Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
4185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | GnupgFedoraproject FedoraCanonical Ubuntu Linux | 20/3/2020 | 17/6/2026 | A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG versions before 2.2.18. | |
| Modificada | Alta (7.1) | 1.0% | — | BluezCanonical Ubuntu LinuxDebian LinuxOpensuse Leap | 12/3/2020 | 17/6/2026 | Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access | |
| Modificada | Alta (8.8) | 2.7% | — | Icu-project International Components FOR UnicodeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+7 | 12/3/2020 | 17/6/2026 | An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp. | |
| Modificada | Crítica (9.8) | 3.3% | — | TwistedFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux | 12/3/2020 | 17/6/2026 | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request. | |
| Modificada | Crítica (9.8) | 4.0% | — | TwistedFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+2 | 12/3/2020 | 17/6/2026 | In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request. | |
| Modificada | Media (6.5) | 3.1% | — | Usrsctp Project UsrsctpDebian LinuxCanonical Ubuntu Linux | 6/3/2020 | 17/6/2026 | usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init. | |
| Modificada | Baja (3.5) | 0.87% | — | QemuOpensuse LeapDebian LinuxCanonical Ubuntu Linux | 5/3/2020 | 17/6/2026 | QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd. | |
| Modificada | Alta (7) | 0.28% | — | Timeshift Project TimeshiftFedoraproject FedoraCanonical Ubuntu Linux | 5/3/2020 | 17/6/2026 | init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses directories owned by unprivileged users. Because Timeshift also executes scripts under this location, an attacker can… | |
| Modificada | Alta (8.8) | 23% | — | Djangoproject DjangoDebian LinuxFedoraproject FedoraNetapp Steelstore Cloud Integrated Storage+1 | 5/3/2020 | 17/6/2026 | Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was possible to break escaping and inject… | |
| Modificada | Media (5.5) | 0.76% | — | GNU GlibcFedoraproject FedoraCanonical Ubuntu LinuxOpensuse Leap+7 | 4/3/2020 | 17/6/2026 | The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d414141414141410000 value to sinl on x86 targets. This is related to… | |
| Modificada | Crítica (9.8) | 5.0% | — | WebkitgtkWpewebkit WPE WebkitFedoraproject FedoraDebian Linux+2 | 2/3/2020 | 17/6/2026 | WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed in 2.28.0 with improved memory handling. | |
| Modificada | Alta (8.8) | 1.4% | — | Mozilla FirefoxCanonical Ubuntu Linux | 2/3/2020 | 17/6/2026 | Mozilla developers reported memory safety bugs present in Firefox 72. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 73. | |
| Modificada | Alta (8.8) | 2.4% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux | 2/3/2020 | 17/6/2026 | Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. In general, these flaws cannot be exploited… | |
| Modificada | Media (6.5) | 1.0% | — | Mozilla ThunderbirdCanonical Ubuntu Linux | 2/3/2020 | 17/6/2026 | If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60. The new master password is added only on… | |
| Modificada | Media (4.3) | 1.3% | — | Mozilla ThunderbirdCanonical Ubuntu Linux | 2/3/2020 | 17/6/2026 | When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 68.5. | |
| Analizada | Alta (8.8) | 46% | ⚠ Explotación activa💥 Exploit | Mozilla FirefoxMozilla ThunderbirdCanonical Ubuntu Linux | 2/3/2020 | 17/6/2026 | Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1. | |
| Modificada | Alta (7.5) | 3.6% | — | PHPOpensuse LeapDebian LinuxCanonical Ubuntu Linux | 27/2/2020 | 17/6/2026 | In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and the file upload fails, the upload procedure would try to clean up data that does not exist and… | |
| Modificada | Alta (7.5) | 6.0% | 💥 Exploit | Pureftpd Pure-ftpdDebian LinuxFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject Fedora+1 | 26/2/2020 | 17/6/2026 | An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, they fail to correctly detect the end of the linked list and try to access a non-existent list member.… | |
| Modificada | Crítica (9.8) | 89% | 💥 Exploit | OpensmtpdCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux | 25/2/2020 | 17/6/2026 | OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to attack a server because the server code launches the client code during bounce handling. | |
| Modificada | Media (4.7) | 0.90% | 💥 Exploit | OpensmtpdFedoraproject FedoraCanonical Ubuntu Linux | 25/2/2020 | 17/6/2026 | OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c. | |
| Modificada | Alta (7.1) | 0.76% | — | Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux+8 | 25/2/2020 | 17/6/2026 | An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-2e90ca68b0d2. | |
| Modificada | Media (4.8) | 9.4% | — | Apache TomcatDebian LinuxCanonical Ubuntu LinuxOpensuse Leap+16 | 24/2/2020 | 17/6/2026 | In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly… | |
| Modificada | Media (6.4) | 1.4% | — | Ruby-lang RakeCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+1 | 24/2/2020 | 17/6/2026 | There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`. | |
| Modificada | Alta (7.5) | 3.5% | — | Freeradius PAM RadiusDebian LinuxCanonical Ubuntu Linux | 24/2/2020 | 17/6/2026 | add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted password to an application (loading the pam_radius library) and crash it. Arbitrary code execution might… | |
| Modificada | Alta (7.5) | 3.7% | — | SqliteNetapp Cloud BackupCanonical Ubuntu LinuxSiemens Sinec Infrastructure Network Services+7 | 21/2/2020 | 17/6/2026 | In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations. |