Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.40% | — | Stormshield Network Security | 21/12/2023 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 3.7.0 through 3.7.39, 3.11.0 through 3.11.27, 4.3.0 through 4.3.22, 4.6.0 through 4.6.9, and 4.7.0 through 4.7.1. It's possible to know if a specific user account exists on the SNS firewall by using remote access commands. | |
| Modificada | Media (5.9) | 0.69% | — | Dogtagpki Network Security Services FOR JavaRedhat Enterprise Linux | 4/10/2023 | 17/6/2026 | A flaw was found in JSS. A memory leak in JSS requires non-standard configuration but is a low-effort DoS vector if configured that way (repeatedly hitting the login page). | |
| Modificada | Alta (7.5) | 0.62% | — | Stormshield Network Security | 28/8/2023 | 17/6/2026 | ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet. | |
| Modificada | Media (4.8) | 0.47% | — | Stormshield Network Security | 25/8/2023 | 17/6/2026 | An issue was discovered in Stormshield SNS 3.8.0. Authenticated Stored XSS in the admin login panel leads to SSL VPN credential theft. A malicious disclaimer file can be uploaded from the admin panel. The resulting file is rendered on the authentication interface of the admin panel. It is possible to inject malicious… | |
| Modificada | Media (5.3) | 7.0% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudClamavStormshield Network Security | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to access sensitive information on an affected device.… | |
| Modificada | Crítica (9.8) | 29% | — | Cisco Secure EndpointCisco Secure Endpoint Private CloudCisco WEB Security ApplianceClamav+1 | 1/3/2023 | 17/6/2026 | On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability… | |
| Modificada | Alta (7.4) | 60% | — | OpensslStormshield Management CenterStormshield Network Security | 8/2/2023 | 17/6/2026 | There is a type confusion vulnerability relating to X.400 address processing inside an X.509 GeneralName. X.400 addresses were parsed as an ASN1_STRING but the public structure definition for GENERAL_NAME incorrectly specified the type of the x400Address field as ASN1_TYPE. This field is subsequently interpreted by… | |
| Modificada | Alta (7.5) | 20% | — | OpensslStormshield Network Security | 8/2/2023 | 17/6/2026 | The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are populated with pointers to buffers containing the relevant decoded data. The caller is… | |
| Modificada | Media (5.9) | 16% | — | OpensslStormshield Endpoint SecurityStormshield SslvpnStormshield Network Security | 8/2/2023 | 17/6/2026 | A timing based side channel exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The… | |
| Modificada | Alta (7.5) | 1.8% | — | StrongswanCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 31/10/2022 | 17/6/2026 | strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted end-entity (and intermediate CA) certificate that contains a CRL/OCSP URL that points to a server (under the attacker's control) that doesn't properly respond but (for example) just does nothing… | |
| Modificada | Alta (7.5) | 0.76% | — | Mozilla Network Security Services | 14/10/2022 | 17/6/2026 | A vulnerability found in nss. By this security vulnerability, nss client auth crash without a user certificate in the database and this can lead us to a segmentation fault or crash. | |
| Modificada | Alta (7.5) | 1.6% | — | Dogtagpki Network Security Services FOR JavaRedhat Enterprise LinuxDebian Linux | 24/8/2022 | 17/6/2026 | A flaw was found in JSS, where it did not properly free up all memory. Over time, the wasted memory builds up in the server memory, saturating the server’s RAM. This flaw allows an attacker to force the invocation of an out-of-memory process, causing a denial of service. | |
| Modificada | Alta (7.5) | 0.75% | — | Stormshield Network Security | 24/8/2022 | 17/6/2026 | Flooding SNS firewall versions 3.7.0 to 3.7.29, 3.11.0 to 3.11.17, 4.2.0 to 4.2.10, and 4.3.0 to 4.3.6 with specific forged traffic, can lead to SNS DoS. | |
| Modificada | Crítica (9.8) | 19% | — | ZlibFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+14 | 5/8/2022 | 14/7/2026 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the… | |
| Modificada | Alta (7.5) | 0.98% | — | IBM Qradar Network Security | 12/7/2022 | 17/6/2026 | IBM QRadar Network Security 5.4.0 and 5.5.0 discloses sensitive information to unauthorized users which could be used to mount further attacks against the system. IBM X-Force ID: 174339. | |
| Modificada | Alta (7.5) | 0.82% | — | IBM Qradar Network Security | 12/7/2022 | 17/6/2026 | IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 174337. | |
| Modificada | Alta (7.5) | 0.99% | — | Stormshield Network Security | 12/5/2022 | 17/6/2026 | An issue was discovered in Stormshield Network Security (SNS) 4.3.x before 4.3.8. The event logging of the ASQ sofbus lacbus plugin triggers the dereferencing of a NULL pointer, leading to a crash of SNS. An attacker could exploit this vulnerability via forged sofbus lacbus traffic to cause a firmware crash. | |
| Modificada | Alta (7.5) | 0.93% | — | Stormshield Network Security | 15/3/2022 | 17/6/2026 | In Stormshield Network Security (SNS) before 3.7.25, 3.8.x through 3.11.x before 3.11.13, 4.x before 4.2.10, and 4.3.x before 4.3.5, a flood of connections to the SSLVPN service might lead to saturation of the loopback interface. This could result in the blocking of almost all network traffic, making the firewall… | |
| Modificada | Media (5.8) | 0.92% | — | Stormshield Network Security | 10/2/2022 | 17/6/2026 | Stormshield Network Security (SNS) 3.x has an Integer Overflow in the high-availability component. | |
| Modificada | Media (6.5) | 0.41% | — | Stormshield Network Security | 10/2/2022 | 17/6/2026 | Stormshield Network Security (SNS) 1.0.0 through 4.2.3 allows a Denial of Service. | |
| Modificada | Media (6.1) | 0.20% | — | Stormshield Network Security | 10/2/2022 | 17/6/2026 | In Stormshield 1.1.0, and 2.1.0 through 2.9.0, an attacker can block a client from accessing the VPN and can obtain sensitive information through the SN VPN SSL Client. | |
| Modificada | Crítica (9.8) | 2.1% | — | Stormshield Network Security | 31/1/2022 | 17/6/2026 | In ASQ in Stormshield Network Security (SNS) 1.0.0 through 2.7.8, 2.8.0 through 2.16.0, 3.0.0 through 3.7.20, 3.8.0 through 3.11.8, and 4.0.1 through 4.2.2, mishandling of memory management can lead to remote code execution. | |
| Modificada | Alta (7.2) | 1.2% | — | Stormshield Network Security | 31/1/2022 | 17/6/2026 | Stormshield Network Security (SNS) before 4.2.2 allows a read-only administrator to gain privileges via CLI commands. | |
| Modificada | Media (5.3) | 0.89% | — | Stormshield Network Security | 27/1/2022 | 17/6/2026 | An issue was discovered in Stormshield SNS before 4.2.3 (when the proxy is used). An attacker can saturate the proxy connection table. This would result in the proxy denying any new connections. | |
| Modificada | Media (5.5) | 0.24% | — | Stormshield Network Security | 17/1/2022 | 17/6/2026 | In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer. |