Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
4241 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.2) | 1.9% | — | Libexif Project LibexifDebian LinuxCanonical Ubuntu LinuxOpensuse Leap | 21/5/2020 | 17/6/2026 | An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions. | |
| Modificada | Alta (7.5) | 2.4% | — | Libexif Project LibexifCanonical Ubuntu LinuxOpensuse Leap | 21/5/2020 | 17/6/2026 | An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data. | |
| Modificada | Crítica (9.1) | 2.8% | — | Libexif Project LibexifDebian LinuxCanonical Ubuntu LinuxOpensuse Leap | 21/5/2020 | 17/6/2026 | An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093. | |
| Modificada | Alta (8.8) | 3.3% | — | Google ChromeFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+2 | 21/5/2020 | 17/6/2026 | Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (7) | 56% | 💥 Exploit | Apache TomcatDebian LinuxOpensuse LeapFedoraproject Fedora+22 | 20/5/2020 | 25/8/2026 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is… | |
| Modificada | Media (4.4) | 0.35% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxFedoraproject Fedora | 19/5/2020 | 17/6/2026 | A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read. | |
| Modificada | Media (6.7) | 0.38% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+2 | 19/5/2020 | 17/6/2026 | A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption. | |
| Modificada | Media (6.7) | 0.38% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+2 | 19/5/2020 | 17/6/2026 | A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption. | |
| Modificada | Media (5.9) | 93% | 💥 Exploit | ISC BindDebian LinuxFedoraproject FedoraOpensuse Leap+1 | 19/5/2020 | 17/6/2026 | Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make… | |
| Modificada | Alta (7.5) | 3.6% | — | Nlnetlabs UnboundDebian LinuxOpensuse LeapCanonical Ubuntu Linux+1 | 19/5/2020 | 17/6/2026 | Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers. | |
| Modificada | Alta (7.5) | 3.2% | — | Nlnetlabs UnboundDebian LinuxOpensuse LeapCanonical Ubuntu Linux+1 | 19/5/2020 | 17/6/2026 | Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records. | |
| Modificada | Media (6.5) | 5.2% | — | Linux KernelOpensuse LeapDebian LinuxCanonical Ubuntu Linux+20 | 18/5/2020 | 17/6/2026 | gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out-of-bounds read, aka CID-15753588bcd4. | |
| Modificada | Media (5.3) | 0.40% | — | Linux KernelFedoraproject FedoraOpensuse LeapDebian Linux+21 | 15/5/2020 | 17/6/2026 | The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space. | |
| Modificada | Baja (2.2) | 2.0% | — | FreerdpCanonical Ubuntu LinuxOpensuse LeapDebian Linux | 15/5/2020 | 17/6/2026 | libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read. | |
| Modificada | Baja (2.2) | 1.7% | — | FreerdpCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 15/5/2020 | 17/6/2026 | libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read. | |
| Modificada | Media (6.6) | 1.9% | — | FreerdpCanonical Ubuntu LinuxOpensuse Leap | 15/5/2020 | 17/6/2026 | libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write. | |
| Modificada | Media (6.6) | 2.0% | — | FreerdpCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 15/5/2020 | 17/6/2026 | libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow. | |
| Modificada | Media (6.5) | 2.7% | — | FreerdpCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 15/5/2020 | 17/6/2026 | libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read. | |
| Modificada | Media (6.6) | 2.0% | — | FreerdpCanonical Ubuntu LinuxOpensuse LeapDebian Linux | 15/5/2020 | 17/6/2026 | libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write. | |
| Modificada | Media (5.5) | 1.3% | — | Debian APTDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 15/5/2020 | 17/6/2026 | Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files. | |
| Modificada | Baja (3.3) | 0.33% | — | PulseaudioCanonical Ubuntu Linux | 15/5/2020 | 17/6/2026 | — | |
| Modificada | Media (5) | 0.30% | — | Google AndroidDebian LinuxCanonical Ubuntu LinuxLibexif Project Libexif+1 | 14/5/2020 | 17/6/2026 | In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9… | |
| Modificada | Media (6.3) | 1.8% | — | Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+46 | 14/5/2020 | 17/6/2026 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an… | |
| Modificada | Alta (7.5) | 3.4% | — | Cisco Clam AntivirusCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux | 13/5/2020 | 17/6/2026 | A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a stack buffer overflow read. An attacker could exploit this… | |
| Modificada | Alta (7.5) | 5.1% | — | Cisco Clam AntivirusDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 13/5/2020 | 17/6/2026 | A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An attacker could exploit this vulnerability by… |