Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3259 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.3% | — | OpenldapDebian LinuxApple MAC OS XApple Macos | 26/1/2021 | 17/6/2026 | A flaw was discovered in OpenLDAP before 2.4.57 leading to a slapd crash in the Values Return Filter control handling, resulting in denial of service (double free and out-of-bounds read). | |
| Modificada | Alta (7.5) | 77% | — | OpenldapDebian LinuxApple MAC OS XApple Macos | 26/1/2021 | 17/6/2026 | A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service. | |
| Modificada | Alta (7.5) | 85% | — | OpenldapDebian LinuxApple MAC OS XApple Macos | 26/1/2021 | 17/6/2026 | An integer underflow was discovered in OpenLDAP before 2.4.57 leading to slapd crashes in the Certificate Exact Assertion processing, resulting in denial of service (schema_init.c serialNumberAndIssuerCheck). | |
| Modificada | Alta (7.5) | 4.6% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+13 | 14/12/2020 | 17/6/2026 | curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. | |
| Modificada | Alta (7.5) | 9.8% | — | Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. | |
| Modificada | Baja (3.7) | 3.9% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions. | |
| Modificada | Alta (7.5) | 2.8% | — | Apple IcloudApple IpadosApple Iphone OSApple MAC OS X+2 | 8/12/2020 | 17/6/2026 | This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, iCloud for Windows 7.21, tvOS 14.0. A remote attacker may be able to cause a denial of service. | |
| Modificada | Media (5.5) | 1.5% | — | Apple MAC OS XApple Macos | 8/12/2020 | 17/6/2026 | A path handling issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.0.1. A remote attacker may be able to modify the file system. | |
| Analizada | Alta (7.8) | 10% | ⚠ Explotación activa | Apple IcloudApple ItunesApple IpadosApple Iphone OS+3 | 8/12/2020 | 17/6/2026 | A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS… | |
| Analizada | Alta (7.8) | 22% | ⚠ Explotación activa💥 PoC | Apple IpadosApple Iphone OSApple MAC OS XApple Macos+1 | 8/12/2020 | 17/6/2026 | A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS… | |
| Modificada | Alta (7.8) | 1.4% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Tvos+1 | 8/12/2020 | 17/6/2026 | An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. Processing a maliciously crafted audio file may lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 8.0% | — | Apple IcloudApple ItunesApple IpadosApple Iphone OS+3 | 8/12/2020 | 17/6/2026 | A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iTunes for Windows 12.10.9. Processing a maliciously crafted text file may lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.90% | — | Apple IpadosApple Iphone OSApple MAC OS X | 8/12/2020 | 17/6/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A malicious application may be able to elevate privileges. | |
| Modificada | Media (5.5) | 0.33% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Watchos | 8/12/2020 | 17/6/2026 | The issue was addressed with improved deletion. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0. A local user may be able to discover a user’s deleted messages. | |
| Modificada | Media (5.5) | 0.32% | — | Apple IpadosApple Iphone OSApple MAC OS X | 8/12/2020 | 17/6/2026 | The issue was addressed with improved deletion. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A local user may be able to discover a user’s deleted messages. | |
| Modificada | Alta (7.8) | 1.4% | — | Apple IcloudApple ItunesApple IpadosApple Iphone OS+3 | 8/12/2020 | 17/6/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in watchOS 7.0, iOS 14.0 and iPadOS 14.0, iTunes for Windows 12.10.9, iCloud for Windows 11.5, tvOS 14.0, macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave. Processing a maliciously… | |
| Modificada | Media (5.5) | 0.93% | — | Apple IpadosApple Iphone OSApple MAC OS X | 8/12/2020 | 17/6/2026 | A validation issue existed in the entitlement verification. This issue was addressed with improved validation of the process entitlement. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A malicious application may be able to determine a user's open tabs in Safari. | |
| Modificada | Media (5.5) | 1.1% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Tvos+1 | 8/12/2020 | 17/6/2026 | A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.2 and iPadOS 14.2, tvOS 14.2, watchOS 7.1. A malicious application may be able to determine kernel memory layout. | |
| Modificada | Media (5.5) | 0.34% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Tvos+1 | 8/12/2020 | 17/6/2026 | An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. A local user may be able to view senstive user information. | |
| Modificada | Alta (7.8) | 1.3% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Tvos+1 | 8/12/2020 | 17/6/2026 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to execute arbitrary code with kernel privileges. | |
| Modificada | Media (5.5) | 1.00% | — | Apple IpadosApple Iphone OSApple MAC OS X | 8/12/2020 | 17/6/2026 | The issue was addressed with improved handling of icon caches. This issue is fixed in macOS Big Sur 11.0.1, iOS 14.0 and iPadOS 14.0. A malicious app may be able to determine the existence of files on the computer. | |
| Modificada | Alta (7.8) | 1.5% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Tvos+1 | 8/12/2020 | 17/6/2026 | A buffer overflow issue was addressed with improved memory handling. This issue is fixed in watchOS 7.0, tvOS 14.0, macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave, iOS 14.0 and iPadOS 14.0. Playing a malicious audio file may lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 1.5% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Tvos+1 | 8/12/2020 | 17/6/2026 | A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, iOS 14.0 and iPadOS 14.0, macOS Catalina 10.15.6, Security Update 2020-004 Mojave, Security Update 2020-004 High Sierra, tvOS 14.0. An application may be able to execute arbitrary code with… | |
| Modificada | Media (4.3) | 1.2% | — | Apple SafariApple MAC OS X | 8/12/2020 | 17/6/2026 | A spoofing issue existed in the handling of URLs. This issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.0.1, Safari 14.0.1. Visiting a malicious website may lead to address bar spoofing. | |
| Modificada | Media (5.5) | 1.1% | — | Apple IpadosApple Iphone OSApple MAC OS XApple Tvos+1 | 8/12/2020 | 17/6/2026 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.0, tvOS 14.0, iOS 14.0 and iPadOS 14.0. An application may be able to read restricted memory. |