Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
67 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.4% | — | Windriver VxworksSiemens Ruggedcom WIN Subscriber Station FirmwareSiemens Scalance X200-4 P IRT FirmwareSiemens Scalance X201-3p IRT Firmware+32 | 13/4/2021 | 17/6/2026 | An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client. | |
| Modificada | Media (5.3) | 1.0% | — | Windriver Vxworks | 13/4/2021 | 17/6/2026 | An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on IKE. | |
| Modificada | Alta (7.4) | 18% | — | OpensslFreebsdNetapp Santricity Smi-s Provider FirmwareNetapp Storagegrid Firmware+29 | 25/3/2021 | 17/6/2026 | The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict… | |
| Modificada | Crítica (9.8) | 1.9% | — | Windriver VxworksSiemens Sgt-100 FirmwareSiemens Sgt-200 FirmwareSiemens Sgt-300 Firmware+4 | 11/3/2021 | 17/6/2026 | A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Alta (7.3) | 1.6% | — | Windriver VxworksOracle Communications Eagle | 3/2/2021 | 17/6/2026 | In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption. | |
| Modificada | Alta (7.5) | 1.1% | — | Windriver Vxworks | 23/7/2020 | 17/6/2026 | httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root. | |
| Modificada | Alta (7.5) | 1.4% | — | Windriver Vxworks | 27/4/2020 | 17/6/2026 | The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference. | |
| Modificada | Crítica (9.8) | 4.1% | — | Windriver VxworksBelden Hirschmann HiosBelden Garrettcom Magnum Dx940e FirmwareSiemens Ruggedcom Win7000 Firmware+3 | 14/8/2019 | 17/6/2026 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw). | |
| Modificada | Crítica (9.8) | 9.0% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+9 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host. | |
| Modificada | Crítica (9.8) | 23% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+9 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option. | |
| Modificada | Alta (7.5) | 23% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+8 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. | |
| Modificada | Crítica (9.8) | 75% | — | Windriver VxworksNetapp E-series Santricity OS ControllerSonicwall SonicosSiemens Siprotec 5 Firmware+8 | 9/8/2019 | 17/6/2026 | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. | |
| Modificada | Media (5.3) | 60% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+8 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report. | |
| Modificada | Alta (8.1) | 3.2% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+8 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition. | |
| Modificada | Alta (7.5) | 16% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareSiemens Ruggedcom Win7000 Firmware+7 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing. | |
| Modificada | Alta (8.8) | 84% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+6 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc. | |
| Modificada | Crítica (9.8) | 27% | — | Windriver VxworksNetapp E-series Santricity OS ControllerSonicwall SonicosSiemens Siprotec 5 Firmware+8 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options. | |
| Modificada | Alta (7.1) | 8.3% | — | Windriver VxworksBelden Hirschmann HiosBelden Garrettcom Magnum Dx940e FirmwareSiemens Ruggedcom Win7000 Firmware+3 | 5/8/2019 | 17/6/2026 | Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component. | |
| Modificada | Alta (8.1) | 2.0% | — | Windriver Vxworks | 29/5/2019 | 17/6/2026 | When RPC is enabled in Wind River VxWorks 6.9 prior to 6.9.1, a specially crafted RPC request can trigger an integer overflow leading to an out-of-bounds memory copy. It may allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code. | |
| Modificada | Media (5.5) | 0.36% | — | Jungo Windriver | 12/4/2018 | 17/6/2026 | windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x953827bf DeviceIoControl call. | |
| Modificada | Media (5.5) | 0.36% | — | Jungo Windriver | 12/4/2018 | 17/6/2026 | windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x953826DB DeviceIoControl call. | |
| Modificada | Media (5.5) | 0.73% | — | Jungo Windriver | 30/3/2018 | 17/6/2026 | windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafted .exe file, a different vulnerability than CVE-2018-8821. | |
| Modificada | Media (5.5) | 0.69% | — | Jungo Windriver | 20/3/2018 | 17/6/2026 | windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a crafted .exe file. | |
| Modificada | Alta (7.8) | 1.2% | — | Jungo Windriver | 11/1/2018 | 17/6/2026 | Race condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain system privileges by flipping pool buffer size, aka a "double fetch" vulnerability. | |
| Modificada | Alta (7.8) | 1.8% | — | Jungo Windriver | 12/9/2017 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x95382673 by the… |