Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.93%—Blake2-rust9/9/201917/6/2026
An issue was discovered in the blake2 crate before 0.8.1 for Rust. The BLAKE2b and BLAKE2s algorithms, when used with HMAC, produce incorrect results because the block sizes are half of the required sizes.
ModificadaAlta (7.5)3.8%—Rust-protobuf Project Rust-protobufApache Hbase26/8/201917/6/2026
An issue was discovered in the protobuf crate before 2.6.0 for Rust. Attackers can exhaust all memory via Vec::reserve calls.
ModificadaCrítica (9.8)1.7%—Rust-openssl Project Rust-openssl26/8/201917/6/2026
An issue was discovered in the openssl crate before 0.10.9 for Rust. A use-after-free occurs in CMS Signing.
ModificadaAlta (7.5)1.4%—Untrusted Project Untrusted26/8/201917/6/2026
An issue was discovered in the untrusted crate before 0.6.2 for Rust. Error handling can trigger an integer underflow and panic.
ModificadaAlta (7.5)1.4%—Trust-dns-proto Project Trust-dns-proto26/8/201917/6/2026
An issue was discovered in the trust-dns-proto crate before 0.5.0-alpha.3 for Rust. There is infinite recursion because DNS message compression is mishandled.
ModificadaAlta (7.5)1.4%—Yaml-rust Project Yaml-rust26/8/201917/6/2026
An issue was discovered in the yaml-rust crate before 0.4.1 for Rust. There is uncontrolled recursion during deserialization.
ModificadaAlta (7.5)2.2%—Rustls Project Rustls26/8/201917/6/2026
rustls-mio/examples/tlsserver.rs in the rustls crate before 0.16.0 for Rust allows attackers to cause a denial of service (loop of conn_event and ready) by arranging for a client to never be writable.
ModificadaAlta (8.1)0.74%—Rust-openssl Project Rust-openssl26/8/201917/6/2026
An issue was discovered in the openssl crate before 0.9.0 for Rust. There is an SSL/TLS man-in-the-middle vulnerability because certificate verification is off by default and there is no API for hostname verification.
ModificadaMedia (5.5)1.1%—Virustotal Yara31/7/201917/6/2026
An exploitable denial of service vulnerability exists in the object lookup functionality of Yara 3.8.1. A specially crafted binary file can cause a negative value to be read to satisfy an assert, resulting in Denial of Service. An attacker can create a malicious binary to trigger this vulnerability.
ModificadaMedia (6.5)1.1%—Yaml-rust Project Yaml-rust25/7/201917/6/2026
yaml-rust 0.4.0 and earlier is affected by: Uncontrolled Recursion. The impact is: Denial of service by impossible to catch abort. The component is: YamlLoader::load_from_str function. The attack vector is: Parsing of a malicious YAML document. The fixed version is: 0.4.1 and later.
ModificadaCrítica (9.8)1.6%—Trustedfirmware Op-tee16/7/201917/6/2026
Linaro/OP-TEE OP-TEE Prior to version v3.4.0 is affected by: Boundary checks. The impact is: This could lead to corruption of any memory which the TA can access. The component is: optee_os. The fixed version is: v3.4.0.
ModificadaMedia (5.3)1.5%—Rust-lang Rust15/7/201917/6/2026
The Rust Programming Language Standard Library 1.18.0 and later is affected by: CWE-200: Information Exposure. The impact is: Contents of uninitialized memory could be printed to string or to log file. The component is: Debug trait implementation for std::collections::vec_deque::Iter. The attack vector is: The program…
ModificadaCrítica (9.8)3.9%💥 PoCTrustedfirmware Op-tee15/7/201917/6/2026
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.
ModificadaCrítica (9.8)2.7%—Trustedfirmware Op-tee15/7/201917/6/2026
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Execution of code in TEE core (kernel) context. The component is: optee_os. The fixed version is: 3.4.0 and later.
ModificadaCrítica (9.8)2.8%—Trustedfirmware Op-tee15/7/201917/6/2026
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.
ModificadaCrítica (9.8)1.6%—Trustedfirmware Op-tee15/7/201917/6/2026
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Memory corruption and disclosure of memory content. The component is: optee_os. The fixed version is: 3.4.0 and later.
ModificadaAlta (7.5)1.4%—Trustedfirmware Op-tee15/7/201917/6/2026
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Rounding error. The impact is: Potentially leaking code and/or data from previous Trusted Application. The component is: optee_os. The fixed version is: 3.4.0 and later.
ModificadaCrítica (9.8)1.6%—Trustedfirmware Op-tee15/7/201917/6/2026
Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Boundary crossing. The impact is: Memory corruption of the TEE itself. The component is: optee_os. The fixed version is: 3.4.0 and later.
ModificadaAlta (7.8)0.81%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA Linux/macOS binary openvpn_launcher.64 binary is setuid root. This binary accepts several parameters to update…
ModificadaAlta (7.8)0.81%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher.64 binary is setuid root. This binary executes /opt/pia/openvpn-64/openvpn, passing the parameters provided…
ModificadaAlta (7.8)0.63%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The macOS binary openvpn_launcher.64 is setuid root. This binary creates /tmp/pia_upscript.sh when executed. Because the file…
ModificadaAlta (7.8)0.86%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection process and executes several operating…
ModificadaAlta (7.8)0.91%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The root_runner.64 binary is setuid root. This binary executes /opt/pia/ruby/64/ruby, which in turn attempts to load several…
ModificadaAlta (7.8)2.1%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA client is vulnerable to a DLL injection vulnerability during the software update process. The updater loads several…
ModificadaAlta (7.1)0.58%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to overwrite arbitrary files. The openvpn_launcher binary is setuid root. This binary supports the --log option, which accepts a path as an argument. This parameter is…
Orbitaley — Vulnerabilidades