Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
494 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.2% | — | Radare2 | 27/10/2017 | 17/6/2026 | In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems. | |
| Modificada | Alta (7.8) | 1.1% | — | Radare2 | 16/10/2017 | 17/6/2026 | The store_versioninfo_gnu_verdef function in libr/bin/format/elf/elf.c in radare2 2.0.0 allows remote attackers to cause a denial of service (r_read_le16 invalid write and application crash) or possibly have unspecified other impact via a crafted ELF file. | |
| Modificada | Alta (7.8) | 1.3% | — | Radare2 | 16/10/2017 | 17/6/2026 | The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted WASM file that triggers an incorrect r_hex_bin2str call. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM Qradar Security Information AND Event Manager | 12/9/2017 | 17/6/2026 | IBM QRadar 7.2 and 7.3 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM X-Force ID: 122957. | |
| Modificada | Alta (7.5) | 1.3% | — | IBM Qradar Network Security | 5/9/2017 | 17/6/2026 | IBM QRadar Network Security 5.4 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 128689. | |
| Modificada | Alta (8.1) | 2.5% | — | IBM Qradar Network Security | 5/9/2017 | 17/6/2026 | IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 128377. | |
| Modificada | Media (6.1) | 1.3% | — | IBM Qradar Network Security | 5/9/2017 | 17/6/2026 | IBM QRadar Network Security 5.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 128376. | |
| Modificada | Alta (7.8) | 1.9% | — | Radare2 | 5/7/2017 | 17/6/2026 | The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a read overflow in the grub_disk_read_small_real function… | |
| Modificada | Media (5.4) | 0.73% | — | IBM Qradar Security Information AND Event Manager | 27/6/2017 | 17/6/2026 | IBM QRadar 7.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 123913. | |
| Modificada | Media (5.9) | 1.5% | — | IBM Qradar Security Information AND Event Manager | 27/6/2017 | 17/6/2026 | IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 120208. | |
| Modificada | Alta (7.5) | 1.6% | — | IBM Qradar Security Information AND Event Manager | 27/6/2017 | 17/6/2026 | IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 119783. | |
| Modificada | Alta (7.8) | 1.8% | — | Radare2 | 26/6/2017 | 17/6/2026 | The grub_memmove function in shlr/grub/kern/misc.c in radare2 1.5.0 allows remote attackers to cause a denial of service (stack-based buffer underflow and application crash) or possibly have unspecified other impact via a crafted binary file, possibly related to a buffer underflow in fs/ext2.c in GNU GRUB 2.02. | |
| Modificada | Alta (7.5) | 4.1% | — | Radare2 | 19/6/2017 | 17/6/2026 | The grub_ext2_read_block function in fs/ext2.c in GNU GRUB before 2013-11-12, as used in shlr/grub/fs/ext2.c in radare2 1.5.0, allows remote attackers to cause a denial of service (excessive stack use and application crash) via a crafted binary file, related to use of a variable-size stack array. | |
| Modificada | Media (5.5) | 1.0% | — | Radare2 | 19/6/2017 | 17/6/2026 | The cmd_info function in libr/core/cmd_info.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted binary file. | |
| Modificada | Media (5.5) | 1.4% | — | Radare2 | 19/6/2017 | 17/6/2026 | The find_eoq function in libr/core/cmd.c in radare2 1.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted binary file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 8/6/2017 | 17/6/2026 | The r_config_set function in libr/config/config.c in radare2 1.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted DEX file. | |
| Modificada | Media (6.5) | 0.82% | — | IBM Qradar Security Information AND Event Manager | 15/5/2017 | 17/6/2026 | IBM QRadar 7.2 and 7.3 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 120207. | |
| Modificada | Media (5.5) | 0.88% | — | Radare2 | 18/4/2017 | 17/6/2026 | The get_relocs_64 function in libr/bin/format/mach0/mach0.c in radare2 1.3.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted Mach0 file. | |
| Modificada | Media (5.5) | 1.1% | — | Radare2 | 13/4/2017 | 17/6/2026 | The consume_init_expr function in wasm.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file. | |
| Modificada | Media (5.5) | 0.73% | — | Radare2 | 12/4/2017 | 17/6/2026 | The read_u32_leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file. | |
| Modificada | Alta (7.8) | 1.8% | — | Radare2 | 3/4/2017 | 17/6/2026 | The dalvik_disassemble function in libr/asm/p/asm_dalvik.c in radare2 1.2.1 allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted DEX file. | |
| Modificada | Alta (7.8) | 1.9% | — | Radare2 | 3/4/2017 | 17/6/2026 | The relocs function in libr/bin/p/bin_bflt.c in radare2 1.2.1 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted binary file. | |
| Modificada | Media (5.5) | 1.6% | — | Radare2 | 27/3/2017 | 17/6/2026 | The r_pkcs7_parse_cms function in libr/util/r_pkcs7.c in radare2 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PE file. | |
| Modificada | Media (5.4) | 0.52% | — | IBM Qradar Incident ForensicsIBM Qradar Security Information AND Event Manager | 7/3/2017 | 17/6/2026 | IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Reference #: 1999534. | |
| Modificada | Alta (7.5) | 1.4% | — | IBM Qradar Security Information AND Event Manager | 7/3/2017 | 17/6/2026 | IBM QRadar 7.2 could allow a remote attacker to consume all resources on the server due to not properly restricting the size or amount of resources requested by an actor. IBM Reference #: 1999556. |