Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
623 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.7) | 1.7% | — | Oracle JDKOracle JREOracle JrockitRedhat Satellite+9 | 24/4/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access… | |
| Modificada | Baja (3.1) | 2.0% | — | Oracle JDKOracle JRERedhat SatelliteDebian Linux+7 | 24/4/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Baja (3.7) | 3.0% | — | Oracle JDKOracle JREOracle JrockitRedhat Satellite+8 | 24/4/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access… | |
| Modificada | Media (4.3) | 2.1% | — | Oracle MysqlDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+5 | 24/4/2017 | 17/6/2026 | Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise… | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Media (5.5) | 1.5% | — | Icoutils Project IcoutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 16/2/2017 | 17/6/2026 | An issue was discovered in icoutils 0.31.1. An out-of-bounds read leading to a buffer overflow was observed in the "simple_vec" function in the "extract.c" source file. This affects icotool. | |
| Modificada | Media (5.5) | 1.5% | — | Icoutils Project IcoutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 16/2/2017 | 17/6/2026 | An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "extract_icons" function in the "extract.c" source file. This issue can be triggered by processing a corrupted ico file and will result in an icotool crash. | |
| Modificada | Media (5.5) | 1.5% | — | Icoutils Project IcoutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 16/2/2017 | 17/6/2026 | An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. This is happening because the "len" parameter for memcpy is not checked for size and thus becomes a negative integer in the process, resulting in a failed memcpy. This… | |
| Modificada | Alta (7.5) | 4.9% | — | Oracle MysqlMariadbDebian LinuxRedhat Enterprise Linux Desktop+4 | 12/2/2017 | 17/6/2026 | Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through 5.5.54, 10.0.x through 10.0.29, 10.1.x through 10.1.21, and 10.2.x through 10.2.3. | |
| Modificada | Alta (7.1) | 2.8% | — | Littlecms Little CMS Color EngineCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+15 | 3/2/2017 | 17/6/2026 | The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read. | |
| Modificada | Media (5.3) | 15% | — | NTPDebian LinuxNetapp Clustered Data OntapNetapp Data Ontap+13 | 30/1/2017 | 17/6/2026 | The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value. | |
| Modificada | Crítica (9.8) | 3.6% | — | TcpdumpDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 28/1/2017 | 17/6/2026 | The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print(). | |
| Modificada | Crítica (9.8) | 6.0% | — | TcpdumpDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 28/1/2017 | 17/6/2026 | The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print(). | |
| Modificada | Crítica (9.8) | 3.8% | — | TcpdumpDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 28/1/2017 | 17/6/2026 | The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print(). | |
| Modificada | Crítica (9.8) | 3.8% | — | TcpdumpDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 28/1/2017 | 17/6/2026 | The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print(). | |
| Modificada | Media (5.5) | 2.2% | — | Libical Project LibicalCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 27/1/2017 | 17/6/2026 | libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file. | |
| Modificada | Media (5.5) | 0.43% | — | GNU BashDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 23/1/2017 | 17/6/2026 | popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address. | |
| Modificada | Alta (7.5) | 12% | — | NTPCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+5 | 13/1/2017 | 17/6/2026 | NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address. | |
| Modificada | Media (5.5) | 1.6% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+5 | 21/9/2016 | 17/6/2026 | libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file. | |
| Modificada | Media (6.5) | 4.1% | — | LibarchiveRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+6 | 21/9/2016 | 17/6/2026 | Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file. | |
| Modificada | Alta (7.5) | 4.7% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+6 | 21/9/2016 | 17/6/2026 | The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file. | |
| Modificada | Alta (7.5) | 4.8% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+5 | 21/9/2016 | 17/6/2026 | The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink. | |
| Modificada | Alta (7.8) | 4.8% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+4 | 21/9/2016 | 17/6/2026 | Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary. | |
| Modificada | Alta (7.8) | 4.9% | — | LibarchiveRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+4 | 21/9/2016 | 17/6/2026 | Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow. | |
| Modificada | Crítica (9.8) | 68% | 💥 Exploit | Oracle MysqlPercona ServerMariadbDebian Linux+8 | 20/9/2016 | 17/6/2026 | Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain… |