Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.49% | — | Meafinancial Blue Ridge Bank AND Trust CO. Mobile Banking | 16/6/2017 | 17/6/2026 | The "Blue Ridge Bank and Trust Co. Mobile Banking" by Blue Ridge Bank and Trust Co. app 3.0.1 -- aka blue-ridge-bank-and-trust-co-mobile-banking/id699679197 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a… | |
| Modificada | Media (5.9) | 0.49% | — | Meafinancial Pioneer Bank & Trust Mobile Banking | 16/6/2017 | 17/6/2026 | The "Pioneer Bank & Trust Mobile Banking" by PIONEER BANK AND TRUST app 3.0.0 -- aka pioneer-bank-trust-mobile-banking/id603182861 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.9) | 0.49% | — | Meafinancial Mount Vernon Bank & Trust Mobile Banking | 16/6/2017 | 17/6/2026 | The mount-vernon-bank-trust-mobile-banking/id542706679 app 3.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.9) | 0.49% | — | Lbtc LEE Bank & Trust | 16/6/2017 | 17/6/2026 | The Lee Bank & Trust lbtc-mobile/id1068984753 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Analizada | Alta (7.5) | 1.0% | — | Trustedfirmware Trusted Firmware-a | 7/6/2017 | 17/6/2026 | In ARM Trusted Firmware through 1.3, the secure self-hosted invasive debug interface allows normal world attackers to cause a denial of service (secure world panic) via vectors involving debug exceptions and debug registers. | |
| Analizada | Alta (8.1) | 0.89% | — | Trustedfirmware Trusted Firmware-a | 7/6/2017 | 17/6/2026 | In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits). | |
| Modificada | Alta (7.1) | 1.2% | — | Virustotal Yara | 6/6/2017 | 17/6/2026 | The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function… | |
| Modificada | Alta (7.5) | 2.5% | — | Virustotal Yara | 5/6/2017 | 17/6/2026 | libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishandled in the _yr_re_emit function, a different vulnerability than CVE-2017-9304. | |
| Modificada | Alta (7.5) | 1.8% | — | Virustotal Yara | 31/5/2017 | 17/6/2026 | libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is mishandled in the _yr_re_emit function. | |
| Modificada | Alta (7.5) | 1.8% | — | Virustotal Yara | 14/5/2017 | 17/6/2026 | The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule. | |
| Modificada | Alta (7.5) | 3.1% | — | Virustotal Yara | 27/4/2017 | 17/6/2026 | libyara/re.c in the regex component in YARA 3.5.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted rule that is mishandled in the yr_re_exec function. | |
| Modificada | Alta (8.1) | 3.4% | — | Trustedfirmware Mbed TLS | 20/4/2017 | 17/6/2026 | An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed TLS library, can cause an invalid free of a stack pointer leading to a potential remote… | |
| Modificada | Media (5.9) | 1.6% | — | ARM Trusted Firmware Project ARM Trusted Firmware | 6/4/2017 | 17/6/2026 | In ARM Trusted Firmware 1.2 and 1.3, a malformed firmware update SMC can result in copying unexpectedly large data into secure memory because of integer overflows. This affects certain cases involving execution of both AArch64 Generic Trusted Firmware (TF) BL1 code and other firmware update code. | |
| Modificada | Alta (7.5) | 1.6% | — | Virustotal Yara | 3/4/2017 | 17/6/2026 | libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_compiler_destroy function. | |
| Modificada | Alta (7.5) | 1.6% | — | Virustotal Yara | 3/4/2017 | 17/6/2026 | libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (heap-based out-of-bounds read and application crash) via a crafted rule that is mishandled in the yara_yyparse function. | |
| Modificada | Alta (7.5) | 1.6% | — | Virustotal Yara | 3/4/2017 | 17/6/2026 | libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_parser_lookup_loop_variable function. | |
| Modificada | Alta (7.5) | 2.9% | — | Virustotal Yara | 3/4/2017 | 17/6/2026 | libyara/lexer.l in YARA 3.5.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted rule that is mishandled in the yy_get_next_buffer function. | |
| Modificada | Crítica (9.8) | 0.72% | — | Cloudera KEY Trustee Server | 23/3/2017 | 17/6/2026 | Cloudera Key Trustee Server before 5.4.3 does not store keys synchronously, which might allow attackers to have unspecified impact via vectors related to loss of an encryption key. | |
| Analizada | Alta (7.5) | 0.78% | — | Trustedfirmware Op-teeLibtomcrypt | 13/2/2017 | 17/6/2026 | The rsa_verify_hash_ex function in rsa_verify_hash.c in LibTomCrypt, as used in OP-TEE before 2.2.0, does not validate that the message length is equal to the ASN.1 encoded data length, which makes it easier for remote attackers to forge RSA signatures or public certificates by leveraging a Bleichenbacher signature… | |
| Modificada | Media (6.8) | 2.9% | — | PolarsslTrustedfirmware Mbed TLSDebian LinuxFedoraproject Fedora+1 | 2/11/2015 | 17/6/2026 | Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the session ticket extension, which is not properly handled when creating a… | |
| Modificada | Media (6.8) | 3.7% | — | PolarsslTrustedfirmware Mbed TLSDebian LinuxFedoraproject Fedora+2 | 2/11/2015 | 17/6/2026 | Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long hostname to the server name indication (SNI) extension, which is… | |
| Modificada | Media (5) | 2.7% | — | Trustwave ModsecurityDebian Linux | 15/4/2014 | 16/6/2026 | apache2/modsecurity.c in ModSecurity before 2.7.6 allows remote attackers to bypass rules by using chunked transfer coding with a capitalized Chunked value in the Transfer-Encoding HTTP header. | |
| Modificada | Media (6.9) | 0.36% | — | Intel C202 ChipsetIntel C204 ChipsetIntel C206 ChipsetIntel C216 Chipset+6 | 12/9/2013 | 16/6/2026 | Unspecified vulnerability in the Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) before 1.2, as used by the Intel QM77, QS77, Q77 Express, C216, Q67 Express, C202, C204, and C206 chipsets and Mobile Intel QM67 and QS67 chipsets, when the measured launch environment (MLE) is invoked,… | |
| Modificada | Alta (7.8) | 3.4% | — | Trustport Webfilter | 16/8/2013 | 16/6/2026 | Directory traversal vulnerability in help.php in Trustport Webfilter 5.5.0.2232 allows remote attackers to read arbitrary files via a .. (dot dot) in the hf parameter. | |
| Modificada | Media (4.3) | 1.3% | — | Trustgo Antivirus & Mobile Security | 29/7/2013 | 16/6/2026 | The TrustGo Antivirus & Mobile Security application before 1.3.6 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent to com.trustgo.mobile.security.USSDScannerActivity with zero arguments. |