Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

4185 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)1.1%—Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap24/6/202017/6/2026
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.
ModificadaAlta (8.8)3.0%—Sane-project Sane BackendsCanonical Ubuntu LinuxOpensuse Leap24/6/202017/6/2026
A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.
ModificadaMedia (4.3)1.9%—GNU MailmanCanonical Ubuntu LinuxDebian Linux24/6/202017/6/2026
GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page.
ModificadaMedia (6.5)1.8%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.
ModificadaMedia (4.3)1.8%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2.
ModificadaAlta (7.5)1.8%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2.
ModificadaMedia (6.5)1.8%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
ModificadaMedia (6.5)2.1%—FreerdpOpensuse LeapFedoraproject FedoraCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2.1.2.
ModificadaMedia (6.5)1.7%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enabled This is fixed in version 2.1.2.
ModificadaMedia (5.4)1.4%💥 PoCFreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.
ModificadaMedia (6.5)1.8%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one can disable bitmap cache with -bitmap-cache (default). This is fixed in version 2.1.2.
ModificadaMedia (5.4)1.5%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.
ModificadaMedia (5.9)2.3%—MuttDebian LinuxNeomuttFedoraproject Fedora+221/6/202017/6/2026
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."
ModificadaAlta (7.5)2.9%—Rack Project RackDebian LinuxCanonical Ubuntu Linux19/6/202017/6/2026
A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.
ModificadaMedia (6.3)0.26%—Cisco Advanced Malware Protection FOR EndpointsCisco Clam AntivirusFedoraproject FedoraDebian Linux+118/6/202017/6/2026
A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability is due to a race condition that could occur when scanning malicious files. An attacker with local…
ModificadaMedia (4.9)2.1%—ISC BindFedoraproject FedoraOpensuse LeapDebian Linux+217/6/20201/9/2026
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*")…
ModificadaMedia (4.9)1.8%—ISC BindOpensuse LeapNetapp Steelstore Cloud Integrated StorageCanonical Ubuntu Linux17/6/202017/6/2026
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
ModificadaMedia (6.5)1.9%—Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+517/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
ModificadaMedia (5.4)1.6%—Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+517/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rre.c allows out-of-bounds access via encodings.
ModificadaMedia (5.4)1.6%—Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+517/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/hextile.c allows out-of-bounds access via encodings.
ModificadaMedia (5.4)1.9%—Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+517/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/corre.c allows out-of-bounds access via encodings.
ModificadaAlta (7.5)2.8%—Libvncserver Project LibvncserverDebian LinuxOpensuse LeapCanonical Ubuntu Linux17/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary
ModificadaAlta (7.5)2.8%—Libvncserver Project LibvncserverDebian LinuxOpensuse LeapCanonical Ubuntu Linux17/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed.
ModificadaAlta (7.5)2.8%—Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+617/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.
ModificadaAlta (7.5)3.4%—Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+617/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.