Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

609 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.4%—Openstack Puppet-gerrit12/1/201717/6/2026
The Gerrit configuration in the Openstack Puppet module for Gerrit (aka puppet-gerrit) improperly marks text/html as a safe mimetype, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a crafted review.
ModificadaMedia (6.5)0.41%—QemuDebian LinuxRedhat OpenstackRedhat Virtualization23/12/201617/6/2026
Quick emulator (Qemu) built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to a divide by zero issue. It could occur while copying VGA data when cirrus graphics mode was set to be VGA. A privileged user inside guest could use this flaw to crash the Qemu process instance on the host, resulting in DoS.
ModificadaMedia (6.5)0.38%—QemuDebian LinuxRedhat OpenstackRedhat Virtualization23/12/201617/6/2026
Quick Emulator (Qemu) built with the USB EHCI Emulation support is vulnerable to a memory leakage issue. It could occur while processing packet data in 'ehci_init_transfer'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
ModificadaMedia (6.5)0.43%—QemuDebian LinuxRedhat OpenstackRedhat Virtualization23/12/201617/6/2026
Quick Emulator (Qemu) built with the USB redirector usb-guest support is vulnerable to a memory leakage flaw. It could occur while destroying the USB redirector in 'usbredir_handle_destroy'. A guest user/process could use this issue to leak host memory, resulting in DoS for a host.
ModificadaMedia (6)0.42%—QemuOpensuse LeapRedhat OpenstackRedhat Virtualization10/12/201617/6/2026
Memory leak in the usb_xhci_exit function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator), when the xhci uses msix, allows local guest OS administrators to cause a denial of service (memory consumption and possibly QEMU process crash) by repeatedly unplugging a USB device.
ModificadaMedia (6)0.36%—QemuOpensuse LeapRedhat OpenstackRedhat Virtualization10/12/201617/6/2026
The virtqueue_map_desc function in hw/virtio/virtio.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (NULL pointer dereference and QEMU process crash) via a large I/O descriptor buffer length value.
ModificadaMedia (4.4)0.40%—QemuDebian LinuxRedhat VirtualizationRedhat Openstack10/12/201617/6/2026
Integer overflow in the net_tx_pkt_init function in hw/net/net_tx_pkt.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (QEMU process crash) via the maximum fragmentation count, which triggers an unchecked multiplication and NULL pointer dereference.
ModificadaCrítica (9.8)2.4%—Barclamp-trove Project Barclamp-troveCrowbar-openstack Project Crowbar-openstack9/12/201617/6/2026
The trove service user in (1) Openstack deployment (aka crowbar-openstack) and (2) Trove Barclamp (aka barclamp-trove and crowbar-barclamp-trove) in the Crowbar Framework has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors.
ModificadaMedia (6)0.41%—QemuDebian LinuxOpensuse LeapRedhat Openstack+14/11/201617/6/2026
The rtl8139_cplus_transmit function in hw/net/rtl8139.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) by leveraging failure to limit the ring descriptor count.
ModificadaMedia (6)0.44%—QemuDebian LinuxOpensuse LeapRedhat Openstack+14/11/201617/6/2026
The intel_hda_xfer function in hw/audio/intel-hda.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via an entry with the same value for buffer length and pointer position.
ModificadaMedia (6)0.36%—QemuOpensuse LeapRedhat OpenstackRedhat Virtualization+14/11/201617/6/2026
The serial_update_parameters function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (divide-by-zero error and QEMU process crash) via vectors involving a value of divider greater than baud base.
ModificadaMedia (6)0.40%—QemuOpensuse LeapRedhat OpenstackRedhat Virtualization+14/11/201617/6/2026
The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (infinite loop and QEMU process crash) by leveraging failure to limit the number of link Transfer Request Blocks (TRB) to process.
ModificadaMedia (4.3)1.5%—Openstack Heat4/11/201617/6/2026
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.
ModificadaAlta (7.5)3.1%—Openstack CinderOpenstack GlanceOpenstack Nova7/10/201617/6/2026
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consumption) via a crafted disk image.
ModificadaMedia (6.5)2.3%—Openstack Compute (nova)27/9/201617/6/2026
OpenStack Compute (nova) 13.0.0 does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. NOTE: this vulnerability exists because of a CVE-2015-3280 regression.
ModificadaCrítica (9.8)3.2%—Openstack Mitaka-muranoOpenstack MuranoOpenstack Murano-dashboardOpenstack Python-muranoclient26/9/201617/6/2026
OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and python-muranoclient before 0.7.3 (liberty) and 0.8.x before 0.8.5 (mitaka) improperly use loaders inherited from yaml.Loader when parsing MuranoPL and UI files, which allows…
ModificadaCrítica (9.8)68%💥 ExploitOracle MysqlPercona ServerMariadbDebian Linux+820/9/201617/6/2026
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain…
ModificadaMedia (5.5)0.52%—Canonical Ubuntu LinuxOracle LinuxOracle VM ServerQemu+92/8/201617/6/2026
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
ModificadaAlta (7.5)2.9%—Redhat OpenstackCanonical Openstack Ironic12/7/201617/6/2026
The ironic-api service in OpenStack Ironic before 4.2.5 (Liberty) and 5.x before 5.1.2 (Mitaka) allows remote attackers to obtain sensitive information about a registered node by leveraging knowledge of the MAC address of a network card belonging to that node and sending a crafted POST request to the…
ModificadaMedia (5.4)2.1%—Openstack HorizonRedhat OpenstackDebian Linux12/7/201617/6/2026
Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form.
ModificadaAlta (7.5)45%—NTPOracle SolarisSuse Manager ProxySuse Openstack Cloud+55/7/201617/6/2026
ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547.
ModificadaMedia (5.3)16%—NTPOracle SolarisSuse Manager ProxySuse Openstack Cloud+65/7/201617/6/2026
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548.
ModificadaMedia (5.9)8.8%—NTPOracle SolarisSuse Manager ProxySuse Openstack Cloud+65/7/201617/6/2026
ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time.
ModificadaAlta (7.5)13%—NTPOracle SolarisSuse ManagerSuse Manager Proxy+85/7/201617/6/2026
The process_packet function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (peer-variable modification) by sending spoofed packets from many source IP addresses in a certain scenario, as demonstrated by triggering an incorrect leap indication.
ModificadaAlta (7.5)17%—NTPOracle SolarisSuse ManagerSuse Manager Proxy+85/7/201617/6/2026
ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (ephemeral-association demobilization) by sending a spoofed crypto-NAK packet with incorrect authentication data at a certain time.