Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
620 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.90% | — | Jenkins Blue Ocean | 5/10/2017 | 17/6/2026 | The optional Run/Artifacts permission can be enabled by setting a Java system property. Blue Ocean did not check this permission before providing access to archived artifacts, Item/Read permission was sufficient. | |
| Modificada | Media (6.5) | 7.8% | 💥 PoC | Bluez | 12/9/2017 | 17/6/2026 | All versions of the SDP server in BlueZ 5.46 and earlier are vulnerable to an information disclosure vulnerability which allows remote attackers to obtain sensitive information from the bluetoothd process memory. This vulnerability lies in the processing of SDP search attribute requests. | |
| Modificada | Media (5.9) | 0.49% | — | Meafinancial Blue Ridge Bank AND Trust CO. Mobile Banking | 16/6/2017 | 17/6/2026 | The "Blue Ridge Bank and Trust Co. Mobile Banking" by Blue Ridge Bank and Trust Co. app 3.0.1 -- aka blue-ridge-bank-and-trust-co-mobile-banking/id699679197 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a… | |
| Modificada | Alta (7.8) | 0.56% | — | Bluez | 9/6/2017 | 17/6/2026 | Buffer overflow in BlueZ 5.41 and earlier allows an attacker to execute arbitrary code via the parse_line function used in some userland utilities. | |
| Modificada | Alta (7.5) | 1.3% | — | Bluecoat Advanced Secure GatewayBluecoat CacheflowBluecoat Proxysg | 8/6/2017 | 17/6/2026 | Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning. | |
| Modificada | Alta (7.5) | 1.1% | — | Bavarian Motor Works Bluetooth Stack | 23/5/2017 | 17/6/2026 | The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name. | |
| Modificada | Media (5.4) | 0.68% | — | Blueriver Muracms | 27/4/2017 | 17/6/2026 | Mura CMS 7.0.6967 allows admin/?muraAction= XSS attacks, related to admin/core/views/carch/list.cfm, admin/core/views/carch/loadsiteflat.cfm, admin/core/views/cusers/inc/dsp_nextn.cfm, admin/core/views/cusers/inc/dsp_search_form.cfm, admin/core/views/cusers/inc/dsp_users_list.cfm, admin/core/views/cusers/list.cfm, and… | |
| Analizada | Alta (7.5) | 2.1% | — | Hyundai Blue Link | 26/4/2017 | 17/6/2026 | A Use of Hard-Coded Cryptographic Key issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. The application uses a hard-coded decryption password to protect sensitive user information. | |
| Analizada | Baja (3.7) | 0.60% | — | Hyundai Blue Link | 26/4/2017 | 17/6/2026 | A Man-in-the-Middle issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. Communication channel endpoints are not verified, which may allow a remote attacker to access or influence communications between the identified endpoints. | |
| Modificada | Media (5.9) | 1.5% | — | Bluecoat SSL Visibility Appliance Sv1800 FirmwareBluecoat SSL Visibility Appliance Sv800 FirmwareBluecoat SSL Visibility Appliance Sv3800 FirmwareBluecoat SSL Visibility Appliance Sv2800 Firmware | 11/4/2017 | 17/6/2026 | Symantec SSL Visibility (SSLV) 3.8.4FC, 3.9, 3.10 before 3.10.4.1, and 3.11 before 3.11.3.1 is susceptible to a denial-of-service vulnerability that impacts the SSL servers for intercepted SSL connections. A malicious SSL client can, under certain circumstances, temporarily exhaust the TCP connection pool of an SSL… | |
| Modificada | Alta (7.2) | 10% | 💥 Exploit | Bluecoat Advanced Secure GatewayBluecoat Content Analysis System Software | 5/4/2017 | 17/6/2026 | Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability. An authenticated malicious administrator can execute arbitrary OS commands with elevated system privileges. | |
