Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

3303 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.9%—Coturn Project CoturnDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+129/6/202017/6/2026
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from…
ModificadaAlta (7.8)0.50%—Opensuse LeapOpensuse Tumbleweed Kopano-spamd29/6/202017/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of kopano-spamd of openSUSE Leap 15.1, openSUSE Tumbleweed allowed local attackers with the privileges of the kopano user to escalate to root. This issue affects: openSUSE Leap 15.1 kopano-spamd versions prior to 10.0.5-lp151.4.1. openSUSE…
ModificadaCrítica (9.8)1.4%—Opensuse OSC29/6/202017/6/2026
A External Control of File Name or Path vulnerability in osc of SUSE Linux Enterprise Module for Development Tools 15, SUSE Linux Enterprise Software Development Kit 12-SP5, SUSE Linux Enterprise Software Development Kit 12-SP4; openSUSE Leap 15.1, openSUSE Factory allowed remote attackers that can change downloaded…
ModificadaAlta (7.8)0.86%—Apache TomcatOpensuse Leap29/6/202017/6/2026
A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux…
ModificadaMedia (5.3)0.54%—Opensuse Hylafax+29/6/202017/6/2026
A Incorrect Default Permissions vulnerability in the packaging of hylafax+ of openSUSE Leap 15.2, openSUSE Leap 15.1, openSUSE Factory allows local attackers to escalate from user uucp to users calling hylafax binaries. This issue affects: openSUSE Leap 15.2 hylafax+ versions prior to 7.0.2-lp152.2.1. openSUSE Leap…
ModificadaAlta (7.5)27%💥 PoCApache TomcatCanonical Ubuntu LinuxOracle Mysql Enterprise MonitorOracle Siebel UI Framework+426/6/202017/6/2026
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
ModificadaMedia (5.5)0.51%—Redhat Enterprise LinuxOpensuse Leap26/6/202017/6/2026
A buffer over-read flaw was found in RH kernel versions before 5.0 in crypto_authenc_extractkeys in crypto/authenc.c in the IPsec Cryptographic algorithm's module, authenc. When a payload longer than 4 bytes, and is not following 4-byte alignment boundary guidelines, it causes a buffer over-read threat, leading to a…
ModificadaMedia (6.5)1.6%—Redhat Ceph StorageRedhat OpenstackFedoraproject FedoraOpensuse Leap+226/6/202017/6/2026
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made.…
ModificadaMedia (5.5)0.46%—OpenexrFedoraproject FedoraOpensuse LeapDebian Linux+126/6/202017/6/2026
An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
ModificadaMedia (5.5)0.42%—OpenexrFedoraproject FedoraOpensuse LeapDebian Linux+126/6/202017/6/2026
An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp.
ModificadaMedia (5.5)0.40%—OpenexrFedoraproject FedoraOpensuse Leap26/6/202017/6/2026
An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.
ModificadaMedia (4.9)3.4%—NTPOpensuse LeapNetapp Cloud BackupNetapp Steelstore Cloud Integrated Storage+1224/6/202017/6/2026
ntpd in ntp 4.2.8 before 4.2.8p15 and 4.3.x before 4.3.101 allows remote attackers to cause a denial of service (memory consumption) by sending packets, because memory is not freed in situations where a CMAC key is used and associated with a CMAC algorithm in the ntp.keys file.
ModificadaMedia (5.7)1.0%—Sane-project Sane BackendsCanonical Ubuntu LinuxOpensuse Leap24/6/202017/6/2026
A NULL pointer dereference in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, GHSL-2020-079.
ModificadaAlta (8)1.5%—Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap24/6/202017/6/2026
A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.
ModificadaMedia (4.3)1.2%—Sane-project Sane BackendsOpensuse LeapCanonical Ubuntu Linux24/6/202017/6/2026
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-081.
ModificadaMedia (4.3)1.0%—Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap24/6/202017/6/2026
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-083.
ModificadaMedia (4.3)1.1%—Sane-project Sane BackendsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap24/6/202017/6/2026
An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-082.
ModificadaAlta (8.8)3.0%—Sane-project Sane BackendsCanonical Ubuntu LinuxOpensuse Leap24/6/202017/6/2026
A heap buffer overflow in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-080.
ModificadaMedia (6.5)1.8%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.
ModificadaMedia (4.3)1.8%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2.
ModificadaAlta (7.5)1.8%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2.
ModificadaMedia (6.5)1.8%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
ModificadaMedia (6.5)2.1%—FreerdpOpensuse LeapFedoraproject FedoraCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2.1.2.
ModificadaMedia (6.5)1.7%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enabled This is fixed in version 2.1.2.
ModificadaMedia (5.4)1.4%💥 PoCFreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.