Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.3% | — | Clickhouse | 14/3/2022 | 17/6/2026 | Divide-by-zero in Clickhouse's Delta compression codec when parsing a malicious query. The first byte of the compressed buffer is used in a modulo operation without being checked for 0. | |
| Modificada | Alta (8.1) | 1.6% | — | ClickhouseDebian Linux | 14/3/2022 | 17/6/2026 | Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the lower bounds of… | |
| Modificada | Alta (8.1) | 1.6% | — | ClickhouseDebian Linux | 14/3/2022 | 17/6/2026 | Heap out-of-bounds read in Clickhouse's LZ4 compression codec when parsing a malicious query. As part of the LZ4::decompressImpl() loop, a 16-bit unsigned user-supplied value ('offset') is read from the compressed data. The offset is later used in the length of a copy operation, without checking the upper bounds of… | |
| Modificada | Crítica (9.8) | 2.7% | — | Clickhouse-driver Project Clickhouse-driver | 6/1/2021 | 17/6/2026 | clickhouse-driver before 0.1.5 allows a malicious clickhouse server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, due to a buffer overflow. | |
| Modificada | Crítica (9.8) | 1.7% | — | Clickhouse | 30/12/2019 | 17/6/2026 | In all versions of ClickHouse before 19.14, an OOB read, OOB write and integer underflow in decompression algorithms can be used to achieve RCE or DoS via native protocol. | |
| Modificada | Media (6.5) | 0.95% | — | Clickhouse | 30/12/2019 | 17/6/2026 | In all versions of ClickHouse before 19.14.3, an attacker having write access to ZooKeeper and who is able to run a custom server available from the network where ClickHouse runs, can create a custom-built malicious server that will act as a ClickHouse replica and register it in ZooKeeper. When another replica will… | |
| Modificada | Media (5.3) | 1.5% | — | Clickhouse | 31/10/2019 | 17/6/2026 | ClickHouse before 19.13.5.44 allows HTTP header injection via the url table function. | |
| Modificada | Media (5.3) | 1.7% | — | Clickhouse | 15/8/2019 | 17/6/2026 | In ClickHouse before 18.12.13, functions for loading CatBoost models allowed path traversal and reading arbitrary files through error messages. | |
| Modificada | Crítica (9.8) | 3.4% | — | Clickhouse | 15/8/2019 | 17/6/2026 | In ClickHouse before 18.10.3, unixODBC allowed loading arbitrary shared objects from the file system which led to a Remote Code Execution vulnerability. | |
| Modificada | Crítica (9.8) | 1.8% | — | Clickhouse | 15/8/2019 | 17/6/2026 | Incorrect configuration in deb package in ClickHouse before 1.1.54131 could lead to unauthorized use of the database. | |
| Modificada | Alta (7.5) | 1.7% | — | Clickhouse | 15/8/2019 | 17/6/2026 | ClickHouse MySQL client before versions 1.1.54390 had "LOAD DATA LOCAL INFILE" functionality enabled that allowed a malicious MySQL database read arbitrary files from the connected ClickHouse server. | |
| Modificada | Alta (8.8) | 0.72% | — | Clickhouse | 15/8/2019 | 17/6/2026 | In ClickHouse before 1.1.54388, "remote" table function allowed arbitrary symbols in "user", "password" and "default_database" fields which led to Cross Protocol Request Forgery Attacks. |