Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.47% | — | Linux KernelFedoraproject FedoraDebian LinuxStarwindsoftware Starwind SAN & NAS+4 | 20/10/2021 | 17/6/2026 | The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking. | |
| Modificada | Baja (3.3) | 0.50% | — | Linux KernelOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Exposure FunctionOracle Communications Cloud Native Core Policy | 18/8/2021 | 17/6/2026 | An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The latest version (5.11-rc4) seems to still be vulnerable. A userland application can read the contents of the sigpage, which can leak kernel memory contents. An attacker can read a process’s memory at… | |
| Modificada | Media (6.4) | 0.39% | — | Linux KernelDebian LinuxOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Exposure Function+1 | 21/7/2021 | 17/6/2026 | hso_free_net_device in drivers/net/usb/hso.c in the Linux kernel through 5.13.4 calls unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free. | |
| Modificada | Alta (7.8) | 0.69% | — | Linux KernelRedhat Enterprise LinuxFedoraproject FedoraDebian Linux+13 | 9/7/2021 | 17/6/2026 | An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or possibly escalate their privileges on the system. The highest threat from this vulnerability is to… | |
| Modificada | Media (4.7) | 0.39% | — | IBM ViosIBM AIXFedoraproject FedoraOracle Communications Cloud Native Core Binding Support Function+2 | 20/11/2020 | 17/6/2026 | IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296. | |
| Modificada | Media (5.5) | 0.23% | — | Google AndroidOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Exposure FunctionOracle Communications Cloud Native Core Policy | 17/9/2020 | 17/6/2026 | In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android… |