Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 2.0% | — | Cryptocat Project Cryptocat | 5/11/2019 | 16/6/2026 | Cryptocat has an Unspecified Chat Participant User List Disclosure | |
| Modificada | Media (6.1) | 1.1% | — | Cryptocat Project Cryptocat | 5/11/2019 | 16/6/2026 | Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting | |
| Modificada | Alta (7.5) | 1.1% | — | Cryptocat Project Cryptocat | 4/11/2019 | 16/6/2026 | Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure | |
| Modificada | Crítica (9.8) | 2.2% | — | Cryptocat Project Cryptocat | 4/11/2019 | 16/6/2026 | Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness | |
| Modificada | Crítica (9.8) | 3.7% | — | Cryptocat Project Cryptocat | 4/11/2019 | 16/6/2026 | Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview | |
| Modificada | Media (5.3) | 1.4% | — | Cryptocat Project Cryptocat | 4/11/2019 | 16/6/2026 | Cryptocat before 2.0.22 has Nickname User Impersonation | |
| Modificada | Alta (7.5) | 2.0% | — | Cryptocat Project Cryptocat | 4/11/2019 | 16/6/2026 | Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness | |
| Modificada | Alta (7.5) | 0.76% | — | Cryptocat Project Cryptocat | 4/11/2019 | 16/6/2026 | Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol | |
| Modificada | Alta (7.5) | 1.9% | — | Cryptocat Project Cryptocat | 4/11/2019 | 16/6/2026 | Cryptocat strophe.js before 2.0.22 has information disclosure | |
| Modificada | Alta (7.5) | 12% | 💥 Exploit | Cryptocat Project Cryptocat | 4/11/2019 | 16/6/2026 | Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure | |
| Modificada | Crítica (9.8) | 6.9% | 💥 Exploit | Cryptocat Project Cryptocat | 4/11/2019 | 16/6/2026 | Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input | |
| Modificada | Crítica (9.1) | 2.0% | — | Cryptocat Project Cryptocat | 4/11/2019 | 16/6/2026 | Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness | |
| Modificada | Media (5.3) | 1.4% | — | Cryptocat Project Cryptocat | 4/11/2019 | 16/6/2026 | Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness | |
| Modificada | Alta (7.5) | 2.4% | — | Cryptocat Project Cryptocat | 4/11/2019 | 16/6/2026 | Cryptocat before 2.0.22 has Remote Denial of Service via username | |
| Modificada | Media (4.6) | 0.39% | — | Shiftcrypto Bitbox02 | 2/11/2019 | 17/6/2026 | On SHIFT BitBox02 devices, a side channel for the row-based OLED display was found. The power consumption of each row-based display cycle depends on the number of illuminated pixels, allowing a partial recovery of display contents. For example, a hardware implant in the USB cable might be able to leverage this… | |
| Modificada | Alta (7.4) | 0.86% | — | JSS Cryptomanager Project JSS CryptomanagerRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+4 | 14/10/2019 | 17/6/2026 | A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the… | |
| Modificada | Media (4.9) | 0.60% | — | Dell Bsafe Crypto-c-micro-editionEMC RSA Bsafe Crypto-c | 30/9/2019 | 17/6/2026 | RSA BSAFE Crypto-C Micro Edition, all versions prior to 4.1.4, is vulnerable to three (3) different Improper Clearing of Heap Memory Before Release vulnerability, also known as 'Heap Inspection vulnerability'. A malicious remote user could potentially exploit this vulnerability to extract information leaving data at… | |
| Modificada | Alta (7.5) | 1.4% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suiteEMC RSA Bsafe Crypto-c | 30/9/2019 | 17/6/2026 | RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) versions prior to 4.1.6.1 (in 4.1.x) and versions prior to 4.3.3 (4.2.x and 4.3.x) are vulnerable to an Information Exposure Through Timing… | |
| Modificada | Alta (7.5) | 1.4% | — | Dell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suite | 30/9/2019 | 17/6/2026 | RSA BSAFE Crypto-C Micro Edition versions prior to 4.1.4 and RSA Micro Edition Suite versions prior to 4.4 are vulnerable to an Information Exposure Through Timing Discrepancy. A malicious remote user could potentially exploit this vulnerability to extract information leaving data at risk of exposure. | |
| Modificada | Alta (7.5) | 2.4% | — | Dell Bsafe Crypto-cDell Bsafe Crypto-c-micro-editionDell Bsafe Micro-edition-suite | 30/9/2019 | 17/6/2026 | RSA BSAFE Crypto-C Micro Edition versions from 4.0.0.0 before 4.0.5.4 and from 4.1.0 before 4.1.4, RSA BSAFE Micro Edition Suite versions from 4.0.0 before 4.0.13 and from 4.1.0 before 4.4 and RSA Crypto-C versions from 6.0.0 through 6.4.* are vulnerable to an out-of-bounds read vulnerability when processing DSA… | |
| Modificada | Media (5.3) | 1.8% | — | ARM Mbed CryptoARM Mbed TLSTrustedfirmware Mbed TLSFedoraproject Fedora+1 | 26/9/2019 | 17/6/2026 | Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in… | |
| Modificada | Media (6.5) | 3.8% | — | Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jOracle Application Performance Management+14 | 18/9/2019 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys. | |
| Modificada | Media (6.5) | 2.5% | — | Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jOracle Application Performance Management+12 | 18/9/2019 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys. | |
| Modificada | Media (6.5) | 1.7% | — | Dell Bsafe Cert-jDell Bsafe Crypto-jDell Bsafe Ssl-jMcafee Threat Intelligence Exchange Server+12 | 18/9/2019 | 17/6/2026 | RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key. | |
| Modificada | Media (5.9) | 2.7% | — | Cryptopp Crypto++ | 30/7/2019 | 17/6/2026 | Crypto++ 8.3.0 and earlier contains a timing side channel in ECDSA signature generation. This allows a local or remote attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue occurs because scalar multiplication in ecp.cpp (prime field curves,… |