Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
4241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.5% | — | Websocket-extensions Project Websocket-extensionsDebian LinuxCanonical Ubuntu Linux | 2/6/2020 | 17/6/2026 | websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be… | |
| Modificada | Media (6.7) | 0.42% | — | QemuCanonical Ubuntu LinuxDebian Linux | 2/6/2020 | 17/6/2026 | hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation. | |
| Modificada | Baja (2.5) | 0.43% | — | QemuDebian LinuxOpensuse LeapCanonical Ubuntu Linux | 2/6/2020 | 17/6/2026 | address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer. | |
| Modificada | Alta (7.5) | 1.4% | — | Python-rsa Project Python-rsaFedoraproject FedoraCanonical Ubuntu Linux | 1/6/2020 | 17/6/2026 | Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory… | |
| Modificada | Media (5.5) | 0.50% | — | Sane-project Sane BackendsFedoraproject FedoraDebian LinuxOpensuse Leap+1 | 1/6/2020 | 17/6/2026 | A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075. | |
| Modificada | Baja (3.2) | 0.38% | — | QemuDebian LinuxOpensuse LeapCanonical Ubuntu Linux | 28/5/2020 | 17/6/2026 | In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user. | |
| Modificada | Baja (3.9) | 0.37% | — | QemuDebian LinuxOpensuse LeapCanonical Ubuntu Linux | 28/5/2020 | 17/6/2026 | In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation. | |
| Modificada | Media (5.3) | 0.49% | — | VIMDebian LinuxOpensuse LeapCanonical Ubuntu Linux+3 | 28/5/2020 | 17/6/2026 | In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua). | |
| Modificada | Media (6.5) | 2.0% | — | Gnome BalsaGnome Glib-networkingCanonical Ubuntu LinuxFedoraproject Fedora+2 | 28/5/2020 | 17/6/2026 | In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications… | |
| Modificada | Alta (7.8) | 0.50% | — | SympaFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux | 27/5/2020 | 17/6/2026 | Sympa before 6.2.56 allows privilege escalation. | |
| Modificada | Media (5.5) | 0.57% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+8 | 27/5/2020 | 17/6/2026 | ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query. | |
| Modificada | Media (5.5) | 0.62% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+14 | 27/5/2020 | 17/6/2026 | SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c. | |
| Modificada | Alta (7) | 1.0% | — | SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+15 | 27/5/2020 | 17/6/2026 | ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature. | |
| Modificada | Media (5.5) | 0.43% | — | QemuCanonical Ubuntu LinuxDebian Linux | 27/5/2020 | 17/6/2026 | sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process. | |
| Modificada | Crítica (9.8) | 5.8% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux+2 | 26/5/2020 | 17/6/2026 | A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0. | |
| Modificada | Media (5.5) | 0.35% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux | 26/5/2020 | 17/6/2026 | The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects… | |
| Modificada | Crítica (9.8) | 2.5% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux | 26/5/2020 | 17/6/2026 | Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8,… | |
| Modificada | Media (5.5) | 0.43% | — | NetqmailDebian LinuxCanonical Ubuntu Linux | 26/5/2020 | 17/6/2026 | qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its… | |
| Modificada | Alta (7.5) | 1.8% | — | NetqmailDebian LinuxCanonical Ubuntu Linux | 26/5/2020 | 17/6/2026 | qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability. | |
| Modificada | Media (5.5) | 1.0% | — | SqliteDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+11 | 24/5/2020 | 17/6/2026 | SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c. | |
| Modificada | Media (4.3) | 0.61% | — | Mozilla ThunderbirdCanonical Ubuntu Linux | 22/5/2020 | 17/6/2026 | By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0. | |
| Modificada | Alta (8.3) | 2.3% | 💥 PoC | FreerdpCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 22/5/2020 | 17/6/2026 | An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c. | |
| Modificada | Media (5.5) | 0.54% | — | FreerdpCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 22/5/2020 | 17/6/2026 | An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value. | |
| Modificada | Alta (7.1) | 2.3% | — | FreerdpCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 22/5/2020 | 17/6/2026 | An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. | |
| Modificada | Media (5.9) | 3.1% | — | Linux KernelRedhat 3scaleRedhat OpenstackRedhat Virtualization Host+7 | 22/5/2020 | 17/6/2026 | A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO… |