Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3733 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.32%—AvahiRedhat Enterprise Linux2/11/202317/6/2026
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_escape_label() function.
ModificadaMedia (5.5)0.32%—AvahiRedhat Enterprise Linux2/11/202317/6/2026
A vulnerability was found in Avahi, where a reachable assertion exists in avahi_dns_packet_append_record.
ModificadaMedia (5.5)0.32%—LibtiffRedhat Enterprise Linux2/11/202317/6/2026
A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.
ModificadaMedia (6.5)1.1%—Linux KernelRedhat Enterprise Linux1/11/202317/6/2026
A use-after-free flaw was found in smb2_is_status_io_timeout() in CIFS in the Linux Kernel. After CIFS transfers response data to a system call, there are still local variable points to the memory region, and if the system call frees it faster than CIFS uses it, CIFS will access a free memory region, leading to a…
ModificadaAlta (8.8)9.5%💥 PoCLinux KernelRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+11/11/202317/6/2026
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local…
ModificadaAlta (7.8)0.27%—Redhat Insights-clientRedhat Enterprise LinuxRedhat Enterprise Linux AUSRedhat Enterprise Linux Desktop+151/11/202317/6/2026
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could…
ModificadaAlta (7)0.62%—X.org X ServerRedhat Enterprise Linux25/10/202323/6/2026
A use-after-free flaw was found in xorg-x11-server-Xvfb. This issue occurs in Xvfb with a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode). If the pointer is warped from a screen 1 to a screen 0, a use-after-free issue may be triggered during…
ModificadaMedia (4.7)0.71%—X.org X ServerX.org XwaylandRedhat Enterprise LinuxFedoraproject Fedora+125/10/202323/6/2026
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the…
ModificadaAlta (7.8)0.62%—X.org X ServerX.org XwaylandRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+825/10/202323/6/2026
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProperty function in randr/rrproperty.c, allowing for possible escalation…
ModificadaMedia (4.6)0.49%—GNU Grub2Redhat Enterprise Linux25/10/202321/7/2026
An out-of-bounds read flaw was found on grub2's NTFS filesystem driver. This issue may allow a physically present attacker to present a specially crafted NTFS file system image to read arbitrary memory locations. A successful attack allows sensitive data cached in memory or EFI variable values to be leaked, presenting…
ModificadaAlta (7.8)0.54%—GNU Grub2Redhat Enterprise Linux25/10/202321/7/2026
An out-of-bounds write flaw was found in grub2's NTFS filesystem driver. This issue may allow an attacker to present a specially crafted NTFS filesystem image, leading to grub's heap metadata corruption. In some circumstances, the attack may also corrupt the UEFI firmware heap metadata. As a result, arbitrary code…
ModificadaAlta (7.8)0.28%—Linux KernelRedhat Codeready Linux BuilderRedhat Codeready Linux Builder EUSRedhat Codeready Linux Builder FOR Arm64+1823/10/202317/6/2026
The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use…
ModificadaAlta (7.7)0.86%—Gnome Tracker MinersRedhat Enterprise Linux13/10/202317/6/2026
A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute code outside the sandbox if the tracker-extract process has first been compromised by a separate vulnerability.
ModificadaMedia (5.5)0.36%—Libxpm Project LibxpmRedhat Enterprise LinuxFedoraproject Fedora12/10/202317/6/2026
A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a local user can trigger an out-of-bounds read error and read contents of memory on the system.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaMedia (5.5)0.38%—X.org LibxpmFedoraproject FedoraRedhat Enterprise Linux10/10/202317/6/2026
A vulnerability was found in libXpm due to a boundary condition within the XpmCreateXpmImageFromBuffer() function. This flaw allows a local attacker to trigger an out-of-bounds read error and read the contents of memory on the system.
ModificadaAlta (7.8)0.47%—X.org Libx11Redhat Enterprise LinuxFedoraproject Fedora10/10/202317/6/2026
A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.
ModificadaMedia (5.5)0.47%💥 PoCX.org Libx11Redhat Enterprise LinuxFedoraproject Fedora10/10/202317/6/2026
A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition.
ModificadaMedia (5.5)0.67%—X.org Libx11Redhat Enterprise LinuxFedoraproject Fedora10/10/202317/6/2026
A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system.
ModificadaMedia (4.4)0.40%—Linux KernelRedhat Enterprise LinuxFedoraproject Fedora9/10/202317/6/2026
A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an…
ModificadaMedia (6)0.40%—Linux KernelRedhat Enterprise LinuxFedoraproject Fedora9/10/202317/6/2026
A flaw was found in the Netfilter subsystem in the Linux kernel. The sctp_mt_check did not validate the flag_count field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure.
ModificadaMedia (6)0.39%—Linux KernelRedhat Enterprise LinuxFedoraproject Fedora9/10/202317/6/2026
A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt_u32 structure. This flaw allows a local privileged attacker to trigger an out-of-bounds read by setting the size fields with a value beyond the array boundaries, leading to a crash or information…
ModificadaMedia (6)0.40%—Linux KernelRedhat Enterprise LinuxFedoraproject Fedora9/10/202317/6/2026
A flaw was found in the Netfilter subsystem in the Linux kernel. The nfnl_osf_add_callback function did not validate the user mode controlled opt_num field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure.
ModificadaMedia (5.5)0.42%—OpenvswitchRedhat Openshift Container PlatformRedhat VirtualizationRedhat Enterprise Linux+16/10/202317/6/2026
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.
ModificadaMedia (5.5)0.40%—Linux KernelRedhat Enterprise LinuxDebian Linux5/10/202317/6/2026
A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyond the linear part of the skb, leading to an out-of-bounds read in the `rsvp_classify` function. This issue may allow a local user to crash the system and cause a denial of service.