Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
707 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.0% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp AFF Baseboard Management ControllerNetapp Cloud Backup+11 | 18/11/2019 | 17/6/2026 | Two memory leaks in the v3d_submit_cl_ioctl() function in drivers/gpu/drm/v3d/v3d_gem.c in the Linux kernel before 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering kcalloc() or v3d_job_init() failures, aka CID-29cd13cfd762. | |
| Modificada | Media (5.5) | 0.21% | — | Broadcom Brocade Sannav | 8/11/2019 | 17/6/2026 | Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save. | |
| Modificada | Alta (7.4) | 0.74% | — | Broadcom Brocade Sannav | 8/11/2019 | 17/6/2026 | A vulnerability, in The ReportsTrustManager class of Brocade SANnav versions before v2.0, could allow an attacker to perform a man-in-the-middle attack against Secure Sockets Layer(SSL)connections. | |
| Modificada | Alta (7.5) | 0.40% | — | Broadcom Brocade Sannav | 8/11/2019 | 17/6/2026 | Password-based encryption (PBE) algorithm, of Brocade SANnav versions before v2.0, has a weakness in generating cryptographic keys that may allow an attacker to decrypt passwords used with several services (Radius, TACAS, etc.). | |
| Modificada | Alta (7.8) | 0.25% | — | Broadcom Brocade Sannav | 8/11/2019 | 17/6/2026 | Brocade SANnav versions before v2.0 use a hard-coded password, which could allow local authenticated attackers to access a back-end database and gain privileges. | |
| Modificada | Media (5.5) | 0.20% | — | Broadcom Brocade Sannav | 8/11/2019 | 17/6/2026 | The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level; which could allow a local authenticated attacker to access sensitive information. | |
| Modificada | Alta (8.8) | 1.3% | — | Broadcom Brocade Sannav | 8/11/2019 | 17/6/2026 | A vulnerability, in Brocade SANnav versions before v2.0, could allow remote attackers to brute-force a valid session ID. The vulnerability is due to an insufficiently random session ID for several post-authentication actions in the SANnav portal. | |
| Modificada | Crítica (9.8) | 3.4% | — | Linux KernelOpensuse LeapRedhat Enterprise LinuxNetapp Active IQ Unified Manager+13 | 7/11/2019 | 17/6/2026 | An issue was discovered in net/ipv4/sysctl_net_ipv4.c in the Linux kernel before 5.0.11. There is a net/ipv4/tcp_input.c signed integer overflow in tcp_ack_update_rtt() when userspace writes a very large integer to /proc/sys/net/ipv4/tcp_min_rtt_wlen, leading to a denial of service or possibly unspecified other… | |
| Modificada | Alta (7) | 0.99% | 💥 PoC | Linux KernelCanonical Ubuntu LinuxOpensuse LeapNetapp Active IQ Unified Manager+14 | 4/11/2019 | 17/6/2026 | An issue was discovered in drivers/media/platform/vivid in the Linux kernel through 5.3.8. It is exploitable for privilege escalation on some Linux distributions where local users have /dev/video0 access, but only if the driver happens to be loaded. There are multiple race conditions during streaming stopping in this… | |
| Modificada | Alta (8.8) | 2.5% | — | Broadcom CA Performance ManagementBroadcom Network Operations | 17/10/2019 | 17/6/2026 | CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security. | |
| Modificada | Alta (8.6) | 0.89% | — | Broadcom Reactor Netty | 17/10/2019 | 4/9/2026 | Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious user may gain access to credentials for a different server than they have access to. | |
| Modificada | Crítica (9.8) | 3.4% | — | Broadcom Network Flow Analysis | 2/10/2019 | 17/6/2026 | CA Network Flow Analysis 9.x and 10.0.x have a default credential vulnerability that can allow a remote attacker to execute arbitrary commands and compromise system security. | |
| Modificada | Crítica (9.8) | 5.8% | — | Broadcom CA Client AutomationBroadcom CA Workload Automation AE | 6/9/2019 | 17/6/2026 | An access vulnerability in CA Common Services DIA of CA Technologies Client Automation 14 and Workload Automation AE 11.3.5, 11.3.6 allows a remote attacker to execute arbitrary code. | |
| Modificada | Media (6.5) | 0.59% | — | Broadcom Advanced Secure GatewayBroadcom Symantec Proxysg | 30/8/2019 | 17/6/2026 | The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. An information disclosure vulnerability in the WebFTP mode allows a malicious user to obtain plaintext authentication credentials for a remote FTP server from the… | |
| Modificada | Media (6.1) | 0.77% | — | Broadcom Advanced Secure GatewayBroadcom Symantec Proxysg | 30/8/2019 | 17/6/2026 | The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. A stored cross-site scripting (XSS) vulnerability in the WebFTP mode allows a remote attacker to inject malicious JavaScript code in ASG/ProxySG's web listing of a remote FTP… | |
| Modificada | Alta (8.8) | 1.0% | — | Broadcom Bcm4335c0 FirmwareBroadcom Bcm43438a1 FirmwareCypress Cyw20702a1kwfbg FirmwareCypress Cyw20702a1kwfbgt Firmware+59 | 7/6/2019 | 17/6/2026 | Broadcom firmware before summer 2014 on Nexus 5 BCM4335C0 2012-12-11, Raspberry Pi 3 BCM43438A1 2014-06-02, and unspecifed other devices does not properly restrict LMP commnds and executes certain memory contents upon receiving an LMP command, as demonstrated by executing an HCI command. | |
| Modificada | Crítica (9.1) | 1.7% | — | Broadcom Privileged Access Manager | 26/2/2019 | 17/6/2026 | An improper authentication vulnerability in CA Privileged Access Manager 3.x Web-UI jk-manager and jk-status allows a remote attacker to gain sensitive information or alter configuration. | |
| Modificada | Alta (7.8) | 1.1% | — | Broadcom TcpreplayFedoraproject Fedora | 17/2/2019 | 17/6/2026 | An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact. | |
| Modificada | Alta (7.8) | 1.3% | — | Broadcom TcpreplayFedoraproject Fedora | 17/2/2019 | 17/6/2026 | An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified… | |
| Modificada | Alta (7.8) | 1.3% | — | Broadcom TcpreplayFedoraproject Fedora | 17/2/2019 | 17/6/2026 | An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other… | |
| Modificada | Media (6.1) | 2.0% | — | Broadcom Automic Workload Automation | 6/2/2019 | 17/6/2026 | Insufficient output sanitization in the Automic Web Interface (AWI), in CA Automic Workload Automation 12.0 to 12.2, allow attackers to potentially conduct persistent cross site scripting (XSS) attacks via a crafted object. | |
| Modificada | Crítica (9.8) | 1.2% | — | Broadcom Service Desk ManagerCA Service Desk Manager | 22/1/2019 | 17/6/2026 | CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to escalate privileges in the user interface. | |
| Modificada | Alta (7.5) | 1.3% | — | Broadcom Service Desk ManagerCA Service Desk Manager | 22/1/2019 | 17/6/2026 | CA Service Desk Manager 14.1 and 17 contain a vulnerability that can allow a malicious actor to access survey information. | |
| Modificada | Crítica (9.8) | 3.0% | — | Broadcom Spring Batch | 18/1/2019 | 1/9/2026 | Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. | |
| Modificada | Crítica (9.8) | 4.1% | — | Broadcom Spring WEB ServicesOracle Financial Services Analytical Applications InfrastructureOracle Flexcube Private Banking | 18/1/2019 | 4/9/2026 | Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources. |