | — | Fasterxml Jackson-databindDebian LinuxRedhat Openshift Container PlatformRedhat Satellite+20 | 6/2/2018 | 17/6/2026 | A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525 by blacklisting… | |
| Modificada | Alta (8.1) | 7.2% | — | Fasterxml Jackson-databindDebian LinuxRedhat Openshift Container PlatformRedhat Virtualization+5 | 22/1/2018 | 17/6/2026 | FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist. | |
| Modificada | Crítica (9.8) | 50% | 💥 PoC | Fasterxml Jackson-databindDebian LinuxRedhat Jboss Enterprise Application PlatformRedhat Openshift Container Platform+4 | 10/1/2018 | 17/6/2026 | FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that… | |
| Modificada | Crítica (9.8) | 3.7% | — | Debian Xbindkeys-config | 28/8/2017 | 17/6/2026 | Insecure use of temporary files in xbindkeys-config 0.1.3-2 allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 81% | 💥 Exploit | Rpcbind Project RpcbindLibtirpc Project LibtirpcNtirpc Project Ntirpc | 4/5/2017 | 17/6/2026 | rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider the maximum RPC data size during memory allocation for XDR strings, which allows remote attackers to cause a denial of service (memory consumption with no subsequent free) via a crafted UDP packet to… | |
| Modificada | Alta (7.5) | 18% | — | ISC Bind | 12/1/2017 | 17/6/2026 | named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DS resource record in an answer. | |
| Modificada | Alta (7.5) | 25% | — | ISC Bind | 12/1/2017 | 17/6/2026 | named in ISC BIND 9.9.9-P4, 9.9.9-S6, 9.10.4-P4, and 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a response containing an inconsistency among the DNSSEC-related RRsets. | |
| Modificada | Alta (7.5) | 41% | — | ISC BindDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+8 | 12/1/2017 | 17/6/2026 | named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query. | |
| Modificada | Alta (7.5) | 39% | — | ISC BindNetapp Data Ontap EdgeNetapp SolidfireNetapp Steelstore Cloud Integrated Storage+7 | 2/11/2016 | 17/6/2026 | named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c. | |
| Modificada | Alta (7.5) | 26% | — | ISC Bind | 21/10/2016 | 17/6/2026 | ISC BIND 9.1.0 through 9.8.4-P2 and 9.9.0 through 9.9.2-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via malformed options data in an OPT resource record. | |
| Modificada | Alta (7.5) | 89% | 💥 Exploit | Oracle LinuxOracle VM ServerISC BindHp-ux+1 | 28/9/2016 | 17/6/2026 | buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query. | |
| Modificada | Media (5.9) | 63% | — | Hp-uxISC BindFedoraproject FedoraRedhat Enterprise Linux Desktop+5 | 19/7/2016 | 17/6/2026 | ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol. | |
| Modificada | Media (6.5) | 41% | — | ISC BindRedhat Enterprise Linux | 6/7/2016 | 17/6/2026 | ISC BIND through 9.9.9-P1, 9.10.x through 9.10.4-P1, and 9.11.x through 9.11.0b1 allows primary DNS servers to cause a denial of service (secondary DNS server crash) via a large AXFR response, and possibly allows IXFR servers to cause a denial of service (IXFR client crash) via a large IXFR response and allows remote… | |
| Modificada | Media (6.8) | 23% | — | ISC Bind | 9/3/2016 | 17/6/2026 | resolver.c in named in ISC BIND 9.10.x before 9.10.3-P4, when DNS cookies are enabled, allows remote attackers to cause a denial of service (INSIST assertion failure and daemon exit) via a malformed packet with more than one cookie option. | |
| Modificada | Alta (8.6) | 62% | — | ISC BindSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+10 | 9/3/2016 | 17/6/2026 | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c. | |
| Modificada | Media (6.8) | 59% | — | ISC BindSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+10 | 9/3/2016 | 17/6/2026 | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to… | |
| Modificada | Media (5.9) | 3.3% | — | ISC Bind | 4/2/2016 | 17/6/2026 | rdataset.c in ISC BIND 9 Supported Preview Edition 9.9.8-S before 9.9.8-S5, when nxdomain-redirect is enabled, allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via crafted flag values in a query. |