Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

601 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.12%—Linuxfoundation Edge Virtualization Engine20/9/202317/6/2026
Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the system update different PCR values in the TPM, resulting in a unique value for each PCR entry. These PCRs are then used in order to seal/unseal a key from the TPM which is used to…
ModificadaAlta (8.8)0.11%—Linuxfoundation Edge Virtualization Engine20/9/202317/6/2026
PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, fixing this issue alone would not solve the problem of the config partition not being measured correctly. Also, the “vault” key is sealed/unsealed with…
ModificadaCrítica (9.8)1.2%—Linuxfoundation Nats-server19/9/202317/6/2026
NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account.
ModificadaMedia (4.4)0.10%—Linuxfoundation YoctoGoogle AndroidOpenwrt4/9/202317/6/2026
In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08037801; Issue ID: ALPS08037801.
ModificadaMedia (4.4)0.10%—Linuxfoundation YoctoGoogle AndroidOpenwrt4/9/202317/6/2026
In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017370; Issue ID: ALPS08017370.
ModificadaMedia (6.7)0.10%—Linuxfoundation YoctoGoogle AndroidOpenwrt4/9/202317/6/2026
In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esclation of privileges with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017365; Issue ID: ALPS08017365.
ModificadaMedia (6.7)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle Android4/9/202317/6/2026
In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID: ALPS07929848.
ModificadaMedia (4.4)0.10%—Linuxfoundation YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In bluetooth driver, there is a possible out of bounds read due to improper input validation. This could lead to local information leak with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07867212; Issue ID: ALPS07867212.
ModificadaMedia (4.4)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle Android4/9/202317/6/2026
In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588360; Issue ID: ALPS07588360.
ModificadaMedia (6.7)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidOpenwrt4/9/202317/6/2026
In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441589; Issue ID: ALPS07441589.
ModificadaMedia (6.5)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340381.
ModificadaMedia (6.5)0.11%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340350.
ModificadaMedia (6.5)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340433.
ModificadaMedia (4.2)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354025; Issue ID: ALPS07340108.
ModificadaMedia (4.2)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354023; Issue ID: ALPS07340098.
ModificadaMedia (4.2)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07197795; Issue ID: ALPS07340357.
ModificadaMedia (4.2)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354058; Issue ID: ALPS07340121.
ModificadaMedia (4.2)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340119; Issue ID: ALPS07340119.
ModificadaMedia (6.5)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354259; Issue ID: ALPS07340477.
ModificadaMedia (6.5)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326441.
ModificadaMedia (6.5)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326430; Issue ID: ALPS07326430.
ModificadaMedia (4.2)0.10%—Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326409.
ModificadaMedia (4)0.09%—Linuxfoundation YoctoGoogle AndroidLinux Kernel4/9/202317/6/2026
In imgsys, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326418.
ModificadaMedia (6.4)0.07%—Linuxfoundation YoctoMediatek IOT YoctoGoogle Android4/9/202317/6/2026
In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID: ALPS07326570.
ModificadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/9/202317/6/2026
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08013530.
Orbitaley — Vulnerabilidades