Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
787 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.6% | — | Redhat Enterprise Linux AUSRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+4 | 11/6/2018 | 17/6/2026 | A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the library during checks and results in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and… | |
| Modificada | Crítica (9.8) | 2.9% | — | Redhat Enterprise Linux AUSRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+2 | 11/6/2018 | 17/6/2026 | HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1. | |
| Modificada | Media (5.5) | 61% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… | |
| Modificada | Alta (7.5) | 2.4% | — | Xiph.org LibvorbisDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 26/4/2018 | 17/6/2026 | bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read. | |
| Modificada | Alta (8.8) | 3.3% | — | Xiph.org LibvorbisDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUS+2 | 26/4/2018 | 17/6/2026 | mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-read) or possibly have unspecified other impact via a crafted file. | |
| Modificada | Media (6.5) | 3.1% | — | Oracle MysqlMariadbCanonical Ubuntu LinuxDebian Linux+11 | 19/4/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Media (6.5) | 3.1% | — | Oracle MysqlCanonical Ubuntu LinuxDebian LinuxRedhat Openstack+11 | 19/4/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Media (4.9) | 3.3% | — | Debian LinuxNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation+11 | 19/4/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise… | |
| Modificada | Media (4.4) | 3.6% | — | Oracle MysqlDebian LinuxCanonical Ubuntu LinuxMariadb+11 | 19/4/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Locking). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise… | |
| Modificada | Media (5.9) | 4.0% | — | Oracle MysqlDebian LinuxCanonical Ubuntu LinuxMariadb+11 | 19/4/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Alta (7.7) | 0.84% | — | Oracle MysqlDebian LinuxCanonical Ubuntu LinuxMariadb+11 | 19/4/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server… | |
| Modificada | Crítica (9.8) | 16% | — | Apache Http ServerCanonical Ubuntu LinuxDebian LinuxNetapp Cloud Backup+9 | 26/3/2018 | 17/6/2026 | In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an… | |
| Modificada | Crítica (9.8) | 15% | — | QOS Slf4jRedhat Jboss Enterprise Application PlatformRedhat VirtualizationRedhat Virtualization Host+9 | 20/3/2018 | 17/6/2026 | org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x series. | |
| Modificada | Media (6.5) | 4.0% | — | Oracle MysqlMariadbDebian LinuxCanonical Ubuntu Linux+11 | 18/1/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Media (6.5) | 4.0% | — | Oracle MysqlMariadbDebian LinuxCanonical Ubuntu Linux+11 | 18/1/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Media (6.5) | 4.0% | — | Oracle MysqlMariadbDebian LinuxCanonical Ubuntu Linux+11 | 18/1/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Alta (8.3) | 2.9% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+3 | 18/1/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human… | |
| Modificada | Alta (8.3) | 3.3% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+20 | 18/1/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human… | |
| Modificada | Media (6.5) | 4.0% | — | Oracle MysqlMariadbDebian LinuxCanonical Ubuntu Linux+11 | 18/1/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL… | |
| Modificada | Alta (7.1) | 3.4% | — | Oracle MysqlMariadbDebian LinuxCanonical Ubuntu Linux+11 | 18/1/2018 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Partition). Supported versions that are affected are 5.5.58 and prior, 5.6.38 and prior and 5.7.19 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise… | |
| Modificada | Media (4.7) | 0.36% | — | Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxRedhat Enterprise Linux+16 | 9/1/2018 | 17/6/2026 | A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption.… | |
| Modificada | Crítica (9.8) | 53% | — | Linux KernelDebian LinuxArista EOSF5 ARX+25 | 3/1/2018 | 17/6/2026 | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action. | |
| Modificada | Media (6.5) | 3.7% | 💥 PoC | Torproject TORRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+4 | 4/11/2017 | 17/6/2026 | Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected. | |
| Modificada | Media (5.3) | 3.4% | — | Openbsd OpensshOracle SUN ZFS Storage Appliance KITDebian LinuxNetapp Active IQ Unified Manager+17 | 26/10/2017 | 17/6/2026 | The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files. | |
| Modificada | Alta (7.1) | 1.7% | — | Apache Portable RuntimeDebian LinuxRedhat Jboss Core ServicesRedhat Jboss Enterprise WEB Server+7 | 24/10/2017 | 17/6/2026 | When apr_time_exp*() or apr_os_exp_time*() functions are invoked with an invalid month field value in Apache Portable Runtime APR 1.6.2 and prior, out of bounds memory may be accessed in converting this value to an apr_time_exp_t value, potentially revealing the contents of a different static heap value or resulting… |