Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
4185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.51% | — | Linux KernelCanonical Ubuntu LinuxDebian Linux | 20/2/2020 | 16/6/2026 | fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts. | |
| Modificada | Alta (8.8) | 2.3% | — | LibarchiveCanonical Ubuntu LinuxFedoraproject Fedora | 20/2/2020 | 17/6/2026 | archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact. | |
| Modificada | Media (5.5) | 0.39% | — | Linux KernelCanonical Ubuntu Linux | 20/2/2020 | 16/6/2026 | The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of service (memory consumption) by triggering creation of PTE pages. | |
| Modificada | Alta (8.8) | 8.8% | — | Canonical Ubuntu LinuxFedoraproject FedoraAudiofile | 19/2/2020 | 17/6/2026 | Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by sixteen-stereo-to-eight-mono.c. | |
| Modificada | Alta (7.5) | 6.1% | — | Coturn Project CoturnDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux | 19/2/2020 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 5.1% | — | Coturn Project CoturnFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux | 19/2/2020 | 17/6/2026 | An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 1.2% | 💥 Exploit | Linux KernelCanonical Ubuntu Linux | 19/2/2020 | 16/6/2026 | OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions. | |
| Modificada | Alta (8.8) | 3.8% | — | O-dyn CollabtiveDebian LinuxCanonical Ubuntu Linux | 17/2/2020 | 17/6/2026 | Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension. | |
| Modificada | Media (5.5) | 0.42% | — | Linux KernelCanonical Ubuntu LinuxOpensuse LeapNetapp Active IQ Unified Manager+6 | 14/2/2020 | 17/6/2026 | ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size. | |
| Modificada | Alta (7) | 0.43% | — | Linuxfoundation RuncDebian LinuxOpensuse LeapCanonical Ubuntu Linux+1 | 12/2/2020 | 17/6/2026 | runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due… | |
| Modificada | Alta (7.5) | 3.4% | — | LibgdFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+1 | 11/2/2020 | 17/6/2026 | gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled). | |
| Modificada | Alta (8.1) | 4.7% | — | HtmlunitDebian LinuxCanonical Ubuntu LinuxApache Camel | 11/2/2020 | 17/6/2026 | HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper… | |
| Modificada | Baja (3.3) | 0.26% | — | Apport Project ApportCanonical Ubuntu Linux | 8/2/2020 | 17/6/2026 | Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling. | |
| Modificada | Alta (7.8) | 0.44% | — | Whoopsie Project WhoopsieCanonical Ubuntu Linux | 8/2/2020 | 17/6/2026 | Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie. | |
| Modificada | Baja (3.3) | 0.40% | — | Apport Project ApportCanonical Ubuntu Linux | 8/2/2020 | 17/6/2026 | Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user. | |
| Modificada | Media (4.7) | 0.23% | — | Canonical Ubuntu LinuxApport Project Apport | 8/2/2020 | 17/6/2026 | Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories. | |
| Modificada | Alta (7.8) | 0.45% | — | Canonical Ubuntu LinuxApport Project Apport | 8/2/2020 | 17/6/2026 | Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, with unknown consequences. | |
| Modificada | Media (6.5) | 2.4% | — | CephRedhat Openshift Container StorageOpensuse LeapCanonical Ubuntu Linux | 7/2/2020 | 17/6/2026 | A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of service condition by pile up of CLOSE_WAIT… | |
| Modificada | Alta (8.8) | 11% | 💥 Exploit | ImagemagickCanonical Ubuntu LinuxOpensuse | 6/2/2020 | 17/6/2026 | Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-1947. | |
| Modificada | Alta (8.8) | 3.5% | — | ImagemagickCanonical Ubuntu LinuxOpensuse | 6/2/2020 | 17/6/2026 | Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030. | |
| Modificada | Alta (7.4) | 4.5% | — | McabberCanonical Ubuntu LinuxDebian Linux | 6/2/2020 | 17/6/2026 | MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets. | |
| Modificada | Alta (7.1) | 0.66% | — | Linux KernelDebian LinuxOpensuse LeapNetapp Active IQ Unified Manager+5 | 6/2/2020 | 17/6/2026 | There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c. | |
| Modificada | Alta (7.5) | 2.6% | — | ClamavCanonical Ubuntu Linux | 5/2/2020 | 17/6/2026 | A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to an out-of-bounds read affecting users that have enabled the… | |
| Modificada | Alta (7.5) | 10% | — | Squid-cache SquidFedoraproject FedoraDebian LinuxOpensuse Leap+1 | 4/2/2020 | 17/6/2026 | An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes. | |
| Modificada | Alta (7.5) | 6.8% | — | Squid-cache SquidOpensuse LeapCanonical Ubuntu Linux | 4/2/2020 | 17/6/2026 | An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can result in the helper process being terminated unexpectedly. This leads… |