Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

623 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.7)1.7%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+924/4/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access…
ModificadaBaja (3.1)2.0%—Oracle JDKOracle JRERedhat SatelliteDebian Linux+724/4/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaBaja (3.7)3.0%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+824/4/201717/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u141, 7u131 and 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access…
ModificadaMedia (4.3)2.1%—Oracle MysqlDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+524/4/201717/6/2026
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL). Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise…
ModificadaCrítica (9.8)90%💥 ExploitApache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+7517/4/201717/6/2026
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
ModificadaMedia (5.5)1.5%—Icoutils Project IcoutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+416/2/201717/6/2026
An issue was discovered in icoutils 0.31.1. An out-of-bounds read leading to a buffer overflow was observed in the "simple_vec" function in the "extract.c" source file. This affects icotool.
ModificadaMedia (5.5)1.5%—Icoutils Project IcoutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+416/2/201717/6/2026
An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "extract_icons" function in the "extract.c" source file. This issue can be triggered by processing a corrupted ico file and will result in an icotool crash.
ModificadaMedia (5.5)1.5%—Icoutils Project IcoutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+416/2/201717/6/2026
An issue was discovered in icoutils 0.31.1. A buffer overflow was observed in the "decode_ne_resource_id" function in the "restable.c" source file. This is happening because the "len" parameter for memcpy is not checked for size and thus becomes a negative integer in the process, resulting in a failed memcpy. This…
ModificadaAlta (7.5)4.9%—Oracle MysqlMariadbDebian LinuxRedhat Enterprise Linux Desktop+412/2/201717/6/2026
Crash in libmysqlclient.so in Oracle MySQL before 5.6.21 and 5.7.x before 5.7.5 and MariaDB through 5.5.54, 10.0.x through 10.0.29, 10.1.x through 10.1.21, and 10.2.x through 10.2.3.
ModificadaAlta (7.1)2.8%—Littlecms Little CMS Color EngineCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+153/2/201717/6/2026
The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.
ModificadaMedia (5.3)15%—NTPDebian LinuxNetapp Clustered Data OntapNetapp Data Ontap+1330/1/201717/6/2026
The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value.
ModificadaCrítica (9.8)3.6%—TcpdumpDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+428/1/201717/6/2026
The ISAKMP parser in tcpdump before 4.9.0 has a buffer overflow in print-isakmp.c:ikev2_e_print().
ModificadaCrítica (9.8)6.0%—TcpdumpDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+428/1/201717/6/2026
The IPv6 parser in tcpdump before 4.9.0 has a buffer overflow in print-ip6.c:ip6_print().
ModificadaCrítica (9.8)3.8%—TcpdumpDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+428/1/201717/6/2026
The BOOTP parser in tcpdump before 4.9.0 has a buffer overflow in print-bootp.c:bootp_print().
ModificadaCrítica (9.8)3.8%—TcpdumpDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+428/1/201717/6/2026
The ISO CLNS parser in tcpdump before 4.9.0 has a buffer overflow in print-isoclns.c:clnp_print().
ModificadaMedia (5.5)2.2%—Libical Project LibicalCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+427/1/201717/6/2026
libical 1.0 allows remote attackers to cause a denial of service (use-after-free) via a crafted ics file.
ModificadaMedia (5.5)0.43%—GNU BashDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+423/1/201717/6/2026
popd in bash might allow local users to bypass the restricted shell and cause a use-after-free via a crafted address.
ModificadaAlta (7.5)12%—NTPCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+513/1/201717/6/2026
NTP before 4.2.8p9 rate limits responses received from the configured sources when rate limiting for all associations is enabled, which allows remote attackers to cause a denial of service (prevent responses from the sources) by sending responses with a spoofed source address.
ModificadaMedia (5.5)1.6%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+521/9/201617/6/2026
libarchive before 3.2.0 does not limit the number of recursive decompressions, which allows remote attackers to cause a denial of service (memory consumption and application crash) via a crafted gzip file.
ModificadaMedia (6.5)4.1%—LibarchiveRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+621/9/201617/6/2026
Integer overflow in the ISO parser in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a crafted ISO file.
ModificadaAlta (7.5)4.7%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+621/9/201617/6/2026
The sandboxing code in libarchive 3.2.0 and earlier mishandles hardlink archive entries of non-zero data size, which might allow remote attackers to write to arbitrary files via a crafted archive file.
ModificadaAlta (7.5)4.8%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+521/9/201617/6/2026
The archive_read_format_cpio_read_header function in archive_read_support_format_cpio.c in libarchive before 3.2.1 allows remote attackers to cause a denial of service (application crash) via a CPIO archive with a large symlink.
ModificadaAlta (7.8)4.8%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+421/9/201617/6/2026
Heap-based buffer overflow in the parse_codes function in archive_read_support_format_rar.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a RAR file with a zero-sized dictionary.
ModificadaAlta (7.8)4.9%—LibarchiveRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+421/9/201617/6/2026
Integer overflow in the read_SubStreamsInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a 7zip file with a large number of substreams, which triggers a heap-based buffer overflow.
ModificadaCrítica (9.8)68%💥 ExploitOracle MysqlPercona ServerMariadbDebian Linux+820/9/201617/6/2026
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.27, and 10.1.x before 10.1.17; and Percona Server before 5.5.51-38.1, 5.6.x before 5.6.32-78.0, and 5.7.x before 5.7.14-7 allow local users to create arbitrary configurations and bypass certain…