Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
368 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.4) | 19% | — | HP Network Virtualization | 26/7/2014 | 17/6/2026 | Directory traversal vulnerability in the toServerObject function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to create files, and consequently execute arbitrary code, via crafted input, aka ZDI-CAN-2024. | |
| Modificada | Alta (8.5) | 9.9% | — | HP Network Virtualization | 26/7/2014 | 17/6/2026 | Directory traversal vulnerability in the storedNtxFile function in HP Network Virtualization 8.6 (aka Shunra Network Virtualization) allows remote attackers to read arbitrary files via crafted input, aka ZDI-CAN-2023. | |
| Modificada | Media (4.3) | 2.1% | — | Oracle VirtualizationOracle Virtualization Secure Global Desktop | 17/7/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization 4.63, 4.71, 5.0, and 5.1 allows remote attackers to affect integrity via unknown vectors related to Workspace Web Application, a different vulnerability than CVE-2014-2463. | |
| Modificada | Media (4) | 1.5% | — | Redhat Enterprise Virtualization | 11/7/2014 | 17/6/2026 | The REST API in the ovirt-engine in oVirt, as used in Red Hat Enterprise Virtualization (rhevm) 3.4, allows remote authenticated users to read arbitrary files and have other unspecified impact via unknown vectors, related to an XML External Entity (XXE) issue. | |
| Modificada | Alta (10) | 78% | 💥 Exploit | HP Service Virtualization | 18/6/2014 | 17/6/2026 | Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled, allows remote attackers to create arbitrary files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-2031. | |
| Modificada | Media (6) | 0.27% | — | IBM System Storage Virtualization Engine Ts7700 FirmwareIBM System Storage Virtualization Engine Ts7700 | 8/6/2014 | 17/6/2026 | Unspecified vulnerability on the IBM System Storage Virtualization Engine TS7700 allows local users to gain privileges by leveraging the TSSC service-user role to enter a crafted SSH command. | |
| Modificada | Media (5) | 3.8% | — | GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+10 | 5/6/2014 | 17/6/2026 | The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument. | |
| Modificada | Alta (7.5) | 3.8% | — | GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+11 | 5/6/2014 | 17/6/2026 | The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data. | |
| Modificada | Media (5) | 6.8% | — | GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+11 | 5/6/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data. | |
| Modificada | Media (4.3) | 1.5% | — | Oracle Virtualization | 16/4/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization 4.63, 4.71, 5.0, and 5.1 allows remote attackers to affect integrity via unknown vectors related to Workspace Web Application, a different vulnerability than CVE-2014-4232. | |
| Modificada | Media (6.4) | 1.8% | — | Oracle Virtualization | 16/4/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization 5.0 and 5.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Workspace Web Application. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | OpensslFilezilla-project Filezilla ServerSiemens Application Processing Engine FirmwareSiemens CP 1543-1 Firmware+24 | 7/4/2014 | 17/6/2026 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to… | |
| Modificada | Media (6.8) | 3.2% | — | GNU GlibcRedhat Enterprise VirtualizationCanonical Ubuntu LinuxRedhat Enterprise Linux | 10/2/2014 | 16/6/2026 | The vfprintf function in stdio-common/vfprintf.c in GNU C Library (aka glibc) 2.5, 2.12, and probably other versions does not "properly restrict the use of" the alloca function when allocating the SPECS array, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and… | |
| Modificada | Media (5) | 2.1% | — | GNU GlibcRedhat Enterprise VirtualizationCanonical Ubuntu LinuxRedhat Enterprise Linux | 10/2/2014 | 16/6/2026 | The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.14 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (segmentation fault and… | |
| Modificada | Media (5) | 2.2% | — | GNU GlibcRedhat Enterprise VirtualizationCanonical Ubuntu LinuxRedhat Enterprise Linux | 10/2/2014 | 16/6/2026 | The vfprintf function in stdio-common/vfprintf.c in libc in GNU C Library (aka glibc) 2.12 and other versions does not properly calculate a buffer length, which allows context-dependent attackers to bypass the FORTIFY_SOURCE format-string protection mechanism and cause a denial of service (stack corruption and crash)… | |
| Modificada | Media (4.3) | 0.97% | — | Redhat Enterprise Virtualization Manager | 24/1/2014 | 17/6/2026 | The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server. | |
| Modificada | Alta (7.2) | 0.41% | — | Redhat Enterprise Virtualization | 21/1/2014 | 16/6/2026 | Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain privileges via a crafted application in an unspecified folder. | |
| Modificada | Alta (7.2) | 0.41% | — | Redhat Enterprise Virtualization | 21/1/2014 | 16/6/2026 | Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted application in an unspecified folder. | |
| Modificada | Media (5.1) | 1.5% | — | Oracle Virtualization Secure Global Desktop | 15/1/2014 | 17/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization SGD before 4.63 with December 2013 PSU, 4.71, 5.0 with December 2013 PSU, and 5.10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Administration Console… | |
| Modificada | Alta (7.5) | 16% | — | Redhat Cloudforms Management EngineRedhat Manageiq Enterprise Virtualization Manager | 11/1/2014 | 16/6/2026 | SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action. | |
| Modificada | Alta (7.4) | 0.54% | — | Redhat Enterprise Virtualization Hypervisor | 27/12/2013 | 16/6/2026 | libspice, as used in QEMU-KVM in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 and possibly other products, allows guest OS users to read from or write to arbitrary QEMU memory by modifying the address that is used by Cairo for memory mappings. | |
| Modificada | Media (5) | 2.7% | — | Spice Project SpiceRedhat Enterprise VirtualizationRedhat Enterprise Linux | 2/11/2013 | 16/6/2026 | Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket. | |
| Modificada | Media (5) | 1.3% | — | Oracle Virtualization | 16/10/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle Secure Global Desktop component in Oracle Virtualization 5 allows remote attackers to affect availability via unknown vectors related to ttaauxserv. | |
| Modificada | Alta (7.2) | 0.43% | — | QemuOpensuseRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 4/10/2013 | 16/6/2026 | Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command. | |
| Modificada | Media (4.3) | 1.4% | — | Redhat Enterprise Virtualization | 16/9/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the addAlert function in the RedirectServlet servlet in oVirt Engine and Red Hat Enterprise Virtualization Manager (RHEV-M), as used in Red Hat Enterprise Virtualization 3 and 3.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |