Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

3303 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.54%—Intel Celeron 1000mIntel Celeron 1005mIntel Celeron 1007uIntel Celeron 1017u+69015/6/202017/6/2026
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.9)2.1%—MuttCanonical Ubuntu LinuxDebian LinuxOpensuse Leap15/6/202017/6/2026
Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response.
ModificadaAlta (7.8)0.74%—IcingaOpensuse Backports SLEOpensuse Leap12/6/202017/6/2026
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be…
ModificadaMedia (4.4)0.62%—Linux KernelOpensuse LeapCanonical Ubuntu LinuxNetapp Active IQ Unified Manager+1512/6/202017/6/2026
A flaw was found in the Linux kernel's implementation of Userspace core dumps. This flaw allows an attacker with a local account to crash a trivial program and exfiltrate private kernel data.
ModificadaAlta (7.8)1.0%—Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8.1Microsoft Windows RT 8.1+59/6/202017/6/2026
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0986, CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1273,…
ModificadaMedia (5)1.8%—QemuRedhat Enterprise LinuxOpensuse LeapCanonical Ubuntu Linux9/6/202017/6/2026
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-client sends a spec-compliant request that is near the boundary of maximum permitted request length. A remote nbd-client could use this flaw to crash the qemu-nbd server…
ModificadaAlta (7.8)0.99%💥 PoCLinux KernelOpensuse LeapRedhat Enterprise LinuxRedhat Enterprise MRG+69/6/202017/6/2026
A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.
ModificadaAlta (7.5)3.0%—MumbleQTFedoraproject FedoraOpensuse Leap9/6/202017/6/2026
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not…
ModificadaMedia (5.5)0.49%—ARM Cortex-a32 FirmwareARM Cortex-a35 FirmwareARM Cortex-a53 FirmwareARM Cortex-a57 Firmware+48/6/202017/6/2026
Arm Armv8-A core implementations utilizing speculative execution past unconditional changes in control flow may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka "straight-line speculation."
ModificadaMedia (4.4)0.36%—Linuxtv XawtvDebian LinuxOpensuse Backports SLEOpensuse Leap+28/6/202017/6/2026
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the…
ModificadaMedia (6.5)1.7%—LibreofficeOpensuse LeapFedoraproject Fedora8/6/202017/6/2026
ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements the XForms W3C standard, which allows data to be submitted without the need for macros or other…
ModificadaMedia (5.3)1.9%—LibreofficeFedoraproject FedoraOpensuse Leap8/6/202017/6/2026
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic…
ModificadaAlta (7.5)6.0%—PerlNetapp Oncommand Workflow AutomationNetapp Snap Creator FrameworkFedoraproject Fedora+125/6/202017/6/2026
regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
ModificadaAlta (8.6)4.9%—PerlFedoraproject FedoraOpensuse LeapNetapp Oncommand Workflow Automation+135/6/202017/6/2026
Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
ModificadaAlta (8.2)11%—PerlFedoraproject FedoraOpensuse LeapOracle Communications Billing AND Revenue Management+115/6/202017/6/2026
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
ModificadaMedia (6)0.49%—QemuCanonical Ubuntu LinuxOpensuse Leap4/6/202017/6/2026
ati-vga in hw/display/ati.c in QEMU 4.2.0 allows guest OS users to trigger infinite recursion via a crafted mm_index value during an ati_mm_read or ati_mm_write call.
ModificadaAlta (7.4)3.3%—NTPNetapp Cloud BackupNetapp Clustered Data OntapNetapp Data Ontap+214/6/202017/6/2026
ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows remote attackers to cause a denial of service (daemon exit or system time change) by predicting transmit timestamps for use in spoofed packets. The victim must be relying on unauthenticated IPv4 time sources. There must be an off-path attacker who can query…
ModificadaAlta (8.8)1.4%—Google ChromeDebian LinuxOpensuse Backports SLEOpensuse Leap3/6/202017/6/2026
Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
ModificadaMedia (6.5)1.1%—Google ChromeDebian LinuxOpensuse BackportsOpensuse Leap3/6/202017/6/2026
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
ModificadaMedia (6.5)1.3%—Google ChromeDebian LinuxOpensuse Backports SLEOpensuse Leap3/6/202017/6/2026
Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ModificadaCrítica (9.6)1.7%—Google ChromeDebian LinuxOpensuse BackportsOpensuse Leap3/6/202017/6/2026
Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
ModificadaAlta (7.5)5.3%—Nghttp2Debian LinuxOpensuse LeapFedoraproject Fedora+63/6/202017/6/2026
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at…
ModificadaAlta (8.2)100%💥 ExploitGrafanaFedoraproject FedoraNetapp E-series Performance AnalyzerOpensuse Leap+13/6/202017/6/2026
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running…
ModificadaMedia (5.5)0.48%—Linux KernelOpensuse LeapCanonical Ubuntu Linux3/6/202017/6/2026
go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586.
ModificadaBaja (2.5)0.43%—QemuDebian LinuxOpensuse LeapCanonical Ubuntu Linux2/6/202017/6/2026
address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
Orbitaley — Vulnerabilidades