Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 3.0% | — | Linux KernelFedoraproject FedoraOracle LinuxOracle Solaris+2 | 27/5/2015 | 17/6/2026 | The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message. | |
| Modificada | Alta (7.5) | 8.6% | — | Linux KernelRedhat Enterprise MRGCanonical Ubuntu LinuxDebian Linux+8 | 10/11/2014 | 17/6/2026 | The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter. | |
| Modificada | Alta (7.5) | 7.5% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRGCanonical Ubuntu Linux+6 | 10/11/2014 | 17/6/2026 | The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c. | |
| Modificada | Media (5) | 1.8% | — | Redhat Enterprise MRG | 19/7/2014 | 16/6/2026 | Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, allows attackers with certain database privileges to cause a denial of service (inaccessible page) via a non-ASCII character in the name of a link. | |
| Modificada | Media (4.3) | 1.6% | — | Redhat Enterprise MRG | 11/7/2014 | 17/6/2026 | Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie. | |
| Modificada | Media (4) | 0.27% | — | Redhat Enterprise LinuxRedhat Enterprise MRGLinux Kernel | 5/6/2014 | 17/6/2026 | The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage… | |
| Modificada | Baja (3.3) | 0.36% | — | Suse Linux Enterprise DesktopRedhat Enterprise LinuxRedhat Enterprise MRGLinux Kernel | 5/6/2014 | 17/6/2026 | kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number. | |
| Modificada | Media (5) | 1.1% | — | Redhat Enterprise MRG | 30/4/2014 | 17/6/2026 | Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier for attackers to obtain sensitive information via a brute-force attack. | |
| Modificada | Media (4.4) | 0.59% | — | Condor Project CondorFedoraproject FedoraRedhat Enterprise MRG | 10/2/2014 | 16/6/2026 | Multiple format string vulnerabilities in Condor 7.2.0 through 7.6.4, and possibly certain 7.7.x versions, as used in Red Hat MRG Grid and possibly other products, allow local users to cause a denial of service (condor_schedd daemon and failure to launch jobs) and possibly execute arbitrary code via format string… | |
| Modificada | Alta (7.5) | 1.9% | — | Redhat Enterprise MRG | 23/12/2013 | 16/6/2026 | SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via vectors related to the "filtering table operator." | |
| Modificada | Media (4.3) | 1.8% | — | Redhat Enterprise MRG | 23/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" form. | |
| Modificada | Media (6.8) | 0.99% | — | Redhat Enterprise MRG | 23/12/2013 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers to hijack the authentication of cumin users for unspecified requests. | |
| Modificada | Media (6.5) | 1.9% | — | Redhat Enterprise MRG | 23/12/2013 | 16/6/2026 | cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors. | |
| Modificada | Baja (3.5) | 1.6% | — | Condor Project CondorRedhat Enterprise MRG | 11/10/2013 | 16/6/2026 | The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, Undefined, or Error state, which allows remote authenticated users to cause a denial of service… | |
| Modificada | Media (4) | 1.9% | — | Condor Project CondorRedhat Enterprise MRG | 11/10/2013 | 16/6/2026 | The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANT_SUSPEND policy that evaluate to an UNDEFINED state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job. | |
| Modificada | Media (5.8) | 3.2% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise MRG | 10/10/2013 | 16/6/2026 | Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, leading to improper management of the state of the consumed data. | |
| Modificada | Media (5) | 2.4% | — | Redhat Enterprise MRG | 9/10/2013 | 16/6/2026 | Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted Ajax update request. | |
| Modificada | Media (6) | 45% | 💥 Exploit | MongodbRedhat Enterprise MRG | 1/10/2013 | 16/6/2026 | MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arbitrary code via a crafted memory address in the first argument. | |
| Modificada | Media (5.8) | 1.6% | — | Redhat Enterprise MRGApache Qpid | 23/8/2013 | 16/6/2026 | The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Baja (2.1) | 0.53% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRG | 4/7/2013 | 16/6/2026 | The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive. | |
| Modificada | Alta (7.2) | 0.98% | 💥 Exploit | Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRGSuse Linux Enterprise Desktop+2 | 29/4/2013 | 16/6/2026 | The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then… | |
| Modificada | Media (4.7) | 0.38% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRG | 29/4/2013 | 16/6/2026 | The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a crafted filesystem on removable media, as demonstrated by the e2fsprogs… | |
| Modificada | Baja (2.1) | 0.39% | — | Linux KernelRedhat Enterprise MRG | 15/3/2013 | 16/6/2026 | The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect length value during a copy operation, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability. | |
| Modificada | Baja (2.1) | 0.40% | — | Linux KernelRedhat Enterprise MRG | 15/3/2013 | 16/6/2026 | The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability. | |
| Modificada | Baja (2.1) | 0.39% | — | Linux KernelRedhat Enterprise MRG | 15/3/2013 | 16/6/2026 | The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability. |