Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
609 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 6.1% | — | Redhat OpenstackOracle LinuxQemu | 7/4/2016 | 17/6/2026 | The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvram/fw_cfg.c in QEMU before 2.4, when built with the Firmware Configuration device emulation support, allow guest OS users with the CAP_SYS_RAWIO privilege to cause a denial of service (out-of-bounds read or write access and process crash) or possibly execute… | |
| Modificada | Alta (8.6) | 62% | — | ISC BindSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+10 | 9/3/2016 | 17/6/2026 | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c. | |
| Modificada | Media (6.8) | 59% | — | ISC BindSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+10 | 9/3/2016 | 17/6/2026 | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to… | |
| Modificada | Alta (8.1) | 91% | 💥 Exploit | Debian LinuxCanonical Ubuntu LinuxHP Helion OpenstackHP Server Migration Pack+26 | 18/2/2016 | 17/6/2026 | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the… | |
| Modificada | Alta (7.5) | 2.0% | — | Openstack KeystonemiddlewareOpenstack KeystoneOracle Solaris | 3/2/2016 | 17/6/2026 | The identity service in OpenStack Identity (Keystone) before 2015.1.3 (Kilo) and 8.0.x before 8.0.2 (Liberty) and keystonemiddleware (formerly python-keystoneclient) before 1.5.4 (Kilo) and Liberty before 2.3.3 does not properly invalidate authorization tokens when using the PKI or PKIZ token providers, which allows… | |
| Modificada | Alta (7.5) | 3.9% | — | Openstack Swift | 29/1/2016 | 17/6/2026 | OpenStack Object Storage (Swift) before 2.3.1 (Kilo), 2.4.x, and 2.5.x before 2.5.1 (Liberty) do not properly close server connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL. | |
| Modificada | Alta (7.5) | 3.8% | — | Openstack Swift | 29/1/2016 | 17/6/2026 | OpenStack Object Storage (Swift) before 2.4.0 does not properly close client connections, which allows remote attackers to cause a denial of service (proxy-server resource consumption) via a series of interrupted requests to a Large Object URL. | |
| Modificada | Media (5.4) | 2.9% | — | Openstack Orchestration APIRedhat OpenstackFedoraproject FedoraOracle Solaris | 20/1/2016 | 17/6/2026 | The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by… | |
| Modificada | Media (5.9) | 2.2% | — | Openstack Nova | 15/1/2016 | 17/6/2026 | The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or… | |
| Modificada | Alta (7.4) | 2.0% | — | Fedoraproject FedoraOpenstack Swift3 | 13/1/2016 | 17/6/2026 | Swift3 before 1.9 allows remote attackers to conduct replay attacks via an Authorization request that lacks a Date header. | |
| Modificada | Baja (3.5) | 1.8% | — | Openstack Nova | 12/1/2016 | 17/6/2026 | OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty), when using libvirt to spawn instances and use_cow_images is set to false, allow remote authenticated users to read arbitrary files by overwriting an instance disk with a crafted image and requesting a snapshot. | |
| Modificada | Crítica (9) | 7.7% | — | QemuRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+5 | 8/1/2016 | 17/6/2026 | Buffer overflow in the pcnet_receive function in hw/net/pcnet.c in QEMU, when a guest NIC has a larger MTU, allows remote attackers to cause a denial of service (guest OS crash) or execute arbitrary code via a large packet. | |
| Modificada | Media (6.8) | 1.6% | — | Openstack Ironic Inspector | 25/11/2015 | 17/6/2026 | OpenStack Ironic Inspector (aka ironic-inspector or ironic-discoverd), when debug mode is enabled, might allow remote attackers to access the Flask console and execute arbitrary Python code by triggering an error. | |
| Modificada | Alta (7.2) | 0.53% | — | Redhat OpenstackFedoraproject FedoraQemu | 6/11/2015 | 17/6/2026 | Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface. | |
| Modificada | Media (5) | 3.7% | — | Openstack Nova | 29/10/2015 | 17/6/2026 | OpenStack Compute (Nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) do not properly apply security group changes, which allows remote attackers to bypass intended restriction by leveraging an instance that was running when the change was made. | |
| Modificada | Baja (3.5) | 0.97% | — | Openstack Neutron | 27/10/2015 | 17/6/2026 | Race condition in OpenStack Neutron before 2014.2.4 and 2015.1 before 2015.1.2, when using the ML2 plugin or the security groups AMQP API, allows remote authenticated users to bypass IP anti-spoofing controls by changing the device owner of a port to start with network: before the security group rules are applied. | |
| Modificada | Media (6.8) | 2.4% | — | Openstack Image Registry AND Delivery Service (glance) | 26/10/2015 | 17/6/2026 | OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allows remote authenticated users to bypass the storage quota and cause a denial of service (disk consumption) by deleting images that are being uploaded using a token that expires during the process. NOTE: this vulnerability… | |
| Modificada | Media (5.5) | 2.1% | — | Openstack Image Registry AND Delivery Service (glance) | 26/10/2015 | 17/6/2026 | OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*. | |
| Modificada | Media (5) | 2.6% | — | Openstack Swift | 26/10/2015 | 17/6/2026 | OpenStack Object Storage (Swift) before 2.4.0 allows attackers to obtain sensitive information via a PUT tempurl and a DLO object manifest that references an object in another container. | |
| Modificada | Media (6.8) | 3.4% | — | Openstack Nova | 26/10/2015 | 17/6/2026 | OpenStack Compute (nova) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) does not properly delete instances from compute nodes, which allows remote authenticated users to cause a denial of service (disk consumption) by deleting instances while in the resize state. | |
| Modificada | Media (6.8) | 3.5% | — | Openstack Nova | 8/9/2015 | 17/6/2026 | OpenStack Compute (nova) 2015.1 through 2015.1.1, 2014.2.3, and earlier does not stop the migration process when the instance is deleted, which allows remote authenticated users to cause a denial of service (disk, network, and other resource consumption) by resizing and then deleting an instance. | |
| Modificada | Media (6.9) | 1.6% | 💥 Exploit | QemuLinux KernelArista EOSDebian Linux+15 | 31/8/2015 | 17/6/2026 | The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index. | |
| Modificada | Media (4) | 11% | 💥 Exploit | Openstack Neutron | 26/8/2015 | 17/6/2026 | OpenStack Neutron before 2014.2.4 (juno) and 2015.1.x before 2015.1.1 (kilo), when using the IPTables firewall driver, allows remote authenticated users to cause a denial of service (L2 agent crash) by adding an address pair that is rejected by the ipset tool. | |
| Modificada | Media (4.3) | 3.2% | — | Debian LinuxOpenstack HorizonOracle Solaris | 20/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015.1.x before 2015.1.1 allows remote attackers to inject arbitrary web script or HTML via the description parameter in a heat template, which is not properly handled in the… | |
| Modificada | Baja (3.5) | 1.5% | — | Openstack Glance | 19/8/2015 | 17/6/2026 | The import task action in OpenStack Image Service (Glance) 2015.1.x before 2015.1.2 (kilo), when using the V2 API, allows remote authenticated users to read arbitrary files via a crafted backing file for a qcow2 image. |