Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
591 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.5% | — | F5 Big-ip Link ControllerF5 Big-ip Policy Enforcement ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Global Traffic Manager+18 | 7/9/2016 | 17/6/2026 | F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP DNS 12.x before… | |
| Modificada | Media (6.3) | 0.40% | — | Oracle Enterprise Manager Base Platform | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 allows local users to affect confidentiality and integrity via vectors related to Security Framework, a different vulnerability than CVE-2016-5604. | |
| Modificada | Media (4.3) | 2.0% | — | Oracle Enterprise Manager Base Platform | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 and 13.1.0.0 allows remote attackers to affect confidentiality via vectors related to UI Framework. | |
| Modificada | Media (4.7) | 2.0% | — | Oracle Enterprise Manager FOR Fusion Middleware | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager for Fusion Middleware component in Oracle Enterprise Manager Grid Control 11.1.1.7, and 11.1.1.9 allows remote attackers to affect confidentiality via vectors related to SOA Topology Viewer. | |
| Modificada | Media (6.5) | 1.6% | — | Oracle Enterprise Manager OPS Center | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2 allows remote attackers to affect availability via vectors related to OS Provisioning. | |
| Modificada | Alta (8.8) | 5.1% | — | Oracle DocumakerOracle Enterprise Manager OPS CenterOracle Health Sciences Information ManagerOracle Healthcare Master Person Index+7 | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index… | |
| Modificada | Alta (8.1) | 56% | — | Apache Http ServerHP System Management HomepageOracle Communications User Data RepositoryOracle Enterprise Manager OPS Center+16 | 19/7/2016 | 17/6/2026 | The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a… | |
| Modificada | Alta (8.1) | 50% | — | Oracle Communications User Data RepositoryOracle Enterprise Manager OPS CenterOracle LinuxFedoraproject Fedora+9 | 19/7/2016 | 17/6/2026 | PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary… | |
| Modificada | Alta (7.5) | 45% | — | NTPOracle SolarisSuse Manager ProxySuse Openstack Cloud+5 | 5/7/2016 | 17/6/2026 | ntpd in NTP before 4.2.8p8 allows remote attackers to cause a denial of service (daemon crash) via a crypto-NAK packet. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-1547. | |
| Modificada | Media (5.3) | 16% | — | NTPOracle SolarisSuse Manager ProxySuse Openstack Cloud+6 | 5/7/2016 | 17/6/2026 | ntpd in NTP 4.x before 4.2.8p8 allows remote attackers to cause a denial of service (interleaved-mode transition and time change) via a spoofed broadcast packet. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-1548. | |
| Modificada | Media (5.9) | 8.8% | — | NTPOracle SolarisSuse Manager ProxySuse Openstack Cloud+6 | 5/7/2016 | 17/6/2026 | ntpd in NTP 4.x before 4.2.8p8, when autokey is enabled, allows remote attackers to cause a denial of service (peer-variable clearing and association outage) by sending (1) a spoofed crypto-NAK packet or (2) a packet with an incorrect MAC value at a certain time. | |
| Modificada | Alta (8.1) | 5.7% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Module FOR Legacy SoftwareNovell Suse Linux Enterprise ServerNovell Suse Manager+9 | 3/6/2016 | 17/6/2026 | The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block,… | |
| Modificada | Alta (8.1) | 4.0% | — | Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node SupplementaryRedhat Enterprise Linux Server+9 | 3/6/2016 | 17/6/2026 | The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController… | |
| Modificada | Media (5.9) | 2.0% | — | F5 Big-ip Access Policy ManagerF5 Big-ip WAN Optimization ManagerF5 Big-ip Application Security ManagerF5 Big-ip Link Controller+17 | 13/5/2016 | 17/6/2026 | F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.x, 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF1; BIG-IP AAM 11.4.x before 11.4.1 HF10, 11.5.x before 11.5.4, 11.6.x before 11.6.1, and 12.x before 12.0.0 HF1; BIG-IP DNS 12.x before 12.0.0 HF1;… | |
| Modificada | Alta (7.5) | 9.1% | — | PerlDebian LinuxOracle Communications Billing AND Revenue ManagementOracle Configuration Manager+6 | 8/4/2016 | 17/6/2026 | Perl might allow context-dependent attackers to bypass the taint protection mechanism in a child process via duplicate environment variables in envp. | |
| Modificada | Media (5) | 22% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0482,… | |
| Modificada | Media (5) | 22% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0477 and CVE-2016-0478. NOTE:… | |
| Modificada | Media (5.2) | 0.36% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality and availability via unknown vectors related to Agent Next Gen. | |
| Modificada | Media (4.6) | 0.40% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen, a different vulnerability than… | |
| Modificada | Media (4.6) | 0.40% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen, a different vulnerability than… | |
| Modificada | Baja (2.1) | 0.40% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality via unknown vectors related to Agent Next Gen. | |
| Modificada | Media (4.6) | 0.40% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen. | |
| Modificada | Media (4.4) | 0.38% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 11.2.0.4, 12.1.0.4, and 12.1.0.5 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Agent Next Gen, a different vulnerability than… | |
| Modificada | Media (4.3) | 1.6% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 11.1.0.1, 12.1.0.4, and 12.1.0.5 allows remote attackers to affect confidentiality via unknown vectors related to Agent Next Gen. | |
| Modificada | Media (6.5) | 1.6% | — | Oracle Enterprise Manager Grid Control | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.4 and 12.1.0.5 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Loader Service. |