Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

518 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)9.3%—Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+1021/3/201917/6/2026
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
ModificadaCrítica (9.1)7.9%—Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+121/3/201917/6/2026
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
ModificadaCrítica (9.1)6.3%—Libssh2Fedoraproject FedoraDebian LinuxNetapp Ontap Select Deploy Administration Utility+121/3/201917/6/2026
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
ModificadaMedia (5.9)17%—OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+7827/2/201917/6/2026
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid…
ModificadaAlta (7.5)1.9%—Netapp Clustered Data Ontap27/2/201917/6/2026
Clustered Data ONTAP versions prior to 9.1P15 and 9.3 prior to 9.3P7 are susceptible to a vulnerability which discloses sensitive information to an unauthenticated user.
ModificadaCrítica (9.8)4.7%—GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage+226/2/201917/6/2026
In the GNU C Library (aka glibc or libc6) through 2.29, proceed_next_node in posix/regexec.c has a heap-based buffer over-read via an attempted case-insensitive regular-expression match.
ModificadaAlta (7.5)5.8%—GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage26/2/201917/6/2026
In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\\1\\1|t1|\\\2537)+' in grep.
ModificadaAlta (7.5)3.9%—GNU GlibcNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Steelstore Cloud Integrated Storage26/2/201916/6/2026
In the GNU C Library (aka glibc or libc6) before 2.28, parse_reg_exp in posix/regcomp.c misparses alternatives, which allows attackers to cause a denial of service (assertion failure and application exit) or trigger an incorrect result by attempting a regular-expression match.
ModificadaAlta (7.5)4.3%—Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Clustered Data Ontap+36/2/201917/6/2026
libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond…
ModificadaCrítica (9.8)13%—Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+126/2/201917/6/2026
libcurl versions from 7.36.0 to before 7.64.0 are vulnerable to a stack-based buffer overflow. The function creating an outgoing NTLM type-3 header (`lib/vauth/ntlm.c:Curl_auth_create_ntlm_type3_message()`), generates the request HTTP header contents based on previously received data. The check that exists to prevent…
ModificadaAlta (7.5)5.4%💥 PoCHaxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Clustered Data Ontap+66/2/201917/6/2026
libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a…
ModificadaMedia (4.4)1.2%—Netapp Clustered Data Ontap1/2/201917/6/2026
Clustered Data ONTAP versions 9.0 through 9.4 are susceptible to a vulnerability which allows remote authenticated attackers to cause a Denial of Service (DoS) in NFS and SMB environments. Exploitation of this vulnerability will allow a remote authenticated attacker to cause a Denial of Service (DoS) on affected…
ModificadaMedia (6.8)21%💥 ExploitOpenbsd OpensshWinscpNetapp Element SoftwareNetapp Ontap Select Deploy+331/1/201917/6/2026
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
ModificadaMedia (6.8)3.8%—Openbsd OpensshWinscpCanonical Ubuntu LinuxDebian Linux+1631/1/201917/6/2026
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects…
ModificadaMedia (4.4)0.37%—Netapp Clustered Data Ontap24/1/201917/6/2026
Clustered Data ONTAP versions prior to 9.1P16, 9.3P10 and 9.4P5 are susceptible to a vulnerability which discloses sensitive information to an unauthorized user.
ModificadaAlta (7.5)60%💥 PoCISC BindRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+716/1/201917/6/2026
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an…
ModificadaAlta (7.5)10%—ISC BindNetapp Cloud BackupNetapp Data Ontap Edge16/1/201917/6/2026
A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.c, even when stale-answer-enable is off. Additionally, problematic interaction between the serve-stale feature and NSEC aggressive negative caching can in some cases cause undesirable behavior from…
ModificadaMedia (5.3)18%—ISC BindNetapp Cloud BackupNetapp Data Ontap Edge16/1/201917/6/2026
An error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND attempts several transfers of a slave zone in quick succession. This defect could be deliberately exercised by an attacker who is permitted to cause a vulnerable server to initiate…
ModificadaAlta (7.5)6.3%—ISC BindNetapp Data Ontap EdgeNetapp Solidfire Element OS Management Node16/1/201917/6/2026
While handling a particular type of malformed packet BIND erroneously selects a SERVFAIL rcode instead of a FORMERR rcode. If the receiving view has the SERVFAIL cache feature enabled, this can trigger an assertion failure in badcache.c when the request doesn't contain all of the expected information. Affects BIND…
ModificadaAlta (7.5)28%—ISC BindRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+616/1/201917/6/2026
BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to…
ModificadaMedia (5.9)12%—ISC BindNetapp Data Ontap EdgeNetapp Element SoftwareNetapp Oncommand Balance16/1/201917/6/2026
If named is configured to use Response Policy Zones (RPZ) an error processing some rule types can lead to a condition where BIND will endlessly loop while handling a query. Affects BIND 9.9.10, 9.10.5, 9.11.0->9.11.1, 9.9.10-S1, 9.10.5-S1.
ModificadaMedia (5.3)5.5%—ISC BindNetapp Data Ontap EdgeNetapp Element SoftwareNetapp Oncommand Balance+116/1/201917/6/2026
named contains a feature which allows operators to issue commands to a running server by communicating with the server process over a control channel, using a utility program such as rndc. A regression introduced in a recent feature change has created a situation under which some versions of named can be caused to…
ModificadaAlta (7.5)9.0%—ISC BindRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+716/1/201917/6/2026
Mistaken assumptions about the ordering of records in the answer section of a response containing CNAME or DNAME resource records could lead to a situation in which named would exit with an assertion failure when processing a response in which records occurred in an unusual order. Affects BIND 9.9.9-P6,…
ModificadaMedia (5.9)11%—ISC BindRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+716/1/201917/6/2026
A query with a specific set of characteristics could cause a server using DNS64 to encounter an assertion failure and terminate. An attacker could deliberately construct a query, enabling denial-of-service against a server if it was configured to use the DNS64 feature and other preconditions were met. Affects BIND…
ModificadaMedia (5.9)17%—ISC BindRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+616/1/201917/6/2026
Under some conditions when using both DNS64 and RPZ to rewrite query responses, query processing can resume in an inconsistent state leading to either an INSIST assertion failure or an attempt to read through a NULL pointer. Affects BIND 9.8.8, 9.9.3-S1 -> 9.9.9-S7, 9.9.3 -> 9.9.9-P5, 9.9.10b1, 9.10.0 -> 9.10.4-P5,…