Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
494 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | IBM Qradar Incident Forensics | 5/12/2018 | 17/6/2026 | IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 144653. | |
| Modificada | Baja (3.3) | 0.35% | — | IBM Qradar Incident Forensics | 5/12/2018 | 17/6/2026 | IBM QRadar SIEM 7.2 and 7.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 143118. | |
| Modificada | Alta (7.4) | 0.64% | — | IBM Qradar Incident Forensics | 5/12/2018 | 17/6/2026 | IBM QRadar SIEM 7.2.8 and 7.3 does not validate, or incorrectly validates, a certificate. This weakness might allow an attacker to spoof a trusted entity by using a man-in-the-middle (MITM) attack. IBM X-force ID: 133120. | |
| Modificada | Media (5.5) | 0.97% | — | Radare2 | 4/12/2018 | 17/6/2026 | opmov in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2. | |
| Modificada | Media (5.5) | 0.98% | — | Radare2 | 4/12/2018 | 17/6/2026 | getToken in libr/asm/p/asm_x86_nz.c in radare2 before 3.1.0 allows attackers to cause a denial of service (stack-based buffer over-read) via crafted x86 assembly data, as demonstrated by rasm2. | |
| Modificada | Media (6.5) | 2.5% | — | IBM Qradar Incident Forensics | 5/10/2018 | 17/6/2026 | IBM QRadar Incident Forensics 7.2 and 7.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 144655. | |
| Modificada | Alta (7.5) | 1.4% | — | IBM Qradar Incident Forensics | 5/10/2018 | 17/6/2026 | IBM QRadar Incident Forensics 7.2 and 7.3 does not properly restrict the size or amount of resources requested which could allow an unauthenticated user to cause a denial of service. IBM X-Force ID: 144650. | |
| Modificada | Media (5.5) | 0.96% | — | Radare2 | 12/9/2018 | 17/6/2026 | In radare2 before 2.9.0, a heap overflow vulnerability exists in the read_module_referenced_functions function in libr/anal/flirt.c via a crafted flirt signature file. | |
| Modificada | Alta (8.8) | 4.7% | — | IBM Qradar Security Information AND Event Manager | 11/9/2018 | 17/6/2026 | IBM QRadar 7.2 and 7.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 143121. | |
| Modificada | Media (5.8) | 56% | 💥 Exploit | IBM Qradar Security Information AND Event Manager | 17/7/2018 | 17/6/2026 | IBM QRadar Incident Forensics (IBM QRadar SIEM 7.2, and 7.3) could allow a remote attacker to bypass authentication and obtain sensitive information. IBM X-Force ID: 144164. | |
| Modificada | Media (5.5) | 1.2% | — | Radare2 | 12/7/2018 | 17/6/2026 | The r_bin_java_annotation_new function in shlr/java/class.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted .class file because of missing input validation in r_bin_java_line_number_table_attr_new. | |
| Modificada | Media (5.5) | 1.2% | — | Radare2 | 12/7/2018 | 17/6/2026 | The r_bin_mdmp_init_directory_entry function in mdmp.c in radare2 2.7.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Mini Crash Dump file. | |
| Analizada | Media (5.5) | 1.2% | — | Radare2 | 12/7/2018 | 17/6/2026 | The sdb_set_internal function in sdb.c in radare2 2.7.0 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted ELF file because of missing input validation in r_bin_dwarf_parse_comp_unit in libr/bin/dwarf.c. | |
| Modificada | Media (5.5) | 0.85% | — | Radare2 | 13/6/2018 | 17/6/2026 | There is a heap out of bounds read in radare2 2.6.0 in _6502_op() in libr/anal/p/anal_6502.c via a crafted iNES ROM binary file. | |
| Modificada | Alta (7.8) | 1.0% | — | Radare2 | 13/6/2018 | 17/6/2026 | There is a heap out of bounds read in radare2 2.6.0 in java_switch_op() in libr/anal/p/anal_java.c via a crafted Java binary file. | |
| Modificada | Alta (7.8) | 1.0% | — | Radare2 | 13/6/2018 | 17/6/2026 | There is a use after free in radare2 2.6.0 in r_anal_bb_free() in libr/anal/bb.c via a crafted Java binary file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 22/5/2018 | 17/6/2026 | The sh_op() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 22/5/2018 | 17/6/2026 | The r_strbuf_fini() function in radare2 2.5.0 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted ELF file because of an uninitialized variable in the CPSE handler in libr/anal/p/anal_avr.c. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 22/5/2018 | 17/6/2026 | The _inst__sts() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file. | |
| Modificada | Media (5.5) | 0.90% | — | Radare2 | 22/5/2018 | 17/6/2026 | The string_scan_range() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file. | |
| Modificada | Media (5.5) | 0.90% | — | Radare2 | 22/5/2018 | 17/6/2026 | The parse_import_ptr() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted Mach-O file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 22/5/2018 | 17/6/2026 | The get_debug_info() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted PE file. | |
| Modificada | Alta (7.8) | 1.1% | — | Radare2 | 22/5/2018 | 17/6/2026 | The wasm_dis() function in libr/asm/arch/wasm/wasm.c in or possibly have unspecified other impact via a crafted WASM file. | |
| Modificada | Media (5.5) | 1.4% | — | Radare2 | 22/5/2018 | 17/6/2026 | The avr_op_analyze() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 22/5/2018 | 17/6/2026 | The r_read_le32() function in radare2 2.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted ELF file. |