Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
623 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 8.5% | — | RubygemsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 31/8/2017 | 17/6/2026 | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command. | |
| Modificada | Crítica (9.8) | 11% | — | RubygemsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 31/8/2017 | 17/6/2026 | RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences. | |
| Modificada | Crítica (9.8) | 9.4% | — | Ruby-lang RubyDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+5 | 31/8/2017 | 17/6/2026 | Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can expose arbitrary memory during a JSON.generate call. The issues lies in using strdup in ext/json/ext/generator/generator.c, which will stop after encountering a '\0' byte, returning a pointer to a string of length zero, which is not the length stored… | |
| Modificada | Alta (8.8) | 3.6% | — | Icoutils Project IcoutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 22/8/2017 | 17/6/2026 | Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code. | |
| Modificada | Alta (7) | 13% | 💥 Exploit | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux AUSRedhat Enterprise Linux Server EUS+2 | 19/8/2017 | 17/6/2026 | Race condition in fs/timerfd.c in the Linux kernel before 4.10.15 allows local users to gain privileges or cause a denial of service (list corruption or use-after-free) via simultaneous file-descriptor operations that leverage improper might_cancel queueing. | |
| Modificada | Media (4.9) | 3.2% | — | Oracle MysqlDebian LinuxRedhat OpenstackRedhat Enterprise Linux Desktop+6 | 8/8/2017 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML). Supported versions that are affected are 5.5.56 and earlier, 5.6.36 and earlier and 5.7.18 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise… | |
| Modificada | Media (5.3) | 0.43% | — | Oracle MysqlDebian LinuxRedhat OpenstackRedhat Enterprise Linux Desktop+6 | 8/8/2017 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client programs). Supported versions that are affected are 5.5.56 and earlier and 5.6.36 and earlier. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise… | |
| Modificada | Media (5.9) | 12% | — | NTPDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+10 | 7/8/2017 | 17/6/2026 | ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets. | |
| Modificada | Alta (7.5) | 11% | — | NTPDebian LinuxNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+10 | 7/8/2017 | 17/6/2026 | The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages. | |
| Modificada | Media (6.5) | 5.2% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 7/8/2017 | 17/6/2026 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750. | |
| Modificada | Alta (7.5) | 6.5% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 7/8/2017 | 17/6/2026 | Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (memory consumption). | |
| Modificada | Alta (7.5) | 6.5% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 7/8/2017 | 17/6/2026 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750. | |
| Modificada | Alta (7.5) | 7.1% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 7/8/2017 | 17/6/2026 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750. | |
| Modificada | Media (5.5) | 0.38% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+3 | 25/7/2017 | 17/6/2026 | The Hotspot component in OpenJDK8 as packaged in Red Hat Enterprise Linux 6 and 7 allows local users to write to arbitrary files via a symlink attack. | |
| Modificada | Alta (7.8) | 0.63% | — | QemuCanonical Ubuntu LinuxDebian LinuxRedhat Openstack+7 | 25/7/2017 | 17/6/2026 | Heap-based buffer overflow in Cirrus CLGD 54xx VGA Emulator in Quick Emulator (Qemu) 2.8 and earlier allows local guest OS users to execute arbitrary code or cause a denial of service (crash) via vectors related to a VNC client updating its display after a VGA operation. | |
| Modificada | Alta (7.5) | 3.8% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 24/7/2017 | 17/6/2026 | The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to… | |
| Modificada | Alta (7.5) | 9.1% | — | Fedoraproject FedoraSuse Linux Enterprise DebuginfoOpensuse LeapOpensuse+16 | 21/7/2017 | 17/6/2026 | The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to… | |
| Modificada | Alta (7.5) | 3.8% | — | FreeradiusDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 17/7/2017 | 17/6/2026 | An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service. | |
| Modificada | Crítica (9.1) | 57% | — | Apache Http ServerDebian LinuxApple MAC OS XNetapp Oncommand Unified Manager+11 | 13/7/2017 | 17/6/2026 | In Apache httpd before 2.2.34 and 2.4.x before 2.4.27, the value placeholder in [Proxy-]Authorization headers of type 'Digest' was not initialized or reset before or between successive key=value assignments by mod_auth_digest. Providing an initial key with no '=' assignment could reflect the stale value of… | |
| Modificada | Alta (7.8) | 2.0% | — | Freedesktop PopplerDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 22/6/2017 | 17/6/2026 | Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document. | |
| Modificada | Media (6.5) | 4.3% | — | Freedesktop PopplerDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 22/6/2017 | 17/6/2026 | Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document. | |
| Modificada | Alta (7.8) | 2.7% | 💥 Exploit | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+16 | 19/6/2017 | 17/6/2026 | glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these… | |
| Modificada | Alta (8.8) | 22% | 💥 Exploit | MercurialDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 6/6/2017 | 17/6/2026 | In Mercurial before 4.1.3, "hg serve --stdio" allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name. | |
| Modificada | Media (6.5) | 4.2% | — | SambaRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+4 | 6/6/2017 | 17/6/2026 | smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks. | |
| Modificada | Media (6.6) | 2.6% | — | Oracle MysqlRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+5 | 24/4/2017 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to… |