| Modificada | Alta (8.4) | 0.60% | — | Bluestacks | 6/1/2017 | 17/6/2026 | A local privilege escalation vulnerability exists in BlueStacks App Player. The BlueStacks App Player installer creates a registry key with weak permissions that allows users to execute arbitrary programs with SYSTEM privileges. | |
| Modificada | Alta (7.8) | 0.47% | — | Intel Wireless Bluetooth Drivers | 8/12/2016 | 17/6/2026 | Unquoted service path vulnerability in Intel Wireless Bluetooth Drivers 16.x, 17.x, and before 18.1.1607.3129 allows local users to launch processes with elevated privileges. | |
| Modificada | Alta (7.5) | 3.8% | — | Bluez Project Bluez | 8/12/2016 | 17/6/2026 | In BlueZ 5.42, an out-of-bounds read was identified in "packet_hexdump" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash. | |
| Modificada | Alta (7.5) | 3.6% | — | Bluez | 8/12/2016 | 17/6/2026 | In BlueZ 5.42, a buffer overflow was observed in "read_n" function in "tools/hcidump.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash. | |
| Modificada | Media (5.3) | 2.5% | — | Bluez | 3/12/2016 | 17/6/2026 | In BlueZ 5.42, a buffer overflow was observed in "commands_dump" function in "tools/parser/csr.c" source file. The issue exists because "commands" array is overflowed by supplied parameter due to lack of boundary checks on size of the buffer from frame "frm->ptr" parameter. This issue can be triggered by processing a… | |
| Modificada | Media (5.3) | 2.7% | — | Bluez | 3/12/2016 | 17/6/2026 | In BlueZ 5.42, an out-of-bounds read was observed in "le_meta_ev_dump" function in "tools/parser/hci.c" source file. This issue exists because 'subevent' (which is used to read correct element from 'ev_le_meta_str' array) is overflowed. | |
| Modificada | Media (5.3) | 3.6% | — | Bluez | 3/12/2016 | 17/6/2026 | In BlueZ 5.42, a buffer over-read was identified in "l2cap_packet" function in "monitor/packet.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash. | |
| Modificada | Media (5.3) | 3.0% | — | Bluez | 3/12/2016 | 17/6/2026 | In BlueZ 5.42, a buffer overflow was observed in "set_ext_ctrl" function in "tools/parser/l2cap.c" source file when processing corrupted dump file. | |
| Modificada | Media (5.3) | 2.9% | — | Bluez | 3/12/2016 | 17/6/2026 | In BlueZ 5.42, a buffer overflow was observed in "pin_code_reply_dump" function in "tools/parser/hci.c" source file. The issue exists because "pin" array is overflowed by supplied parameter due to lack of boundary checks on size of the buffer from frame "pin_code_reply_cp *cp" parameter. | |
| Modificada | Media (5.3) | 2.0% | — | Bluez | 3/12/2016 | 17/6/2026 | In BlueZ 5.42, a buffer overflow was observed in "pklg_read_hci" function in "btsnoop.c" source file. This issue can be triggered by processing a corrupted dump file and will result in btmon crash. | |
| Modificada | Media (5.3) | 3.8% | — | Bluez | 3/12/2016 | 17/6/2026 | In BlueZ 5.42, a use-after-free was identified in "conf_opt" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash. | |
| Modificada | Media (5.3) | 3.7% | — | Bluez | 3/12/2016 | 17/6/2026 | In BlueZ 5.42, a buffer over-read was observed in "l2cap_dump" function in "tools/parser/l2cap.c" source file. This issue can be triggered by processing a corrupted dump file and will result in hcidump crash. | |
| Modificada | Alta (8.1) | 1.1% | — | Blue Coat Packetshaper S-series | 12/7/2016 | 17/6/2026 | The HTTPS server in Blue Coat PacketShaper S-Series 11.5.x before 11.5.3.2 might allow remote attackers to obtain sensitive credentials and other information via unspecified vectors, related to use of insecure cryptographic parameters. | |
| Modificada | Media (6.5) | 0.78% | — | IBM Bluemix | 17/5/2016 | 17/6/2026 | The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors. |