Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

4185 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.9)0.77%—Gnome File-rollerDebian LinuxCanonical Ubuntu Linux13/4/202017/6/2026
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
ModificadaMedia (5.5)0.45%—Canonical Ubuntu LinuxNetapp Cloud BackupNetapp Solidfire & HCI Management NodeNetapp Steelstore Cloud Integrated Storage+2810/4/202017/6/2026
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this…
ModificadaMedia (6.5)0.35%—Linux KernelCanonical Ubuntu LinuxOpensuse Leap9/4/202017/6/2026
KVM in the Linux kernel on Power8 processors has a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability run code in kernel space of a guest VM can cause the host kernel to panic. There were…
ModificadaAlta (7.5)4.3%—SqliteNetapp Ontap Select Deploy Administration UtilityDebian LinuxCanonical Ubuntu Linux+149/4/202017/6/2026
SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.
ModificadaMedia (4.3)0.59%—Linux KernelCanonical Ubuntu Linux7/4/202017/6/2026
An issue was discovered in the stv06xx subsystem in the Linux kernel before 5.6.1. drivers/media/usb/gspca/stv06xx/stv06xx.c and drivers/media/usb/gspca/stv06xx/stv06xx_pb0100.c mishandle invalid descriptors, as demonstrated by a NULL pointer dereference, aka CID-485b06aadb93.
ModificadaMedia (4.3)0.53%—Linux KernelCanonical Ubuntu Linux7/4/202017/6/2026
An issue was discovered in the Linux kernel before 5.6.1. drivers/media/usb/gspca/ov519.c allows NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs when there are zero endpoints, aka CID-998912346c0d.
ModificadaMedia (6)0.52%—Linux KernelCanonical Ubuntu Linux6/4/202017/6/2026
An issue was discovered in the Linux kernel through 5.6.2. mpol_parse_str in mm/mempolicy.c has a stack-based out-of-bounds write because an empty nodelist is mishandled during mount option parsing, aka CID-aa9f7d5172fa. NOTE: Someone in the security community disagrees that this is a vulnerability because the issue…
ModificadaAlta (7.4)3.4%—GnutlsCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+13/4/202017/6/2026
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security…
ModificadaMedia (4.4)0.72%—Linux KernelOpensuse LeapDebian LinuxCanonical Ubuntu Linux2/4/202017/6/2026
An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL, aka CID-b9258a2cece4.
ModificadaAlta (7.8)6.0%💥 PoCLinux KernelFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+232/4/202017/6/2026
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was…
ModificadaAlta (8.8)62%—HaproxyDebian LinuxRedhat Openshift Container PlatformFedoraproject Fedora+22/4/202017/6/2026
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
ModificadaMedia (6.1)57%—Apache Http ServerFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+102/4/202017/6/2026
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.
ModificadaMedia (5.3)52%—Apache Http ServerFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+71/4/202017/6/2026
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
ModificadaAlta (8.8)4.9%—PHPDebian LinuxCanonical Ubuntu LinuxTenable.sc1/4/202017/6/2026
In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memory corruption, crashes and potentially code execution.
ModificadaMedia (5.4)4.3%—PHPDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+11/4/202017/6/2026
In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory. This could potentially lead to information disclosure or crash.
ModificadaCrítica (9.8)1.9%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux25/3/202017/6/2026
Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox <…
ModificadaMedia (5.3)1.6%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux25/3/202017/6/2026
The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices…
ModificadaAlta (8.8)3.3%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux25/3/202017/6/2026
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This…
ModificadaAlta (8.8)1.5%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux25/3/202017/6/2026
When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR <…
ModificadaAlta (8.8)2.6%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux25/3/202017/6/2026
By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox…
ModificadaAlta (8.8)1.5%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux25/3/202017/6/2026
When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.
ModificadaMedia (5.3)1.00%—Linux KernelOpensuse LeapDebian LinuxCanonical Ubuntu Linux24/3/202017/6/2026
In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls.
ModificadaMedia (5.5)2.9%—Apache TikaOracle Business Process Management SuiteOracle Communications Messaging ServerOracle Flexcube Private Banking+223/3/202017/6/2026
A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23.
ModificadaMedia (5.5)3.0%—Apache TikaOracle Business Process Management SuiteOracle Communications Messaging ServerOracle Flexcube Private Banking+223/3/202017/6/2026
A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23.
ModificadaMedia (6.1)5.5%—Squid-cache SquidDebian LinuxCanonical Ubuntu LinuxOpensuse Leap20/3/202017/6/2026
Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.