Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
4185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.53% | — | GNU GlibcCanonical Ubuntu LinuxNetapp Active IQ Unified ManagerNetapp HCI Management Node+4 | 30/4/2020 | 17/6/2026 | A use-after-free vulnerability introduced in glibc upstream version 2.14 was found in the way the tilde expansion was carried out. Directory paths containing an initial tilde followed by a valid username were affected by this issue. A local attacker could exploit this flaw by creating a specially crafted path that,… | |
| Analizada | Media (6.5) | 86% | ⚠ Explotación activa💥 Exploit | Saltstack SaltOpensuse LeapDebian LinuxCanonical Ubuntu Linux+2 | 30/4/2020 | 17/6/2026 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class allows access to some methods that improperly sanitize paths. These methods allow arbitrary directory access to authenticated users. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Saltstack SaltOpensuse LeapDebian LinuxCanonical Ubuntu Linux+1 | 30/4/2020 | 17/6/2026 | An issue was discovered in SaltStack Salt before 2019.2.4 and 3000 before 3000.2. The salt-master process ClearFuncs class does not properly validate method calls. This allows a remote user to access some methods without authentication. These methods can be used to retrieve user tokens from the salt master and/or run… | |
| Modificada | Alta (7) | 0.40% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+19 | 29/4/2020 | 17/6/2026 | In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur. | |
| Modificada | Alta (7.5) | 4.4% | — | OpenldapDebian LinuxOpensuse LeapCanonical Ubuntu Linux+14 | 28/4/2020 | 17/6/2026 | In filter.c in slapd in OpenLDAP before 2.4.50, LDAP search filters with nested boolean expressions can result in denial of service (daemon crash). | |
| Modificada | Crítica (9.8) | 3.9% | — | FfmpegCanonical Ubuntu LinuxDebian Linux | 28/4/2020 | 17/6/2026 | cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check. | |
| Modificada | Baja (3.3) | 0.52% | — | Apport Project ApportCanonical Ubuntu Linux | 28/4/2020 | 17/6/2026 | Apport reads and writes information on a crashed process to /proc/pid with elevated privileges. Apport then determines which user the crashed process belongs to by reading /proc/pid through get_pid_info() in data/apport. An unprivileged user could exploit this to read information about a privileged running process by… | |
| Modificada | Media (6.1) | 2.3% | — | GNU MailmanDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+2 | 24/4/2020 | 17/6/2026 | GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribute to XSS attacks against list-archive visitors, because an HTTP reply from an archive web server may lack a MIME type, and a web browser may perform MIME sniffing, conclude that the MIME… | |
| Modificada | Media (6.7) | 1.2% | 💥 Exploit | Linux KernelCanonical Ubuntu Linux | 24/4/2020 | 17/6/2026 | Overlayfs in the Linux kernel and shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, both replace vma->vm_file in their mmap handlers. On error the original value is not restored, and the reference is put for the file to which vm_file points. On upstream kernels this is… | |
| Modificada | Alta (8.8) | 0.69% | 💥 Exploit | Linux KernelCanonical Ubuntu Linux | 24/4/2020 | 17/6/2026 | In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, several locations which shift ids translate user/group ids before performing operations in the lower filesystem were translating them into init_user_ns, whereas they should have been translated into the s_user_ns for… | |
| Modificada | Alta (7.8) | 1.1% | 💥 Exploit | Linux KernelCanonical Ubuntu Linux | 24/4/2020 | 17/6/2026 | In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() calls fdget(oldfd), then without further checks passes the resulting file* into shiftfs_real_fdget(), which casts file->private_data, a void* that points to a filesystem-dependent… | |
| Modificada | Alta (7.8) | 1.3% | 💥 Exploit | Linux KernelCanonical Ubuntu Linux | 24/4/2020 | 17/6/2026 | In shiftfs, a non-upstream patch to the Linux kernel included in the Ubuntu 5.0 and 5.3 kernel series, shiftfs_btrfs_ioctl_fd_replace() installs an fd referencing a file from the lower filesystem without taking an additional reference to that file. After the btrfs ioctl completes this fd is closed, which then puts a… | |
| Modificada | Crítica (9.8) | 2.5% | — | Libvnc Project LibvncserverCanonical Ubuntu LinuxDebian LinuxSiemens Simatic Itc1500 Firmware+5 | 23/4/2020 | 17/6/2026 | libvncclient/cursor.c in LibVNCServer through 0.9.12 has a HandleCursorShape integer overflow and heap-based buffer overflow via a large height or width value. NOTE: this may overlap CVE-2019-15690. | |
| Modificada | Media (6.1) | 1.6% | — | Linuxfoundation CephRedhat Ceph StorageRedhat Openshift Container PlatformFedoraproject Fedora+2 | 23/4/2020 | 17/6/2026 | A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input. | |
| Modificada | Crítica (9.8) | 27% | — | Squid-cache SquidDebian LinuxOpensuse LeapFedoraproject Fedora+1 | 23/4/2020 | 17/6/2026 | An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token… | |
| Modificada | Media (4.7) | 0.34% | — | Canonical Ubuntu LinuxApport Project Apport | 22/4/2020 | 17/6/2026 | Time-of-check Time-of-use Race Condition vulnerability on crash report ownership change in Apport allows for a possible privilege escalation opportunity. If fs.protected_symlinks is disabled, this can be exploited between the os.open and os.chown calls when the Apport cron script clears out crash files of size 0. A… | |
| Modificada | Media (5.5) | 0.65% | — | Canonical Ubuntu LinuxApport Project Apport | 22/4/2020 | 17/6/2026 | Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /var/lock is a tmpfs), it will create the directory, otherwise it will simply continue execution using the existing directory. This allows for… | |
| Modificada | Media (6.5) | 2.4% | — | Libslirp Project LibslirpFedoraproject FedoraDebian LinuxOpensuse Leap+1 | 22/4/2020 | 17/6/2026 | A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service. | |
| Modificada | Alta (7.5) | 3.0% | — | TeeworldsOpensuse Backports SLEOpensuse LeapFedoraproject Fedora+2 | 22/4/2020 | 17/6/2026 | CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server. | |
| Modificada | Alta (7.5) | 2.7% | — | Linuxfoundation CephCanonical Ubuntu Linux | 22/4/2020 | 17/6/2026 | An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception. | |
| Modificada | Alta (7.5) | 3.9% | — | Git-scm GITCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora | 21/4/2020 | 17/6/2026 | Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker… | |
| Modificada | Alta (7.8) | 1.7% | — | Re2cCanonical Ubuntu Linux | 21/4/2020 | 17/6/2026 | re2c 1.3 has a heap-based buffer overflow in Scanner::fill in parse/scanner.cc via a long lexeme. | |
| Modificada | Alta (7) | 0.54% | — | GNU GlibcRedhat Enterprise LinuxCanonical Ubuntu Linux | 17/4/2020 | 17/6/2026 | An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this… | |
| Modificada | Media (4.4) | 0.48% | — | Google AndroidCanonical Ubuntu Linux | 17/4/2020 | 17/6/2026 | In f2fs_xattr_generic_list of xattr.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not required for exploitation.Product: Android. Versions: Android kernel. Android ID: A-120551147. | |
| Modificada | Alta (8.8) | 2.9% | — | WebkitgtkWpewebkit WPE WebkitCanonical Ubuntu LinuxFedoraproject Fedora+1 | 17/4/2020 | 17/6/2026 | A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash). |