Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.12% | — | Linuxfoundation Edge Virtualization Engine | 20/9/2023 | 17/6/2026 | Vault Key Sealed With SHA1 PCRs The measured boot solution implemented in EVE OS leans on a PCR locking mechanism. Different parts of the system update different PCR values in the TPM, resulting in a unique value for each PCR entry. These PCRs are then used in order to seal/unseal a key from the TPM which is used to… | |
| Modificada | Alta (8.8) | 0.11% | — | Linuxfoundation Edge Virtualization Engine | 20/9/2023 | 17/6/2026 | PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, fixing this issue alone would not solve the problem of the config partition not being measured correctly. Also, the “vault” key is sealed/unsealed with… | |
| Modificada | Crítica (9.8) | 1.2% | — | Linuxfoundation Nats-server | 19/9/2023 | 17/6/2026 | NATS nats-server 2.2.0 through 2.7.4 allows directory traversal because of an unintended path to a management action from a management account. | |
| Modificada | Media (4.4) | 0.10% | — | Linuxfoundation YoctoGoogle AndroidOpenwrt | 4/9/2023 | 17/6/2026 | In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08037801; Issue ID: ALPS08037801. | |
| Modificada | Media (4.4) | 0.10% | — | Linuxfoundation YoctoGoogle AndroidOpenwrt | 4/9/2023 | 17/6/2026 | In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017370; Issue ID: ALPS08017370. | |
| Modificada | Media (6.7) | 0.10% | — | Linuxfoundation YoctoGoogle AndroidOpenwrt | 4/9/2023 | 17/6/2026 | In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esclation of privileges with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08017365; Issue ID: ALPS08017365. | |
| Modificada | Media (6.7) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle Android | 4/9/2023 | 17/6/2026 | In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929848; Issue ID: ALPS07929848. | |
| Modificada | Media (4.4) | 0.10% | — | Linuxfoundation YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In bluetooth driver, there is a possible out of bounds read due to improper input validation. This could lead to local information leak with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07867212; Issue ID: ALPS07867212. | |
| Modificada | Media (4.4) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle Android | 4/9/2023 | 17/6/2026 | In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07588360; Issue ID: ALPS07588360. | |
| Modificada | Media (6.7) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidOpenwrt | 4/9/2023 | 17/6/2026 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07441589; Issue ID: ALPS07441589. | |
| Modificada | Media (6.5) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340381. | |
| Modificada | Media (6.5) | 0.11% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340350. | |
| Modificada | Media (6.5) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340433; Issue ID: ALPS07340433. | |
| Modificada | Media (4.2) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354025; Issue ID: ALPS07340108. | |
| Modificada | Media (4.2) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354023; Issue ID: ALPS07340098. | |
| Modificada | Media (4.2) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07197795; Issue ID: ALPS07340357. | |
| Modificada | Media (4.2) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354058; Issue ID: ALPS07340121. | |
| Modificada | Media (4.2) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07340119; Issue ID: ALPS07340119. | |
| Modificada | Media (6.5) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07354259; Issue ID: ALPS07340477. | |
| Modificada | Media (6.5) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326441. | |
| Modificada | Media (6.5) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326430; Issue ID: ALPS07326430. | |
| Modificada | Media (4.2) | 0.10% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326409. | |
| Modificada | Media (4) | 0.09% | — | Linuxfoundation YoctoGoogle AndroidLinux Kernel | 4/9/2023 | 17/6/2026 | In imgsys, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS07326455; Issue ID: ALPS07326418. | |
| Modificada | Media (6.4) | 0.07% | — | Linuxfoundation YoctoMediatek IOT YoctoGoogle Android | 4/9/2023 | 17/6/2026 | In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07341261; Issue ID: ALPS07326570. | |
| Modificada | Media (6.7) | 0.09% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 4/9/2023 | 17/6/2026 | In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08013530. |