Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1059 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 3.1% | — | Oracle MysqlCanonical Ubuntu LinuxNetapp Oncommand Unified ManagerNetapp Oncommand Workflow Automation+7 | 16/1/2019 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.24 and prior and 8.0.13 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | |
| Modificada | Alta (7.8) | 3.0% | — | Systemd Project SystemdRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+7 | 11/1/2019 | 17/6/2026 | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when many entries are sent to the journal socket. A local attacker, or a remote one if systemd-journal-remote is used, may use this flaw to crash systemd-journald or execute… | |
| Modificada | Alta (7.8) | 0.71% | — | Systemd Project SystemdRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+7 | 11/1/2019 | 17/6/2026 | An allocation of memory without limits, that could result in the stack clashing with another memory region, was discovered in systemd-journald when a program with long command line arguments calls syslog. A local attacker may use this flaw to crash systemd-journald or escalate his privileges. Versions through v240 are… | |
| Modificada | Baja (3.3) | 1.1% | — | Systemd Project SystemdDebian LinuxCanonical Ubuntu LinuxNetapp Active IQ Performance Analytics Services+17 | 11/1/2019 | 17/6/2026 | An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable. | |
| Modificada | Media (6.7) | 0.45% | — | Polkit Project PolkitDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+5 | 11/1/2019 | 17/6/2026 | In PolicyKit (aka polkit) 0.115, the "start time" protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c. | |
| Modificada | Media (5.3) | 3.7% | — | Openbsd OpensshWinscpNetapp Cloud BackupNetapp Element Software+18 | 10/1/2019 | 17/6/2026 | In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. | |
| Modificada | Media (6.5) | 2.3% | — | Freedesktop PopplerDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+7 | 3/1/2019 | 17/6/2026 | In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing. | |
| Modificada | Media (6.5) | 2.7% | — | Freedesktop PopplerCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+6 | 1/1/2019 | 17/6/2026 | A reachable Object::dictLookup assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to the lack of a check for the dict data type, as demonstrated by use of the FileSpec class (in FileSpec.cc) in pdfdetach. | |
| Modificada | Alta (7.8) | 2.9% | — | Artifex GhostscriptDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 20/12/2018 | 17/6/2026 | In Artifex Ghostscript through 9.25, the setpattern operator did not properly validate certain types. A specially crafted PostScript document could exploit this to crash Ghostscript or, possibly, execute arbitrary code in the context of the Ghostscript process. This is a type confusion issue because of failure to… | |
| Modificada | Crítica (9.8) | 15% | — | Libvnc Project LibvncserverCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+5 | 19/12/2018 | 17/6/2026 | LibVNC before commit 502821828ed00b4a2c4bef90683d0fd88ce495de contains heap out-of-bound write vulnerability in server code of file transfer extension that can result remote code execution | |
| Modificada | Media (5.5) | 0.51% | — | Linux KernelRedhat Openshift Container PlatformRedhat Virtualization HostRedhat Enterprise Linux Desktop+6 | 12/12/2018 | 17/6/2026 | The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and… | |
| Modificada | Alta (8.8) | 3.3% | — | Google ChromeDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+6 | 11/12/2018 | 17/6/2026 | An integer overflow in path handling lead to a use after free in Skia in Google Chrome prior to 71.0.3578.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Crítica (9.8) | 12% | — | PerlCanonical Ubuntu LinuxDebian LinuxNetapp E-series Santricity OS Controller+14 | 7/12/2018 | 17/6/2026 | Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | |
| Modificada | Alta (7.8) | 0.76% | — | Google AndroidCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+5 | 6/12/2018 | 17/6/2026 | In sk_clone_lock of sock.c, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-113509306. References:… | |
| Modificada | Alta (7.8) | 1.2% | — | Artifex GhostscriptRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+3 | 3/12/2018 | 17/6/2026 | It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects ghostscript 9.07 as shipped with Red Hat… | |
| Modificada | Crítica (9.8) | 8.4% | — | FreerdpCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+5 | 29/11/2018 | 17/6/2026 | FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption and probably even a remote code execution. | |
| Modificada | Crítica (9.8) | 8.2% | — | FreerdpCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+6 | 29/11/2018 | 17/6/2026 | FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution. | |
| Modificada | Alta (7.5) | 10% | — | Nodejs Node.jsRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+4 | 28/11/2018 | 17/6/2026 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed completion of the headers, it is possible to cause the HTTP server to abort from… | |
| Modificada | Media (5.5) | 0.39% | — | Linux KernelRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+3 | 26/11/2018 | 17/6/2026 | The Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capable() function in the net/netlink/af_netlink.c file. A local attacker could exploit this when a net namespace with a netnsid is assigned to cause a kernel panic and a denial of service. | |
| Modificada | Alta (7.8) | 3.0% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+6 | 23/11/2018 | 17/6/2026 | psi/zfjbig2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a JBIG2Decode type confusion. | |
| Modificada | Alta (7.8) | 3.0% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+6 | 23/11/2018 | 17/6/2026 | psi/zicc.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because of a setcolorspace type confusion. | |
| Modificada | Alta (7.8) | 9.5% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Openshift Container Platform+6 | 23/11/2018 | 17/6/2026 | psi/zdevice2.c in Artifex Ghostscript before 9.26 allows remote attackers to bypass intended access restrictions because available stack space is not checked when the device remains the same. | |
| Modificada | Crítica (9.8) | 7.8% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+4 | 21/11/2018 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 9.26. LockSafetyParams is not checked correctly if another device is used. | |
| Modificada | Media (4.7) | 3.4% | 💥 Exploit | Canonical Ubuntu LinuxDebian LinuxNodejs Node.jsOpenssl+16 | 15/11/2018 | 17/6/2026 | Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. | |
| Modificada | Alta (8.8) | 2.9% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+5 | 14/11/2018 | 17/6/2026 | Incorrect texture handling in Angle in Google Chrome prior to 70.0.3538.67 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. |