Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
371 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.3% | — | Matrixssl | 22/6/2017 | 17/6/2026 | An exploitable heap buffer overflow vulnerability exists in the X509 certificate parsing functionality of InsideSecure MatrixSSL 3.8.7b. A specially crafted x509 certificate can cause a buffer overflow on the heap resulting in remote code execution. To trigger this vulnerability, a specially crafted x509 certificate… | |
| Modificada | Media (6.5) | 1.3% | — | Matrixssl | 3/3/2017 | 17/6/2026 | TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message. | |
| Modificada | Media (5.9) | 14% | — | Matrixssl | 3/3/2017 | 17/6/2026 | MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a Bleichenbacher variant attack. | |
| Modificada | Media (5.9) | 1.3% | — | Matrixssl | 3/3/2017 | 17/6/2026 | MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key information by conducting a Lenstra side-channel attack. | |
| Modificada | Media (5.9) | 1.3% | — | Matrixssl | 13/1/2017 | 17/6/2026 | The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to predict the secret key via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-6887. | |
| Modificada | Media (5.9) | 1.2% | — | Matrixssl | 13/1/2017 | 17/6/2026 | The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to predict the secret key via a CRT attack. | |
| Modificada | Alta (7.5) | 1.7% | — | Matrixssl | 13/1/2017 | 17/6/2026 | The pstm_reverse function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid memory read and crash) via a (1) zero value or (2) the key's modulus for the secret key during RSA key exchange. | |
| Modificada | Alta (7.5) | 1.3% | — | Matrixssl | 13/1/2017 | 17/6/2026 | The pstm_exptmod function in MatrixSSL before 3.8.4 allows remote attackers to cause a denial of service (invalid free and crash) via a base zero value for the modular exponentiation. | |
| Modificada | Alta (7.5) | 1.9% | — | Matrixssl | 5/1/2017 | 17/6/2026 | The x509FreeExtensions function in MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (free of unallocated memory) via a crafted X.509 certificate. | |
| Modificada | Alta (7.5) | 1.9% | — | Matrixssl | 5/1/2017 | 17/6/2026 | MatrixSSL before 3.8.6 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ASN.1 Bit Field primitive in an X.509 certificate. | |
| Modificada | Crítica (9.8) | 6.4% | — | Matrixssl | 5/1/2017 | 17/6/2026 | Heap-based buffer overflow in MatrixSSL before 3.8.6 allows remote attackers to execute arbitrary code via a crafted Subject Alt Name in an X.509 certificate. | |
| Modificada | Alta (8.6) | 1.4% | — | American Auto-matrix Aspect-matrix Building Automation Front-end Solutions ApplicationAmerican Auto-matrix Aspect-nexus Building Automation Front-end Solutions Application | 5/10/2016 | 17/6/2026 | American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application store passwords in cleartext, which allows remote attackers to obtain sensitive information by reading a file. | |
| Modificada | Alta (7.5) | 1.5% | — | American Auto-matrix Aspect-matrix Building Automation Front-end Solutions ApplicationAmerican Auto-matrix Aspect-nexus Building Automation Front-end Solutions Application | 5/10/2016 | 17/6/2026 | American Auto-Matrix Aspect-Nexus Building Automation Front-End Solutions application before 3.0.0 and Aspect-Matrix Building Automation Front-End Solutions application allow remote attackers to read arbitrary files via unspecified vectors, as demonstrated by the configuration file. | |
| Modificada | Alta (8.1) | 1.4% | — | HP Matrix Operating EnvironmentHP Systems Insight Manager | 8/6/2016 | 17/6/2026 | HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2029. | |
| Modificada | Alta (8.1) | 2.2% | — | HP Systems Insight ManagerHP Matrix Operating Environment | 8/6/2016 | 17/6/2026 | HPE Matrix Operating Environment before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2028. | |
| Modificada | Alta (8.1) | 2.1% | — | HP Matrix Operating EnvironmentHP Systems Insight Manager | 8/6/2016 | 17/6/2026 | HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2020, CVE-2016-2021, and CVE-2016-2022. | |
| Modificada | Crítica (9.1) | 4.2% | — | HP Systems Insight ManagerHP Matrix Operating Environment | 8/6/2016 | 17/6/2026 | HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-4358. | |
| Modificada | Alta (8.1) | 2.0% | — | HP Systems Insight ManagerHP Matrix Operating Environment | 8/6/2016 | 17/6/2026 | HPE Matrix Operating Environment before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-4357. | |
| Modificada | Alta (7.5) | 3.7% | — | HP Matrix Operating EnvironmentHP Systems Insight Manager | 8/6/2016 | 17/6/2026 | HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2026. | |
| Modificada | Alta (7.5) | 3.7% | — | HP Systems Insight ManagerHP Matrix Operating Environment | 8/6/2016 | 17/6/2026 | HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-2027. | |
| Modificada | Alta (8.1) | 2.4% | — | HP Matrix Operating EnvironmentHP Systems Insight Manager | 8/6/2016 | 17/6/2026 | HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2020, CVE-2016-2021, and CVE-2016-2030. | |
| Modificada | Alta (8.1) | 3.1% | — | HP Matrix Operating EnvironmentHP Systems Insight Manager | 8/6/2016 | 17/6/2026 | HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2020, CVE-2016-2022, and CVE-2016-2030. | |
| Modificada | Alta (8.1) | 2.7% | — | HP Systems Insight ManagerHP Matrix Operating Environment | 8/6/2016 | 17/6/2026 | HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2019, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030. | |
| Modificada | Alta (8.1) | 3.1% | — | HP Systems Insight ManagerHP Matrix Operating Environment | 8/6/2016 | 17/6/2026 | HPE Systems Insight Manager (SIM) before 7.5.1 allows remote authenticated users to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-2017, CVE-2016-2020, CVE-2016-2021, CVE-2016-2022, and CVE-2016-2030. | |
| Modificada | Crítica (9.1) | 3.8% | — | HP Systems Insight ManagerHP Matrix Operating Environment | 8/6/2016 | 17/6/2026 | HPE Systems Insight Manager (SIM) before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors. |