Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
4241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.6% | — | Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+6 | 17/6/2020 | 17/6/2026 | An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode. | |
| Modificada | Alta (7.5) | 3.6% | — | Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+6 | 17/6/2020 | 17/6/2026 | libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename. | |
| Modificada | Alta (7.5) | 2.5% | — | Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+6 | 17/6/2020 | 17/6/2026 | An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function. | |
| Modificada | Media (4.8) | 1.1% | — | MuttCanonical Ubuntu Linux | 15/6/2020 | 17/6/2026 | Mutt before 1.14.3 proceeds with a connection even if, in response to a GnuTLS certificate prompt, the user rejects an expired intermediate certificate. | |
| Modificada | Media (5.5) | 0.54% | — | Intel Celeron 1000mIntel Celeron 1005mIntel Celeron 1007uIntel Celeron 1017u+690 | 15/6/2020 | 17/6/2026 | Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.9) | 2.1% | — | MuttCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 15/6/2020 | 17/6/2026 | Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response. | |
| Modificada | Media (4.4) | 0.62% | — | Linux KernelOpensuse LeapCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+15 | 12/6/2020 | 17/6/2026 | A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data. | |
| Modificada | Alta (7.5) | 4.3% | 💥 PoC | Google AndroidLibexif Project LibexifCanonical Ubuntu LinuxDebian Linux+1 | 11/6/2020 | 17/6/2026 | In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146428941 | |
| Modificada | Media (6.5) | 1.2% | — | Redhat Openstack-cinderCanonical Ubuntu Linux | 10/6/2020 | 17/6/2026 | An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before openstack-cinder 16.1.0. When using openstack-cinder with the Dell EMC ScaleIO or VxFlex OS backend… | |
| Modificada | Media (5) | 1.8% | — | QemuRedhat Enterprise LinuxOpensuse LeapCanonical Ubuntu Linux | 9/6/2020 | 17/6/2026 | An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server… | |
| Modificada | Alta (7.8) | 0.99% | 💥 PoC | Linux KernelOpensuse LeapRedhat Enterprise LinuxRedhat Enterprise MRG+6 | 9/6/2020 | 17/6/2026 | A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system. | |
| Modificada | Alta (7.8) | 0.57% | — | Linux KernelDebian LinuxCanonical Ubuntu Linux | 9/6/2020 | 17/6/2026 | An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue that the integer overflow does not lead to a security issue in this case. | |
| Modificada | Media (4.4) | 0.36% | — | Linuxtv XawtvDebian LinuxOpensuse Backports SLEOpensuse Leap+2 | 8/6/2020 | 17/6/2026 | An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the… | |
| Modificada | Alta (7.5) | 3.8% | — | Phpmailer Project PhpmailerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux | 8/6/2020 | 17/6/2026 | PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay processing the message. | |
| Modificada | Alta (7.5) | 15% | 💥 PoC | UI Unifi ControllerW1.fi HostapdAsus Rt-n11Broadcom Adsl+213 | 8/6/2020 | 17/6/2026 | The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue. | |
| Modificada | Media (5.5) | 0.57% | — | Freedesktop DbusCanonical Ubuntu Linux | 8/6/2020 | 17/6/2026 | An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make… | |
| Modificada | Media (5.5) | 1.3% | — | FfmpegCanonical Ubuntu LinuxDebian Linux | 7/6/2020 | 17/6/2026 | FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavformat/format.c. | |
| Modificada | Alta (7.5) | 1.7% | — | PAM Tacplus Project PAM TacplusDebian LinuxCanonical Ubuntu LinuxArista Cloudvision Portal | 6/6/2020 | 17/6/2026 | In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used. | |
| Modificada | Media (6) | 0.49% | — | QemuCanonical Ubuntu LinuxOpensuse Leap | 4/6/2020 | 17/6/2026 | ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm_read or ati_mm_write call. | |
| Modificada | Media (5.6) | 2.4% | — | QemuCanonical Ubuntu LinuxDebian Linux | 4/6/2020 | 17/6/2026 | rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation. | |
| Modificada | Alta (7.4) | 22% | 💥 PoC | GnutlsFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux | 4/6/2020 | 17/6/2026 | GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always… | |
| Modificada | Media (6.1) | 2.9% | — | Djangoproject DjangoFedoraproject FedoraCanonical Ubuntu LinuxNetapp SRA Plugin+3 | 3/6/2020 | 17/6/2026 | An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack. | |
| Modificada | Media (5.9) | 6.1% | 💥 PoC | Djangoproject DjangoCanonical Ubuntu LinuxFedoraproject FedoraNetapp SRA Plugin+3 | 3/6/2020 | 17/6/2026 | An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage. | |
| Modificada | Media (5.5) | 0.44% | — | Linux KernelDebian LinuxCanonical Ubuntu Linux | 3/6/2020 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue_add_kobject() in net/core/net-sysfs.c, a reference count is mishandled, aka CID-a3e23f719f5c. | |
| Modificada | Media (5.5) | 0.48% | — | Linux KernelOpensuse LeapCanonical Ubuntu Linux | 3/6/2020 | 17/6/2026 | go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586. |