Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
398 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 9.8% | — | Haxx CurlNetapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp HCI Management Node+15 | 5/8/2021 | 17/6/2026 | libcurl-using applications can ask for a specific client certificate to be used in a transfer. This is done with the `CURLOPT_SSLCERT` option (`--cert` with the command line tool).When libcurl is built to use the macOS native TLS library Secure Transport, an application can ask for the client certificate by name or… | |
| Modificada | Media (5.3) | 4.9% | — | Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+16 | 5/8/2021 | 17/6/2026 | curl supports the `-t` command line option, known as `CURLOPT_TELNETOPTIONS`in libcurl. This rarely used option is used to send variable=content pairs toTELNET servers.Due to flaw in the option parser for sending `NEW_ENV` variables, libcurlcould be made to pass on uninitialized data from a stack based buffer to… | |
| Modificada | Baja (3.7) | 6.3% | 💥 PoC | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Cloud Backup+29 | 5/8/2021 | 17/6/2026 | libcurl keeps previously used connections in a connection pool for subsequenttransfers to reuse, if one of them matches the setup.Due to errors in the logic, the config matching function did not take 'issuercert' into account and it compared the involved paths *case insensitively*,which could lead to libcurl reusing… | |
| Modificada | Media (5.3) | 1.9% | — | Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+12 | 5/8/2021 | 17/6/2026 | When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's… | |
| Modificada | Media (6.5) | 4.3% | — | Haxx CurlFedoraproject FedoraNetapp Cloud BackupNetapp Clustered Data Ontap+12 | 5/8/2021 | 17/6/2026 | When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then… | |
| Modificada | Alta (8.8) | 18% | — | Google ChromeXmlsoft LibxsltDebian LinuxSplunk Universal Forwarder | 3/8/2021 | 17/6/2026 | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 2.8% | — | LibarchiveFedoraproject FedoraApple IpadosApple Iphone OS+3 | 20/7/2021 | 17/6/2026 | libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). | |
| Modificada | Alta (8.1) | 60% | — | Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+22 | 11/6/2021 | 17/6/2026 | curl 7.75.0 through 7.76.1 suffers from a use-after-free vulnerability resulting in already freed memory being used when a TLS 1.3 session ticket arrives over a connection. A malicious server can use this in rare unfortunate circumstances to potentially reach remote code execution in the client. When libcurl at… | |
| Modificada | Baja (3.1) | 4.5% | — | Haxx CurlDebian LinuxFedoraproject FedoraOracle Communications Cloud Native Core Binding Support Function+8 | 11/6/2021 | 17/6/2026 | curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data… | |
| Modificada | Media (5.3) | 3.0% | — | Haxx CurlOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle Communications Cloud Native Core Network Repository Function+18 | 11/6/2021 | 17/6/2026 | curl 7.61.0 through 7.76.1 suffers from exposure of data element to wrong session due to a mistake in the code for CURLOPT_SSL_CIPHER_LIST when libcurl is built to use the Schannel TLS library. The selected cipher set was stored in a single "static" variable in the library, which has the surprising side-effect that if… | |
| Modificada | Crítica (9.8) | 3.2% | — | LZ4 Project LZ4Netapp Active IQ Unified ManagerNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+3 | 2/6/2021 | 17/6/2026 | There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some… | |
| Modificada | Baja (3.7) | 3.1% | — | Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+7 | 1/4/2021 | 17/6/2026 | curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server… | |
| Modificada | Media (5.3) | 5.3% | — | Haxx LibcurlFedoraproject FedoraNetapp HCI Management NodeNetapp Solidfire+8 | 1/4/2021 | 17/6/2026 | curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials from the URL when automatically populating the Referer: HTTP request header field in outgoing HTTP… | |
| Modificada | Alta (7.5) | 4.6% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+13 | 14/12/2020 | 17/6/2026 | curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. | |
| Modificada | Alta (7.5) | 9.8% | — | Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. | |
| Modificada | Baja (3.7) | 3.9% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions. | |
| Modificada | Alta (7.5) | 3.8% | — | Haxx LibcurlSiemens Sinec Infrastructure Network ServicesDebian LinuxOracle Communications Cloud Native Core Policy+1 | 14/12/2020 | 17/6/2026 | Due to use of a dangling pointer, libcurl 7.29.0 through 7.71.1 can use the wrong connection when sending data. | |
| Modificada | Alta (7.8) | 1.3% | — | Haxx CurlDebian LinuxFujitsu M10-1 FirmwareFujitsu M10-4 Firmware+6 | 14/12/2020 | 17/6/2026 | curl 7.20.0 through 7.70.0 is vulnerable to improper restriction of names for files and other resources that can lead too overwriting a local file when the -J flag is used. | |
| Modificada | Alta (7.5) | 3.5% | — | Haxx CurlSiemens Simatic TIM 1531 IRC FirmwareDebian LinuxSiemens Sinec Infrastructure Network Services+1 | 14/12/2020 | 17/6/2026 | curl 7.62.0 through 7.70.0 is vulnerable to an information disclosure vulnerability that can lead to a partial password being leaked over the network and to the DNS server(s). | |
| Modificada | Media (5.3) | 4.2% | — | PcreApple MacosGitlabOracle Communications Cloud Native Core Policy+11 | 15/6/2020 | 17/6/2026 | libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring. | |
| Modificada | Alta (7.5) | 2.8% | — | PcreApple MacosSplunk Universal Forwarder | 15/6/2020 | 17/6/2026 | libpcre in PCRE before 8.43 allows a subject buffer over-read in JIT when UTF is disabled, and \X or \R has more than one fixed quantifier, a related issue to CVE-2019-20454. | |
| Modificada | Alta (7.5) | 1.6% | — | Pcre2Fedoraproject FedoraSplunk Universal Forwarder | 14/2/2020 | 17/6/2026 | An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in… | |
| Modificada | Alta (7.8) | 0.27% | — | Splunk | 23/1/2020 | 17/6/2026 | Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges | |
| Modificada | Media (4.3) | 0.68% | — | Splunk | 23/1/2020 | 17/6/2026 | Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking | |
| Modificada | Alta (8.8) | 1.7% | — | Jenkins Splunk | 28/8/2019 | 17/6/2026 | A sandbox bypass vulnerability in Jenkins Splunk Plugin 1.7.4 and earlier allowed attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM. |