Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

4419 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)2.1%—PHPFedoraproject FedoraDebian LinuxOpensuse Leap+42/10/202017/6/2026
In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to both decreased security and incorrect encryption data.
ModificadaAlta (8.8)0.43%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap30/9/202017/6/2026
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a virtual machine to write arbitrary data to any address in the vhost_crypto application. The highest threat from this vulnerability is to data…
ModificadaBaja (3.3)0.40%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap30/9/202017/6/2026
An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used…
ModificadaAlta (7.1)0.41%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap30/9/202017/6/2026
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A complete lack of validation of attacker-controlled parameters can lead to a buffer over read. The results of the over read are then written back to the guest virtual machine memory. This vulnerability can be used by an attacker in a virtual…
ModificadaAlta (7.8)0.40%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap30/9/202017/6/2026
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A lack of bounds checking when copying iv_data from the VM guest memory into host memory can lead to a large buffer overflow. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
ModificadaAlta (7.8)0.25%—Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap30/9/202017/6/2026
A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the virtual machine and the host. An attacker in a VM can change the contents of the memory after vhost_crypto has validated it. The highest…
ModificadaMedia (6.5)2.3%—Python Urllib3Canonical Ubuntu LinuxDebian LinuxOracle Communications Cloud Native Core Network Function Cloud Native Environment+130/9/202017/6/2026
urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-2020-26116.
ModificadaAlta (7.2)6.4%—PythonFedoraproject FedoraCanonical Ubuntu LinuxNetapp Solidfire+427/9/202017/6/2026
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
ModificadaMedia (5.5)0.40%—Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux24/9/202017/6/2026
A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.
ModificadaMedia (6.1)1.4%—GON Project GONCanonical Ubuntu LinuxDebian Linux23/9/202017/6/2026
An issue was discovered in the gon gem before gon-6.4.0 for Ruby. MultiJson does not honor the escape_mode parameter to escape fields as an XSS protection mechanism. To mitigate, json_dumper.rb in gon now does escaping for XSS by default without relying on MultiJson.
ModificadaMedia (4.7)0.49%—Perl DBIFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+117/9/202017/6/2026
An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.
ModificadaAlta (7.8)1.2%—Cryptsetup Project CryptsetupRedhat Enterprise LinuxCanonical Ubuntu LinuxFedoraproject Fedora16/9/202017/6/2026
A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file 'lib/luks2/luks2_json_metadata.c' in function…
ModificadaMedia (5.5)0.55%—Perl Database InterfaceCanonical Ubuntu LinuxOpensuse LeapFedoraproject Fedora+116/9/202017/6/2026
An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability.
ModificadaMedia (5.5)0.42%—Linux KernelCanonical Ubuntu LinuxDebian Linux15/9/202017/6/2026
A flaw was found in the Linux kernel before 5.9-rc4. A failure of the file system metadata validator in XFS can cause an inode with a valid, user-creatable extended attribute to be flagged as corrupt. This can lead to the filesystem being shutdown, or otherwise rendered inaccessible until it is remounted, leading to a…
ModificadaMedia (5.5)0.37%—Linux KernelDebian LinuxCanonical Ubuntu LinuxStarwindsoftware Starwind Virtual SAN15/9/202017/6/2026
A memory out-of-bounds read flaw was found in the Linux kernel before 5.9-rc2 with the ext3/ext4 file system, in the way it accesses a directory with broken indexing. This flaw allows a local user to crash the system if the directory exists. The highest threat from this vulnerability is to system availability.
ModificadaAlta (7.8)0.59%—X.org X ServerCanonical Ubuntu LinuxRedhat Enterprise Linux15/9/202017/6/2026
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
ModificadaAlta (7.8)0.61%—X.org X ServerCanonical Ubuntu LinuxRedhat Enterprise Linux15/9/202017/6/2026
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
ModificadaAlta (7.8)0.63%—X.org X ServerCanonical Ubuntu LinuxRedhat Enterprise Linux15/9/202017/6/2026
A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
ModificadaAlta (7.8)0.59%—X.org X ServerCanonical Ubuntu Linux15/9/202017/6/2026
A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
ModificadaMedia (6.5)3.2%—Google BrotliDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+615/9/202017/6/2026
A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over chunks of data larger than 2 GiB. It is recommended to update your Brotli library to 1.0.8 or…
ModificadaMedia (6.4)0.27%—Linux KernelDebian LinuxCanonical Ubuntu Linux13/9/202017/6/2026
A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.
ModificadaMedia (5.3)2.7%—Perl DBICanonical Ubuntu Linux11/9/202017/6/2026
An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.
ModificadaBaja (3.3)0.50%—Canonical Ubuntu-ui-toolkit11/9/202017/6/2026
On desktop, Ubuntu UI Toolkit's StateSaver would serialise data on tmp/ files which an attacker could use to expose potentially sensitive data. StateSaver would also open files without the O_EXCL flag. An attacker could exploit this to launch a symlink attack, though this is partially mitigated by symlink and hardlink…
ModificadaAlta (7.5)4.4%—Libproxy Project LibproxyDebian LinuxFedoraproject FedoraOpensuse Leap+19/9/202017/6/2026
url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
ModificadaCrítica (9.8)17%—YawsCanonical Ubuntu LinuxDebian Linux9/9/202017/6/2026
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.