Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
3303 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | Coturn Project CoturnDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+1 | 29/6/2020 | 17/6/2026 | In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from… | |
| Modificada | Alta (7.8) | 0.50% | — | Opensuse LeapOpensuse Tumbleweed Kopano-spamd | 29/6/2020 | 17/6/2026 | A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE… | |
| Modificada | Crítica (9.8) | 1.4% | — | Opensuse OSC | 29/6/2020 | 17/6/2026 | A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4; openSUSE Leap 15.1, openSUSE Factory allowed remote attackers that can change downloaded… | |
| Modificada | Alta (7.8) | 0.86% | — | Apache TomcatOpensuse Leap | 29/6/2020 | 17/6/2026 | A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux… | |
| Modificada | Media (5.3) | 0.54% | — | Opensuse Hylafax+ | 29/6/2020 | 17/6/2026 | A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries. This issue affects: openSUSE Leap 15.2 hylafax+ versions prior to 7.0.2-lp152.2.1. openSUSE Leap… | |
| Modificada | Alta (7.5) | 27% | 💥 PoC | Apache TomcatCanonical Ubuntu LinuxOracle Mysql Enterprise MonitorOracle Siebel UI Framework+4 | 26/6/2020 | 17/6/2026 | A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive. | |
| Modificada | Media (5.5) | 0.51% | — | Redhat Enterprise LinuxOpensuse Leap | 26/6/2020 | 17/6/2026 | A buffer over-read flaw was found in RH kernel versions before 5.0 in crypto_authenc_extractkeys in crypto/authenc.c in the IPsec Cryptographic algorithm's module, authenc. When a payload longer than 4 bytes, and is not following 4-byte alignment boundary guidelines, it causes a buffer over-read threat, leading to a… | |
| Modificada | Media (6.5) | 1.6% | — | Redhat Ceph StorageRedhat OpenstackFedoraproject FedoraOpensuse Leap+2 | 26/6/2020 | 17/6/2026 | A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made.… | |
| Modificada | Media (5.5) | 0.46% | — | OpenexrFedoraproject FedoraOpensuse LeapDebian Linux+1 | 26/6/2020 | 17/6/2026 | An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp. | |
| Modificada | Media (5.5) | 0.42% | — | OpenexrFedoraproject FedoraOpensuse LeapDebian Linux+1 | 26/6/2020 | 17/6/2026 | An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp. | |
| Modificada | Media (5.5) | 0.40% | — | OpenexrFedoraproject FedoraOpensuse Leap | 26/6/2020 | 17/6/2026 | An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference. | |
| Modificada | Media (4.9) | 3.4% | — | NTPOpensuse LeapNetapp Cloud BackupNetapp Steelstore Cloud Integrated Storage+12 | 24/6/2020 | 17/6/2026 | ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file. | |
| Modificada | Media (5.7) | 1.0% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079. | |
| Modificada | Alta (8) | 1.5% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084. | |
| Modificada | Media (4.3) | 1.2% | — | Sane-project Sane BackendsOpensuse LeapCanonical Ubuntu Linux | 24/6/2020 | 17/6/2026 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081. | |
| Modificada | Media (4.3) | 1.0% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083. | |
| Modificada | Media (4.3) | 1.1% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082. | |
| Modificada | Alta (8.8) | 3.0% | — | Sane-project Sane BackendsCanonical Ubuntu LinuxOpensuse Leap | 24/6/2020 | 17/6/2026 | A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080. | |
| Modificada | Media (6.5) | 1.8% | — | FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+1 | 22/6/2020 | 17/6/2026 | In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2. | |
| Modificada | Media (4.3) | 1.8% | — | FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+1 | 22/6/2020 | 17/6/2026 | In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2. | |
| Modificada | Alta (7.5) | 1.8% | — | FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+1 | 22/6/2020 | 17/6/2026 | In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2. | |
| Modificada | Media (6.5) | 1.8% | — | FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+1 | 22/6/2020 | 17/6/2026 | In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2. | |
| Modificada | Media (6.5) | 2.1% | — | FreerdpOpensuse LeapFedoraproject FedoraCanonical Ubuntu Linux+1 | 22/6/2020 | 17/6/2026 | In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2.1.2. | |
| Modificada | Media (6.5) | 1.7% | — | FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+1 | 22/6/2020 | 17/6/2026 | In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enabled This is fixed in version 2.1.2. | |
| Modificada | Media (5.4) | 1.4% | 💥 PoC | FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+1 | 22/6/2020 | 17/6/2026 | In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2. |