Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

518 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)6.8%—ISC BindNetapp Data Ontap EdgeNetapp Solidfire Element OS Management Node16/1/201917/6/2026
An error in handling certain queries can cause an assertion failure when a server is using the nxdomain-redirect feature to cover a zone for which it is also providing authoritative service. A vulnerable server could be intentionally stopped by an attacker if it was using a configuration that met the criteria for the…
ModificadaMedia (5.3)3.7%—Openbsd OpensshWinscpNetapp Cloud BackupNetapp Element Software+1810/1/201917/6/2026
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
ModificadaMedia (4.4)0.39%—Netapp Data Ontap4/12/201817/6/2026
Data ONTAP operating in 7-Mode versions prior to 8.2.5P2 are susceptible to a vulnerability which discloses sensitive information to an unauthorized user.
ModificadaMedia (5.5)2.3%—GNU BinutilsDebian LinuxNetapp Data Ontap23/10/201817/6/2026
An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in elf_link_input_bfd when used for finding STT_TLS symbols without any TLS section. A specially crafted ELF allows remote…
ModificadaMedia (5.5)2.3%—GNU BinutilsDebian LinuxNetapp Data Ontap23/10/201817/6/2026
An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in _bfd_add_merge_section when attempting to merge sections with large alignments. A specially crafted ELF allows remote…
ModificadaMedia (5.5)2.3%—GNU BinutilsDebian LinuxNetapp Data Ontap23/10/201817/6/2026
A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, because _bfd_add_merge_section mishandles section merges when size is not a multiple of entsize. A specially crafted ELF…
ModificadaAlta (7.5)3.6%—Net-snmpNetapp Cloud BackupNetapp Hyper Converged InfrastructureNetapp Storagegrid Webscale+38/10/201817/6/2026
snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
ModificadaMedia (6.5)18%💥 ExploitNet-snmpDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+68/10/201817/6/2026
_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.
ModificadaMedia (5.3)3.6%—Openbsd OpensshNetapp Cloud BackupNetapp Data Ontap EdgeNetapp Ontap Select Deploy+228/8/201817/6/2026
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a…
ModificadaAlta (7.5)3.9%—Palletsprojects FlaskNetapp Active IQNetapp Hyper Converged InfrastructureNetapp Ontap Select Deploy Utility20/8/201817/6/2026
The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of service. This attack appear to be exploitable via Attacker provides JSON data in incorrect encoding. This vulnerability…
ModificadaMedia (5.3)99%💥 ExploitOpenbsd OpensshDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1817/8/201817/6/2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
ModificadaAlta (8.8)0.86%—Netapp Clustered Data Ontap3/8/201817/6/2026
Read-Only export policy rules are not correctly enforced in Clustered Data ONTAP 8.3 Release Candidate versions and therefore may allow more than "read-only" access from authenticated SMBv2 and SMBv3 clients. This behavior has been resolved in the GA release. Customers running prior release candidates (RCs) are…
ModificadaMedia (5.9)4.7%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+1618/7/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise…
ModificadaAlta (8.3)3.2%—Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+1118/7/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaBaja (3.7)4.4%—Oracle JDKOracle JREOracle JrockitDebian Linux+2218/7/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network…
ModificadaAlta (8.3)1.9%—Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+1118/7/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Windows DLL). Supported versions that are affected are Java SE: 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human…
ModificadaAlta (8.3)2.6%—Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+1118/7/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u181, 8u172 and 10.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require…
ModificadaMedia (4.3)3.1%—Oracle JDKOracle JREHP XP7 Command ViewRedhat Satellite+1618/7/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaCrítica (9)2.1%—Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp Cloud Backup+1118/7/201817/6/2026
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in…
ModificadaAlta (7.5)7.3%—Canonical Ubuntu LinuxDebian LinuxPerlArchive\ \+57/6/201817/6/2026
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
ModificadaAlta (7.8)0.88%—GNU GlibcRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+618/5/201817/6/2026
An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper.
ModificadaCrítica (9.8)7.1%—GNU GlibcRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+518/5/201817/6/2026
stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.
ModificadaCrítica (9.8)16%—Apache Http ServerCanonical Ubuntu LinuxDebian LinuxNetapp Cloud Backup+926/3/201817/6/2026
In Apache httpd 2.2.0 to 2.4.29, when generating an HTTP Digest authentication challenge, the nonce sent to prevent reply attacks was not correctly generated using a pseudo-random seed. In a cluster of servers using a common Digest authentication configuration, HTTP requests could be replayed across servers by an…
ModificadaAlta (7.5)70%—Apache Http ServerDebian LinuxCanonical Ubuntu LinuxNetapp Santricity Cloud Connector+326/3/201817/6/2026
A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since…
ModificadaMedia (5.9)13%—Apache Http ServerCanonical Ubuntu LinuxNetapp Clustered Data OntapNetapp Santricity Cloud Connector+226/3/201817/6/2026
When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could…