Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.7% | — | Linuxfoundation Open Network Operating System | 22/7/2019 | 17/6/2026 | The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can remotely execute any commands by sending malicious http request to the controller. The component is: Method runJavaCompiler in YangLiveCompilerManager.java. The attack vector is: network connectivity. | |
| Modificada | Crítica (9.8) | 3.6% | — | Linuxfoundation Open Network Operating System | 19/7/2019 | 17/6/2026 | The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can execute arbitrary commands on the controller. The component is: apps/yang/src/main/java/org/onosproject/yang/impl/YangLiveCompilerManager.java. The attack vector is:… | |
| Modificada | Media (4.9) | 1.1% | — | Linuxfoundation Open Network Operating System | 18/7/2019 | 17/6/2026 | The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: applyFlowRules() and apply() functions in FlowRuleManager.java. The attack vector is: network management… | |
| Modificada | Media (4.9) | 1.1% | — | Linuxfoundation Open Network Operating System | 18/7/2019 | 17/6/2026 | The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java (RESTful service). The attack vector is:… | |
| Modificada | Media (4.9) | 1.1% | — | Linuxfoundation Open Network Operating System | 18/7/2019 | 17/6/2026 | The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java (RESTful service). The attack vector is:… | |
| Modificada | Alta (8.1) | 1.7% | — | Linuxfoundation Osquery | 3/6/2019 | 17/6/2026 | In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a malicious binary to a folder with known 'safe' permissions. Under those circumstances osquery will load said malicious executable with SYSTEM permissions. The solution is to… | |
| Modificada | Alta (8.6) | 98% | 💥 Exploit | DockerLinuxfoundation RuncRedhat Container Development KITRedhat Openshift+15 | 11/2/2019 | 17/6/2026 | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image,… | |
| Modificada | Alta (7.8) | 0.49% | — | Linuxfoundation Osquery | 31/12/2018 | 17/6/2026 | An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute. This… | |
| Modificada | Media (5.3) | 1.7% | — | Linuxfoundation Opendaylight | 27/4/2018 | 17/6/2026 | The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions. | |
| Modificada | Alta (8.6) | 1.4% | — | Linuxfoundation Harbor | 15/12/2017 | 17/6/2026 | The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping. | |
| Modificada | Alta (7.8) | 0.39% | — | DockerLinuxfoundation RuncOpensuse | 1/6/2016 | 17/6/2026 | libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container. | |
| Modificada | Crítica (9.8) | 5.5% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+4 | 15/4/2016 | 16/6/2026 | Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via a long job title. | |
| Modificada | Alta (7.3) | 5.3% | — | Canonical Ubuntu LinuxDebian LinuxLinuxfoundation Cups-filtersLinuxfoundation Foomatic-filters | 14/4/2016 | 17/6/2026 | Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327. | |
| Modificada | Alta (7.5) | 11% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+5 | 17/12/2015 | 17/6/2026 | Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job. | |
| Modificada | Alta (7.5) | 6.9% | — | Linuxfoundation Cups-filtersCanonical Ubuntu LinuxDebian Linux | 14/7/2015 | 17/6/2026 | Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 8.3% | — | Canonical Ubuntu LinuxDebian LinuxLinuxfoundation Cups-filters | 14/7/2015 | 17/6/2026 | Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a small line size in a print job. | |
| Modificada | Alta (7.5) | 3.0% | — | Canonical Ubuntu LinuxLinuxfoundation Cups-filters | 24/3/2015 | 17/6/2026 | The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707. | |
| Modificada | Media (4) | 3.0% | — | Linuxfoundation Cups-filters | 22/6/2014 | 17/6/2026 | cups-browsed in cups-filters before 1.0.53 allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a malformed cups-browsed.conf BrowseAllow directive that is interpreted as granting browse access to all IP addresses. | |
| Modificada | Media (4.3) | 2.9% | — | Linuxfoundation Cups-filters | 22/6/2014 | 17/6/2026 | The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data. | |
| Modificada | Media (5.8) | 1.1% | — | Linuxfoundation Cups-filters | 22/6/2014 | 17/6/2026 | The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707. | |
| Modificada | Alta (8.3) | 1.2% | — | Linuxfoundation Cups-filters | 17/4/2014 | 17/6/2026 | cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model or (2) PDL, related to "System V interface scripts generated for queues." | |
| Modificada | Media (4.4) | 0.31% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraLinuxfoundation Cups-filters | 14/3/2014 | 17/6/2026 | The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file. | |
| Modificada | Media (6.8) | 3.2% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraLinuxfoundation Cups-filters | 14/3/2014 | 17/6/2026 | Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 3.1% | — | Linuxfoundation Cups-filtersCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora | 14/3/2014 | 17/6/2026 | Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file. | |
| Modificada | Media (6.8) | 3.4% | — | Canonical Ubuntu LinuxLinuxfoundation Cups-filters | 14/3/2014 | 17/6/2026 | Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file. |