Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
518 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.8% | — | FreebsdNetapp Clustered Data Ontap | 30/8/2019 | 17/6/2026 | In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350638, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bsnmp library is not properly validating the submitted length from a type-length-value encoding. A remote user could cause an… | |
| Modificada | Crítica (9.8) | 2.1% | — | FreebsdNetapp Clustered Data Ontap | 30/8/2019 | 17/6/2026 | In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350650, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the ICMPv6 input path incorrectly handles cases where an MLDv2 listener query packet is internally fragmented across multiple mbufs. A… | |
| Modificada | Alta (7.5) | 28% | — | Apple SwiftnioApache Http ServerApache Traffic ServerCanonical Ubuntu Linux+19 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The… | |
| Modificada | Crítica (9.1) | 0.91% | — | Netapp Data Ontap | 5/8/2019 | 17/6/2026 | SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or addition or modification of data. | |
| Modificada | Alta (7.5) | 2.0% | — | Netapp Data Ontap | 2/8/2019 | 17/6/2026 | Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 may disclose sensitive LDAP account information to unauthenticated remote attackers. | |
| Modificada | Alta (7.5) | 1.4% | — | Netapp Data Ontap | 2/8/2019 | 17/6/2026 | Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information to an unauthenticated attacker. A successful attack requires that multiple non-default options be enabled. | |
| Modificada | Alta (8.1) | 12% | 💥 PoC | Libssh2Debian LinuxFedoraproject FedoraNetapp Cloud Backup+3 | 16/7/2019 | 17/6/2026 | In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of… | |
| Modificada | Crítica (9.8) | 2.9% | — | Netapp AFF A700s FirmwareNetapp Clustered Data Ontap | 1/7/2019 | 17/6/2026 | NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow unauthorized arbitrary command execution. | |
| Modificada | Media (5.3) | 5.2% | — | Xmlsoft LibxsltOpensuse LeapNetapp Active IQ Unified ManagerNetapp Cloud Backup+21 | 1/7/2019 | 17/6/2026 | In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data. | |
| Modificada | Alta (7.5) | 5.7% | 💥 PoC | Netapp Clustered Data OntapNetapp Data OntapFedoraproject FedoraOpensuse Leap+2 | 15/5/2019 | 17/6/2026 | NTP through 4.2.8p12 has a NULL Pointer Dereference. | |
| Modificada | Alta (8.1) | 4.5% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+10 | 8/5/2019 | 17/6/2026 | An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup. | |
| Modificada | Alta (8.1) | 5.1% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxF5 Traffix Signaling Delivery Controller+9 | 7/5/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free. | |
| Modificada | Alta (7.7) | 4.3% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+10 | 25/4/2019 | 17/6/2026 | An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net… | |
| Modificada | Media (5.5) | 0.54% | — | Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+9 | 24/4/2019 | 17/6/2026 | A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial… | |
| Modificada | Alta (7) | 0.37% | — | Linux KernelDebian LinuxOpensuse LeapNetapp Active IQ+6 | 23/4/2019 | 17/6/2026 | The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions. | |
| Modificada | Media (5.3) | 5.9% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+22 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path.… | |
| Modificada | Media (5.3) | 4.1% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+21 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in… | |
| Modificada | Media (4.7) | 0.34% | — | Linux KernelDebian LinuxNetapp Active IQ Unified Manager FOR Vmware VsphereNetapp HCI Management Node+6 | 22/4/2019 | 17/6/2026 | A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specified target task to perform an execve() syscall with setuid execution before… | |
| Modificada | Alta (7.5) | 17% | 💥 PoC | Apache Http ServerDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+10 | 8/4/2019 | 17/6/2026 | In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions. | |
| Modificada | Crítica (9.1) | 5.1% | — | Libssh2Debian LinuxNetapp Ontap Select Deploy Administration UtilityOpensuse Leap | 25/3/2019 | 17/6/2026 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. | |
| Modificada | Crítica (9.1) | 5.1% | — | Libssh2Debian LinuxNetapp Ontap Select Deploy Administration UtilityOpensuse Leap | 25/3/2019 | 17/6/2026 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. | |
| Modificada | Alta (8.8) | 6.1% | — | Libssh2Debian LinuxNetapp Ontap Select Deploy Administration UtilityOpensuse Leap+9 | 25/3/2019 | 17/6/2026 | An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server. | |
| Modificada | Alta (8.8) | 6.1% | — | Libssh2Debian LinuxNetapp Ontap Select Deploy Administration UtilityOpensuse Leap+9 | 25/3/2019 | 17/6/2026 | An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server. | |
| Modificada | Alta (8.8) | 3.4% | — | Libssh2Debian LinuxNetapp Ontap Select Deploy Administration UtilityOpensuse Leap+6 | 25/3/2019 | 17/6/2026 | A flaw was found in libssh2 before 1.8.1 creating a vulnerability on the SSH client side. A server could send a multiple keyboard interactive response messages whose total length are greater than unsigned char max characters. This value is used by the SSH client as an index to copy memory causing in an out of bounds… | |
| Modificada | Crítica (9.1) | 6.4% | — | Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+1 | 21/3/2019 | 17/6/2026 | An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory. |