Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
570 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.2% | — | Bouncycastle Bc-javaDebian Linux | 4/6/2018 | 17/6/2026 | In the Bouncy Castle JCE Provider version 1.55 and earlier the DSA key pair generator generates a weak private key if used with default values. If the JCA key pair generator is not explicitly initialised with DSA parameters, 1.55 and earlier generates a private value assuming a 1024 bit key size. In earlier releases… | |
| Modificada | Alta (7.5) | 1.8% | — | Bouncycastle Bc-javaDebian Linux | 4/6/2018 | 17/6/2026 | In the Bouncy Castle JCE Provider version 1.55 and earlier ECDSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a… | |
| Modificada | Media (5.9) | 2.6% | — | Bouncycastle Bc-javaDebian Linux | 4/6/2018 | 17/6/2026 | In the Bouncy Castle JCE Provider version 1.55 and earlier DSA signature generation is vulnerable to timing attack. Where timings can be closely observed for the generation of signatures, the lack of blinding in 1.55, or earlier, may allow an attacker to gain information about the signature's k value and ultimately… | |
| Modificada | Alta (7.5) | 2.3% | — | Bouncycastle Bc-java | 4/6/2018 | 17/6/2026 | In the Bouncy Castle JCE Provider versions 1.51 to 1.55, a carry propagation bug was introduced in the implementation of squaring for several raw math classes have been fixed (org.bouncycastle.math.raw.Nat???). These classes are used by our custom elliptic curve implementations (org.bouncycastle.math.ec.custom.**), so… | |
| Modificada | Media (5.3) | 2.7% | — | Bouncycastle Bc-javaDebian Linux | 4/6/2018 | 17/6/2026 | In the Bouncy Castle JCE Provider version 1.55 and earlier the primary engine class used for AES was AESFastEngine. Due to the highly table driven approach used in the algorithm it turns out that if the data channel on the CPU can be monitored the lookup table accesses are sufficient to leak information on the AES key… | |
| Analizada | Alta (7.5) | 1.8% | — | Bouncycastle Legion-of-the-bouncy-castle-java-crytography-apiRedhat SatelliteRedhat Satellite CapsuleCanonical Ubuntu Linux+1 | 1/6/2018 | 17/6/2026 | In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a… | |
| Modificada | Media (4.4) | 0.26% | — | Bouncycastle Bc-javaRedhat SatelliteRedhat Satellite Capsule | 16/4/2018 | 17/6/2026 | The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. Bouncy Castle release 1.47 changes the BKS format to a format which uses a 160 bit HMAC instead. This applies to any BKS keystore generated prior to BC 1.47. For situations where… | |
| Modificada | Media (6.1) | 30% | 💥 PoC | JqueryOracle Agile Product Lifecycle Management FOR ProcessOracle Banking PlatformOracle Business Process Management Suite+43 | 18/1/2018 | 17/6/2026 | jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed. | |
| Modificada | Alta (8.1) | 1.5% | — | Oracle Financial Services Loan Loss Forecasting AND Provisioning | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to… | |
| Modificada | Media (6.1) | 1.1% | — | Oracle Financial Services Loan Loss Forecasting AND Provisioning | 18/1/2018 | 17/6/2026 | Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning component of Oracle Financial Services Applications (subcomponent: User Interface). The supported version that is affected is 8.0.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to… | |
| Modificada | Media (5.9) | 24% | — | Bouncycastle Bc-java | 13/12/2017 | 17/6/2026 | BouncyCastle TLS prior to version 1.0.3, when configured to use the JCE (Java Cryptography Extension) for cryptographic functions, provides a weak Bleichenbacher oracle when any TLS cipher suite using RSA key exchange is negotiated. An attacker can recover the private key from a vulnerable application. This… | |
| Modificada | Media (6.5) | 0.76% | — | Apereo Opencast | 17/11/2017 | 17/6/2026 | In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the access control incorrectly so that users only need to match part of the user name used for the access restriction. For example, a user with the role ROLE_USER will have… | |
| Modificada | Alta (8.8) | 1.9% | — | Opencast | 17/11/2017 | 17/6/2026 | Opencast 2.3.2 and older versions are vulnerable to script injections through media and metadata in the player and media module resulting in arbitrary code execution, fixed in 2.3.3 and 3.0. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Luracast Restler | 15/10/2017 | 17/6/2026 | Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension before 1.7.1 for TYPO3, allows remote attackers to read arbitrary files via the file parameter. | |
| Modificada | Alta (8.8) | 1.1% | — | Podlove Podcast Publisher | 18/8/2017 | 17/6/2026 | lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/admin.php, exploitable through CSRF. | |
| Modificada | Media (5.5) | 0.19% | — | Motorola Mx011anm FirmwareComcast Xfinity Xr11-20 Firmware | 31/7/2017 | 17/6/2026 | The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) and Xfinity XR11-20 Voice Remote devices allows local users to upload arbitrary firmware images to an XR11 by leveraging root access. In other words, there is no protection mechanism involving digital signatures for the firmware. | |
| Modificada | Media (5.9) | 1.4% | — | Comcast Xfinity Wifi Hotspot | 31/7/2017 | 17/6/2026 | Comcast XFINITY WiFi Home Hotspot devices allow remote attackers to spoof the identities of Comcast customers via a forged MAC address. | |
| Modificada | Alta (8.6) | 1.6% | — | IBM Websphere Cast Iron Solution | 5/5/2017 | 17/6/2026 | IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary domain names. By… | |
| Modificada | Alta (8.6) | 1.4% | — | IBM Websphere Cast Iron Solution | 5/5/2017 | 17/6/2026 | IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM X-Force ID:… | |
| Modificada | Media (5.9) | 0.67% | — | Presentcast INC Tver | 28/4/2017 | 17/6/2026 | The TVer App for Android 3.2.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Alta (8.8) | 1.1% | — | Castlerock Snmpc | 10/4/2017 | 17/6/2026 | Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter. | |
| Modificada | Media (6.1) | 0.78% | — | Castlerock Snmpc | 10/4/2017 | 17/6/2026 | Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP. | |
| Modificada | Media (5.5) | 0.42% | — | Bouncycastle Bc-javaGoogle Android | 18/4/2016 | 17/6/2026 | The AES-GCM specification in RFC 5084, as used in Android 5.x and 6.x, recommends 12 octets for the aes-ICVlen parameter field, which might make it easier for attackers to defeat a cryptographic protection mechanism and discover an authentication key via a crafted application, aka internal bug 26234568. NOTE: The… | |
| Modificada | Media (6.5) | 0.61% | — | Comcast Xfinity Home Security System | 17/2/2016 | 17/6/2026 | Comcast XFINITY Home Security System does not properly maintain base-station communication, which allows physically proximate attackers to defeat sensor functionality by interfering with ZigBee 2.4 GHz transmissions. |