Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

3303 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.8%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one can disable bitmap cache with -bitmap-cache (default). This is fixed in version 2.1.2.
ModificadaMedia (5.4)1.5%—FreerdpFedoraproject FedoraOpensuse LeapCanonical Ubuntu Linux+122/6/202017/6/2026
In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.
ModificadaCrítica (9.8)2.7%—Chocolate-doom Chocolate DoomChocolate-doom Crispy DoomOpensuse BackportsOpensuse Leap22/6/202017/6/2026
The server in Chocolate Doom 3.0.0 and Crispy Doom 5.8.0 doesn't validate the user-controlled num_players value, leading to a buffer overflow. A malicious user can overwrite the server's stack.
ModificadaCrítica (9.3)0.35%—Google Guest-osloginOpensuse Leap22/6/202017/6/2026
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using the membership to the "lxd" group, an attacker can attach host devices and filesystems. Within an lxc container, it…
ModificadaCrítica (9.3)0.31%—Google Guest-osloginOpensuse Leap22/6/202017/6/2026
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "docker" group, an attacker with this role is able to run docker and mount the host OS.…
ModificadaAlta (7.3)0.32%—Google Guest-osloginOpensuse Leap22/6/202017/6/2026
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, users with this role are able to read the DHCP XID from the systemd journal.…
ModificadaMedia (5.9)2.3%—MuttDebian LinuxNeomuttFedoraproject Fedora+221/6/202017/6/2026
Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-middle attacker) and evaluates it in a TLS context, aka "response injection."
ModificadaCrítica (9.8)46%💥 PoCRubyonrails RailsDebian LinuxOpensuse Leap19/6/202017/6/2026
A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in an RCE.
ModificadaAlta (7.5)4.9%—Rubyonrails RailsDebian LinuxOpensuse Backports SLEOpensuse Leap19/6/202017/6/2026
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters.
ModificadaCrítica (9.8)2.4%—GNU AdnsOpensuse LeapFedoraproject Fedora18/6/202017/6/2026
An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.
ModificadaCrítica (9.8)2.3%—GNU AdnsOpensuse LeapFedoraproject Fedora18/6/202017/6/2026
An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the first label length. Depending on the circumstances, an attacker might be able to trick adns into crashing the calling program, leaking aspects…
ModificadaMedia (5.9)13%—PythonOpensuse LeapFedoraproject FedoraOracle Enterprise Manager OPS Center18/6/202017/6/2026
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker…
ModificadaCrítica (9.8)2.0%—GNU AdnsOpensuse LeapFedoraproject Fedora18/6/202017/6/2026
An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan finds the same RRs at the first. Otherwise, adns can be confused by interleaving answers for the CNAME target, with the CNAME itself. In that…
ModificadaAlta (7.5)2.1%—GNU AdnsOpensuse LeapFedoraproject Fedora18/6/202017/6/2026
An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong to increment used as well as setting r, since used is incremented according to r, later. Rather one should be doing what read() would have done. Without this fix, adnshost may read and process one…
ModificadaMedia (4.2)0.31%—Linux KernelOpensuse Leap18/6/202017/6/2026
In the Linux kernel before 5.4.16, a race condition in tty->disc_data handling in the slip and slcan line discipline could lead to a use-after-free, aka CID-0ace17d56824. This affects drivers/net/slip/slip.c and drivers/net/can/slcan.c.
ModificadaMedia (4.9)2.1%—ISC BindFedoraproject FedoraOpensuse LeapDebian Linux+217/6/20201/9/2026
In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*")…
ModificadaMedia (4.9)1.8%—ISC BindOpensuse LeapNetapp Steelstore Cloud Integrated StorageCanonical Ubuntu Linux17/6/202017/6/2026
An attacker who is permitted to send zone data to a server via zone transfer can exploit this to intentionally trigger the assertion failure with a specially constructed zone, denying service to clients.
ModificadaMedia (6.5)2.5%—Libvncserver Project LibvncserverDebian LinuxOpensuse LeapSiemens Simatic Itc1500 Firmware+517/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/scale.c has a pixel_value integer overflow.
ModificadaAlta (7.5)2.8%—Libvncserver Project LibvncserverDebian LinuxOpensuse LeapCanonical Ubuntu Linux17/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint16_t pointers in libvncserver/translate.c. NOTE: Third parties do not consider this to be a vulnerability as there is no known path of exploitation or cross of a trust boundary
ModificadaAlta (7.5)2.8%—Libvncserver Project LibvncserverDebian LinuxOpensuse LeapCanonical Ubuntu Linux17/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. Byte-aligned data is accessed through uint32_t pointers in libvncclient/rfbproto.c. NOTE: there is reportedly "no trust boundary crossed.
ModificadaAlta (7.5)2.8%—Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+617/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. An improperly closed TCP connection causes an infinite loop in libvncclient/sockets.c.
ModificadaAlta (7.5)3.4%—Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+617/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.
ModificadaAlta (7.5)2.6%—Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+617/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. libvncserver/ws_decode.c can lead to a crash because of unaligned accesses in hybiReadAndDecode.
ModificadaAlta (7.5)3.6%—Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+617/6/202017/6/2026
libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
ModificadaAlta (7.5)2.5%—Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+617/6/202017/6/2026
An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.
Orbitaley — Vulnerabilidades