Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
179 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.62% | — | OpensslManagement Services FOR Element Software AND Netapp HCINetapp Ontap Select Deploy Administration Utility | 14/7/2023 | 17/6/2026 | Issue summary: The AES-SIV cipher implementation contains a bug that causes it to ignore empty associated data entries which are unauthenticated as a consequence. Impact summary: Applications that use the AES-SIV algorithm and want to authenticate empty data entries as associated data can be misled by removing, adding… | |
| Modificada | Media (5.3) | 2.5% | — | Fedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration UtilityPython | 19/4/2023 | 17/6/2026 | The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after… | |
| Modificada | Alta (7.5) | 20% | 💥 PoC | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+2 | 17/2/2023 | 17/6/2026 | An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters. | |
| Modificada | Alta (7.4) | 1.4% | — | GnutlsRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora+3 | 15/2/2023 | 17/6/2026 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount… | |
| Modificada | Media (6.5) | 90% | 💥 PoC | Openbsd OpensshFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp A250 Firmware+2 | 3/2/2023 | 17/6/2026 | OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states… | |
| Modificada | Alta (7.8) | 0.67% | — | VIMNetapp Ontap Select Deploy Administration Utility | 5/12/2022 | 17/6/2026 | Use After Free in GitHub repository vim/vim prior to 9.0.0882. | |
| Modificada | Alta (7.5) | 41% | — | Xmlsoft Libxml2Netapp Active IQ Unified ManagerNetapp Clustered Data OntapNetapp Clustered Data Ontap Antivirus Connector+13 | 23/11/2022 | 17/6/2026 | An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. This results in an attempt to access an array at a negative 2GB offset, typically leading to a segmentation fault. | |
| Modificada | Alta (7.5) | 2.7% | — | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+5 | 9/11/2022 | 17/6/2026 | An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote… | |
| Modificada | Crítica (9.8) | 1.2% | — | SqliteNetapp Ontap Select Deploy Administration Utility | 1/9/2022 | 17/6/2026 | In SQLite 3.31.1, there is an out of bounds access problem through ALTER TABLE for views that have a nested FROM clause. | |
| Modificada | Media (6.1) | 0.56% | — | LibtiffFedoraproject FedoraRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility+1 | 31/8/2022 | 17/6/2026 | A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service. | |
| Modificada | Media (5.5) | 0.56% | — | LibtiffFedoraproject FedoraRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility+1 | 31/8/2022 | 17/6/2026 | A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service. | |
| Modificada | Media (5.3) | 1.8% | — | GNU GlibcNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+3 | 31/8/2022 | 17/6/2026 | An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap. | |
| Modificada | Media (5.5) | 0.57% | — | LibtiffNetapp Ontap Select Deploy Administration UtilityDebian Linux | 29/8/2022 | 17/6/2026 | LibTIFF 4.4.0 has an out-of-bounds read in extractImageSection in tools/tiffcrop.c:6905, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 48d6ece8. | |
| Modificada | Media (5.5) | 0.52% | — | LibpngDebian LinuxNetapp Ontap Select Deploy Administration Utility | 24/8/2022 | 17/6/2026 | A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service. | |
| Modificada | Media (5.3) | 3.2% | — | PythonDebian LinuxRedhat Software CollectionsRedhat Enterprise Linux+1 | 24/8/2022 | 17/6/2026 | A flaw was found in Python, specifically in the FTP (File Transfer Protocol) client library in PASV (passive) mode. The issue is how the FTP client trusts the host from the PASV response by default. This flaw allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given… | |
| Modificada | Alta (7.8) | 0.75% | — | GNU GlibcDebian LinuxNetapp E-series Performance AnalyzerNetapp NFS Plug-in+6 | 24/8/2022 | 17/6/2026 | A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and… | |
| Modificada | Alta (7.5) | 1.8% | — | GNU GlibcNetapp Ontap Select Deploy Administration UtilityNetapp H300s FirmwareNetapp H500s Firmware+3 | 24/8/2022 | 17/6/2026 | A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data. | |
| Modificada | Alta (7.8) | 0.54% | — | Vmware ToolsDebian LinuxFedoraproject FedoraNetapp Ontap Select Deploy Administration Utility | 23/8/2022 | 17/6/2026 | VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine. | |
| Modificada | Media (6.5) | 1.5% | 💥 PoC | Redhat LibvirtCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux+10 | 23/8/2022 | 17/6/2026 | A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the guest is shutting down. An unprivileged… | |
| Modificada | Crítica (9.8) | 19% | 💥 PoC | ZlibFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+14 | 5/8/2022 | 14/7/2026 | zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the… | |
| Modificada | Alta (7.5) | 23% | 💥 PoC | SqliteNetapp Ontap Select Deploy Administration UtilitySplunk Universal Forwarder | 3/8/2022 | 17/6/2026 | SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API. | |
| Modificada | Media (6.5) | 1.9% | — | LibtiffFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Ontap Select Deploy Administration Utility+1 | 29/7/2022 | 17/6/2026 | A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities. | |
| Modificada | Media (4.5) | 0.47% | — | GNU Grub2Redhat Developer ToolsRedhat OpenshiftRedhat Enterprise Linux+9 | 6/7/2022 | 17/6/2026 | A heap out-of-bounds write may heppen during the handling of Huffman tables in the PNG reader. This may lead to data corruption in the heap space. Confidentiality, Integrity and Availablity impact may be considered Low as it's very complex to an attacker control the encoding and positioning of corrupted Huffman… | |
| Modificada | Media (4.5) | 0.46% | — | GNU Grub2Fedoraproject FedoraRedhat Developer ToolsRedhat Openshift+10 | 6/7/2022 | 17/6/2026 | A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure boot protections. This issue has a high complexity to be exploited as an attacker needs to perform… | |
| Modificada | Media (6.5) | 2.8% | — | GnupgFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+1 | 1/7/2022 | 17/6/2026 | GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line. |