Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
368 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.6) | 1.6% | — | Oracle Virtualization | 18/1/2012 | 16/6/2026 | Unspecified vulnerability in the Virtual Desktop Infrastructure (VDI) component in Oracle Virtualization 3.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Session. NOTE: this CVE identifier was accidentally used for a Concurrency issue in Java Runtime… | |
| Modificada | Media (6.8) | 2.1% | — | Oracle Virtualization | 18/10/2011 | 16/6/2026 | Unspecified vulnerability in the Sun Ray component in Oracle Virtualization 4.0 allows remote attackers to affect integrity, related to Authentication. NOTE: this identifier was inadvertently used for an Oracle Industry Applications issue involving TMS Help, but that issue has been assigned CVE-2011-2323. | |
| Modificada | Media (5.7) | 0.99% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Virtualization Hypervisor | 31/8/2011 | 16/6/2026 | The Generic Receive Offload (GRO) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux 5 and 2.6.32 on Red Hat Enterprise Linux 6, as used in Red Hat Enterprise Virtualization (RHEV) Hypervisor and other products, allows remote attackers to cause a denial of service via crafted VLAN packets that are… | |
| Modificada | Alta (9.3) | 1.7% | — | IBM Systems DirectorIBM Virtualization Manager | 20/5/2011 | 16/6/2026 | Unspecified vulnerability in Virtualization Manager 1.2.2 in IBM Systems Director 1.2.2 has unknown impact and attack vectors. | |
| Modificada | Media (6.8) | 1.0% | — | Redhat Spice-activexRedhat Enterprise Virtualization Manager | 8/12/2010 | 16/6/2026 | Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of… | |
| Modificada | Media (5.7) | 1.00% | — | Redhat Enterprise Virtualization | 24/8/2010 | 16/6/2026 | Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization (RHEV) 2.2 does not properly accept TCP connections for SSL sessions, which allows remote attackers to cause a denial of service (daemon outage) via crafted SSL traffic. | |
| Modificada | Media (6.6) | 0.28% | — | Redhat Enterprise VirtualizationRedhat KVM | 24/8/2010 | 16/6/2026 | The subpage MMIO initialization functionality in the subpage_register function in exec.c in QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly select the index for access to the callback array, which allows guest OS users to cause a… | |
| Modificada | Media (4.6) | 0.36% | — | Redhat Enterprise VirtualizationRedhat KVM | 24/8/2010 | 16/6/2026 | The Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2, and KVM 83, when the Intel VT-x extension is enabled, allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via vectors related to instruction emulation. | |
| Modificada | Media (6.6) | 0.31% | — | Redhat Enterprise VirtualizationRedhat KVM | 24/8/2010 | 16/6/2026 | QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain privileges via… | |
| Modificada | Media (6.6) | 0.31% | — | Redhat Enterprise VirtualizationRedhat Qspice | 24/8/2010 | 16/6/2026 | libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly restrict the addresses upon which memory-management actions are performed, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain… | |
| Modificada | Media (6.6) | 0.31% | — | Redhat Enterprise VirtualizationRedhat Qspice | 24/8/2010 | 16/6/2026 | libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain… | |
| Modificada | Baja (2.1) | 0.33% | — | Redhat Enterprise Virtualization Manager | 24/6/2010 | 16/6/2026 | The snapshot merging functionality in Red Hat Enterprise Virtualization Manager (aka RHEV-M) before 2.2 does not properly pass the postzero parameter during operations on deleted volumes, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine. | |
| Modificada | Baja (2.1) | 0.37% | — | Redhat Enterprise Virtualization Hypervisor | 24/6/2010 | 16/6/2026 | Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to obtain sensitive information by examining the disk blocks… | |
| Modificada | Alta (7.5) | 11% | — | Linux KernelRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+2 | 27/1/2010 | 16/6/2026 | A certain Red Hat patch for net/ipv4/route.c in the Linux kernel 2.6.18 on Red Hat Enterprise Linux (RHEL) 5 allows remote attackers to cause a denial of service (deadlock) via crafted packets that force collisions in the IPv4 routing hash table, and trigger a routing "emergency" in which a hash chain is too long.… | |
| Modificada | Alta (7.2) | 0.42% | — | Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+9 | 20/11/2009 | 16/6/2026 | Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain privileges via a negative event index in an IOCTL request. | |
| Modificada | Alta (7.1) | 0.44% | — | Linux KernelRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+14 | 16/11/2009 | 16/6/2026 | The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the driver by modifying this file. | |
| Modificada | Baja (2.1) | 0.41% | — | Linux KernelSuse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise Desktop+9 | 20/10/2009 | 16/6/2026 | arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode. | |
| Modificada | Alta (10) | 4.5% | — | Redhat Enterprise VirtualizationJasper Project Jasper | 2/10/2008 | 16/6/2026 | Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf. |