Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2675▼ 356 respecto a la semana anterior
Críticas / altas1295▼ 24 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

87 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.5%—Fedoraproject SssdRedhat VirtualizationRedhat Virtualization HostRedhat Enterprise Linux+423/12/202117/6/2026
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially crafted sssctl command, such as via sudo, to gain root access. The highest threat from this…
ModificadaAlta (7.1)0.38%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV+156/5/20215/8/2026
A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The highest threat from this vulnerability is to data integrity and system availability.
ModificadaMedia (5.9)3.1%—Linux KernelRedhat 3scaleRedhat OpenstackRedhat Virtualization Host+722/5/202017/6/2026
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO…
ModificadaAlta (8.8)0.76%—Linux KernelRedhat Virtualization HostRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+2419/9/201917/6/2026
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be…
ModificadaAlta (7.8)0.62%—Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+3017/9/201917/6/2026
A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could…
ModificadaMedia (5.6)4.5%—Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8.1Microsoft Windows RT 8.1+113/9/201917/6/2026
An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and…
ModificadaAlta (8.1)2.7%—Google AndroidApple Iphone OSApple MAC OS XApple Tvos+14314/8/201917/6/2026
The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the…
ModificadaAlta (7.8)0.52%—Redhat LibvirtRedhat Enterprise LinuxRedhat VirtualizationRedhat Virtualization Host+130/7/201917/6/2026
It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the…
ModificadaAlta (7.5)92%—Linux KernelF5 Big-ip Advanced Firewall ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Application Acceleration Manager+1719/6/201917/6/2026
Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182,…
ModificadaCrítica (9.8)3.0%—Redhat UndertowRedhat VirtualizationRedhat Virtualization HostRedhat Jboss Data Grid+212/6/201917/6/2026
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)
ModificadaMedia (6.5)1.8%—Linux KernelCanonical Ubuntu LinuxDebian LinuxRedhat Codeready Linux Builder+1211/4/201917/6/2026
A heap data infoleak in multiple locations including L2CAP_PARSE_CONF_RSP was found in the Linux kernel before 5.1-rc1.
ModificadaMedia (5.9)17%—OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+7827/2/201917/6/2026
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid…
ModificadaAlta (7.5)2.2%—RsyslogRedhat Virtualization ManagerRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+825/1/201917/6/2026
A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.
ModificadaMedia (5.5)0.51%—Linux KernelRedhat Openshift Container PlatformRedhat Virtualization HostRedhat Enterprise Linux Desktop+612/12/201817/6/2026
The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and…
ModificadaMedia (6.5)2.5%—GlusterfsRedhat Virtualization HostRedhat Enterprise Linux ServerRedhat Virtualization+11/11/201817/6/2026
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated usage of GF_META_LOCK_KEY xattr. A remote, authenticated attacker could use this flaw to create multiple locks for single inode by using setxattr repetitively resulting in memory exhaustion of glusterfs server node.
ModificadaMedia (6.5)2.7%—GlusterfsDebian LinuxRedhat VirtualizationRedhat Virtualization Host+131/10/201817/6/2026
It was found that usage of snprintf function in feature/locks translator of glusterfs server 3.8.4, as shipped with Red Hat Gluster Storage, was vulnerable to a format string attack. A remote, authenticated attacker could use this flaw to cause remote denial of service.
ModificadaMedia (6.5)2.2%—Redhat Gluster File SystemDebian LinuxRedhat Enterprise Linux ServerRedhat Virtualization+131/10/201817/6/2026
The Gluster file system through versions 4.1.4 and 3.1.2 is vulnerable to a denial of service attack via use of the 'GF_XATTR_IOSTATS_DUMP_KEY' xattr. A remote, authenticated attacker could exploit this by mounting a Gluster volume and repeatedly calling 'setxattr(2)' to trigger a state dump and create an arbitrary…
ModificadaMedia (6.5)2.6%—Redhat Gluster StorageRedhat Enterprise Linux ServerRedhat Enterprise Linux VirtualizationRedhat Virtualization+231/10/201817/6/2026
The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server.
ModificadaMedia (6.5)2.7%—Redhat Gluster StorageDebian LinuxRedhat Enterprise Virtualization HostRedhat Enterprise Linux Server+131/10/201817/6/2026
The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote authenticated attacker could exploit this on a mounted volume to cause a denial of service.
ModificadaAlta (8.1)2.6%—Linux KernelRedhat Openshift Container PlatformRedhat Virtualization HostRedhat Enterprise Linux Desktop+522/10/201817/6/2026
In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET socket. This issue exists because of the 15fe076edea787807a7cdc168df832544b58eba6 incomplete fix for a race condition. The code mishandles a certain multithreaded case…
ModificadaAlta (8.8)4.4%—ParamikoRedhat Ansible TowerRedhat Virtualization HostRedhat Enterprise Linux Desktop+78/10/201817/6/2026
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
ModificadaMedia (6.5)2.3%—Redhat UndertowRedhat VirtualizationRedhat Virtualization Host11/9/201817/6/2026
It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.
ModificadaMedia (6.5)2.1%—GlusterfsRedhat Enterprise LinuxRedhat Enterprise Linux ServerDebian Linux+34/9/201817/6/2026
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.
ModificadaAlta (8.8)3.3%—Debian LinuxRedhat Enterprise Linux ServerGlusterfsRedhat Virtualization Host+14/9/201817/6/2026
A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files and execute arbitrary code on glusterfs server nodes.
ModificadaAlta (8.8)2.7%—Debian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux ServerGlusterfs+34/9/201817/6/2026
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server…