Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

601 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Linuxfoundation Open Network Operating System22/7/201917/6/2026
The Linux Foundation ONOS 1.15.0 and ealier is affected by: Improper Input Validation. The impact is: The attacker can remotely execute any commands by sending malicious http request to the controller. The component is: Method runJavaCompiler in YangLiveCompilerManager.java. The attack vector is: network connectivity.
ModificadaCrítica (9.8)3.6%—Linuxfoundation Open Network Operating System19/7/201917/6/2026
The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can execute arbitrary commands on the controller. The component is: apps/yang/src/main/java/org/onosproject/yang/impl/YangLiveCompilerManager.java. The attack vector is:…
ModificadaMedia (4.9)1.1%—Linuxfoundation Open Network Operating System18/7/201917/6/2026
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: applyFlowRules() and apply() functions in FlowRuleManager.java. The attack vector is: network management…
ModificadaMedia (4.9)1.1%—Linuxfoundation Open Network Operating System18/7/201917/6/2026
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Poor Input-validation. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java (RESTful service). The attack vector is:…
ModificadaMedia (4.9)1.1%—Linuxfoundation Open Network Operating System18/7/201917/6/2026
The Linux Foundation ONOS 2.0.0 and earlier is affected by: Integer Overflow. The impact is: A network administrator (or attacker) can install unintended flow rules in the switch by mistake. The component is: createFlow() and createFlows() functions in FlowWebResource.java (RESTful service). The attack vector is:…
ModificadaAlta (8.1)1.7%—Linuxfoundation Osquery3/6/201917/6/2026
In some configurations an attacker can inject a new executable path into the extensions.load file for osquery and hard link a parent folder of a malicious binary to a folder with known 'safe' permissions. Under those circumstances osquery will load said malicious executable with SYSTEM permissions. The solution is to…
ModificadaAlta (8.6)98%💥 ExploitDockerLinuxfoundation RuncRedhat Container Development KITRedhat Openshift+1511/2/201917/6/2026
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: (1) a new container with an attacker-controlled image,…
ModificadaAlta (7.8)0.49%—Linuxfoundation Osquery31/12/201817/6/2026
An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will execute. This…
ModificadaMedia (5.3)1.7%—Linuxfoundation Opendaylight27/4/201817/6/2026
The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions.
ModificadaAlta (8.6)1.4%—Linuxfoundation Harbor15/12/201717/6/2026
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.
ModificadaAlta (7.8)0.39%—DockerLinuxfoundation RuncOpensuse1/6/201617/6/2026
libcontainer/user/user.go in runC before 0.1.0, as used in Docker before 1.11.2, improperly treats a numeric UID as a potential username, which allows local users to gain privileges via a numeric username in the password file in a container.
ModificadaCrítica (9.8)5.5%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+415/4/201616/6/2026
Heap-based buffer overflow in the unhtmlify function in foomatic-rip in foomatic-filters before 4.0.6 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via a long job title.
ModificadaAlta (7.3)5.3%—Canonical Ubuntu LinuxDebian LinuxLinuxfoundation Cups-filtersLinuxfoundation Foomatic-filters14/4/201617/6/2026
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.4.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via a ; (semicolon) character in a print job, a different vulnerability than CVE-2015-8327.
ModificadaAlta (7.5)11%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+517/12/201517/6/2026
Incomplete blacklist vulnerability in util.c in foomatic-rip in cups-filters 1.0.42 before 1.2.0 and in foomatic-filters in Foomatic 4.0.x allows remote attackers to execute arbitrary commands via ` (backtick) characters in a print job.
ModificadaAlta (7.5)6.9%—Linuxfoundation Cups-filtersCanonical Ubuntu LinuxDebian Linux14/7/201517/6/2026
Integer overflow in filter/texttopdf.c in texttopdf in cups-filters before 1.0.71 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted line size in a print job, which triggers a heap-based buffer overflow.
ModificadaAlta (7.5)8.3%—Canonical Ubuntu LinuxDebian LinuxLinuxfoundation Cups-filters14/7/201517/6/2026
Heap-based buffer overflow in the WriteProlog function in filter/texttopdf.c in texttopdf in cups-filters before 1.0.70 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a small line size in a print job.
ModificadaAlta (7.5)3.0%—Canonical Ubuntu LinuxLinuxfoundation Cups-filters24/3/201517/6/2026
The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.
ModificadaMedia (4)3.0%—Linuxfoundation Cups-filters22/6/201417/6/2026
cups-browsed in cups-filters before 1.0.53 allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging a malformed cups-browsed.conf BrowseAllow directive that is interpreted as granting browse access to all IP addresses.
ModificadaMedia (4.3)2.9%—Linuxfoundation Cups-filters22/6/201417/6/2026
The process_browse_data function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via crafted packet data.
ModificadaMedia (5.8)1.1%—Linuxfoundation Cups-filters22/6/201417/6/2026
The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.
ModificadaAlta (8.3)1.2%—Linuxfoundation Cups-filters17/4/201417/6/2026
cups-browsed in cups-filters 1.0.41 before 1.0.51 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the (1) model or (2) PDL, related to "System V interface scripts generated for queues."
ModificadaMedia (4.4)0.31%—Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraLinuxfoundation Cups-filters14/3/201417/6/2026
The OPVPWrapper::loadDriver function in oprs/OPVPWrapper.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows local users to gain privileges via a Trojan horse driver in the same directory as the PDF file.
ModificadaMedia (6.8)3.2%—Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraLinuxfoundation Cups-filters14/3/201417/6/2026
Multiple integer overflows in (1) OPVPOutputDev.cxx and (2) oprs/OPVPSplash.cxx in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allow remote attackers to execute arbitrary code via a crafted PDF file, which triggers a heap-based buffer overflow.
ModificadaMedia (6.8)3.1%—Linuxfoundation Cups-filtersCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora14/3/201417/6/2026
Heap-based buffer overflow in the pdftoopvp filter in CUPS and cups-filters before 1.0.47 allows remote attackers to execute arbitrary code via a crafted PDF file.
ModificadaMedia (6.8)3.4%—Canonical Ubuntu LinuxLinuxfoundation Cups-filters14/3/201417/6/2026
Multiple heap-based buffer overflows in the urftopdf filter in cups-filters 1.0.25 before 1.0.47 allow remote attackers to execute arbitrary code via a large (1) page or (2) line in a URF file.
Orbitaley — Vulnerabilidades