Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
4185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.4% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux | 9/7/2020 | 17/6/2026 | When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firefox ESR < 68.9. | |
| Modificada | Alta (7.5) | 0.98% | — | Mozilla ThunderbirdCanonical Ubuntu Linux | 9/7/2020 | 17/6/2026 | If Thunderbird is configured to use STARTTLS for an IMAP server, and the server sends a PREAUTH response, then Thunderbird will continue with an unencrypted connection, causing email data to be sent without protection. This vulnerability affects Thunderbird < 68.9.0. | |
| Modificada | Media (6.5) | 2.7% | — | SambaCanonical Ubuntu LinuxOpensuse LeapFedoraproject Fedora | 6/7/2020 | 17/6/2026 | A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba. | |
| Modificada | Alta (7.5) | 3.5% | — | SambaFedoraproject FedoraOpensuse LeapDebian Linux+1 | 6/7/2020 | 17/6/2026 | A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash. | |
| Modificada | Alta (8.6) | 3.4% | — | Rack Project RackDebian LinuxCanonical Ubuntu Linux | 2/7/2020 | 17/6/2026 | A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure. | |
| Modificada | Media (4.4) | 0.40% | — | Nvidia Virtual GPUCanonical Ubuntu Linux | 30/6/2020 | 17/6/2026 | NVIDIA Virtual GPU Manager and the guest drivers contain a vulnerability in vGPU plugin, in which there is the potential to execute privileged operations, which may lead to denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3). | |
| Modificada | Crítica (9.8) | 2.3% | — | Libvncserver Project LibvncserverCanonical Ubuntu LinuxOpensuse LeapFedoraproject Fedora+6 | 30/6/2020 | 17/6/2026 | It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow. | |
| Modificada | Media (5.5) | 0.45% | — | Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux | 29/6/2020 | 17/6/2026 | In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770. | |
| Modificada | Alta (7.5) | 1.9% | — | Coturn Project CoturnDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+1 | 29/6/2020 | 17/6/2026 | In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from… | |
| Modificada | Media (5.5) | 1.0% | — | SqliteCanonical Ubuntu LinuxApple IcloudApple Ipados+12 | 27/6/2020 | 17/6/2026 | In SQLite before 3.32.3, select.c mishandles query-flattener optimization, leading to a multiSelectOrderBy heap overflow because of misuse of transitive properties for constant propagation. | |
| Modificada | Alta (7.5) | 27% | 💥 PoC | Apache TomcatCanonical Ubuntu LinuxOracle Mysql Enterprise MonitorOracle Siebel UI Framework+4 | 26/6/2020 | 17/6/2026 | A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive. | |
| Modificada | Media (6.5) | 1.6% | — | Redhat Ceph StorageRedhat OpenstackFedoraproject FedoraOpensuse Leap+2 | 26/6/2020 | 17/6/2026 | A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made.… | |
| Modificada | Media (5.5) | 0.46% | — | OpenexrFedoraproject FedoraOpensuse LeapDebian Linux+1 | 26/6/2020 | 17/6/2026 | An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp. | |
| Modificada | Media (5.5) | 0.42% | — | OpenexrFedoraproject FedoraOpensuse LeapDebian Linux+1 | 26/6/2020 | 17/6/2026 | An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp. | |
| Modificada | Media (4.7) | 0.27% | — | Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce FirmwareNvidia NVS Firmware+1 | 25/6/2020 | 17/6/2026 | NVIDIA Linux GPU Display Driver, all versions, contains a vulnerability in the UVM driver, in which a race condition may lead to a denial of service. | |
| Modificada | Alta (8.1) | 2.5% | — | Python PillowFedoraproject FedoraCanonical Ubuntu Linux | 25/6/2020 | 17/6/2026 | In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311. | |
| Modificada | Media (5.5) | 1.4% | — | Python PillowFedoraproject FedoraCanonical Ubuntu Linux | 25/6/2020 | 17/6/2026 | In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file. | |
| Modificada | Alta (7.8) | 1.1% | — | Python PillowFedoraproject FedoraCanonical Ubuntu Linux | 25/6/2020 | 17/6/2026 | In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c. | |
| Modificada | Media (5.5) | 1.1% | — | Python PillowFedoraproject FedoraCanonical Ubuntu Linux | 25/6/2020 | 17/6/2026 | In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer. | |
| Modificada | Media (5.5) | 1.5% | — | Python PillowDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 25/6/2020 | 17/6/2026 | Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c. | |
| Modificada | Alta (7.8) | 0.47% | — | Nvidia Quadro FirmwareNvidia Tesla FirmwareNvidia Geforce FirmwareNvidia NVS Firmware+1 | 25/6/2020 | 17/6/2026 | NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the Inter Process Communication APIs, in which improper access control may lead to code execution, denial of service, or information disclosure. | |
| Modificada | Media (5.7) | 1.0% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079. | |
| Modificada | Alta (8) | 1.5% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084. | |
| Modificada | Media (4.3) | 1.2% | — | Sane-project Sane BackendsOpensuse LeapCanonical Ubuntu Linux | 24/6/2020 | 17/6/2026 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081. | |
| Modificada | Media (4.3) | 1.0% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083. |