Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

4185 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.51%—Linux KernelCanonical Ubuntu LinuxDebian Linux20/2/202016/6/2026
fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts.
ModificadaAlta (8.8)2.3%—LibarchiveCanonical Ubuntu LinuxFedoraproject Fedora20/2/202017/6/2026
archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact.
ModificadaMedia (5.5)0.39%—Linux KernelCanonical Ubuntu Linux20/2/202016/6/2026
The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of service (memory consumption) by triggering creation of PTE pages.
ModificadaAlta (8.8)8.8%—Canonical Ubuntu LinuxFedoraproject FedoraAudiofile19/2/202017/6/2026
Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by sixteen-stereo-to-eight-mono.c.
ModificadaAlta (7.5)6.1%—Coturn Project CoturnDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux19/2/202017/6/2026
An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to send an HTTP request to trigger this vulnerability.
ModificadaCrítica (9.8)5.1%—Coturn Project CoturnFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux19/2/202017/6/2026
An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacker needs to send an HTTPS request to trigger this vulnerability.
ModificadaAlta (7.8)1.2%💥 ExploitLinux KernelCanonical Ubuntu Linux19/2/202016/6/2026
OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions.
ModificadaAlta (8.8)3.8%—O-dyn CollabtiveDebian LinuxCanonical Ubuntu Linux17/2/202017/6/2026
Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3, (2) .php4, (3) .php5, or (4) .phtml extension.
ModificadaMedia (5.5)0.42%—Linux KernelCanonical Ubuntu LinuxOpensuse LeapNetapp Active IQ Unified Manager+614/2/202017/6/2026
ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size.
ModificadaAlta (7)0.43%—Linuxfoundation RuncDebian LinuxOpensuse LeapCanonical Ubuntu Linux+112/2/202017/6/2026
runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount configurations, and be able to run custom images. (This vulnerability does not affect Docker due…
ModificadaAlta (7.5)3.4%—LibgdFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+111/2/202017/6/2026
gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).
ModificadaAlta (8.1)4.7%—HtmlunitDebian LinuxCanonical Ubuntu LinuxApache Camel11/2/202017/6/2026
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android application, Android-specific initialization of Rhino engine is done in an improper…
ModificadaBaja (3.3)0.26%—Apport Project ApportCanonical Ubuntu Linux8/2/202017/6/2026
Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling.
ModificadaAlta (7.8)0.44%—Whoopsie Project WhoopsieCanonical Ubuntu Linux8/2/202017/6/2026
Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.
ModificadaBaja (3.3)0.40%—Apport Project ApportCanonical Ubuntu Linux8/2/202017/6/2026
Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user.
ModificadaMedia (4.7)0.23%—Canonical Ubuntu LinuxApport Project Apport8/2/202017/6/2026
Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories.
ModificadaAlta (7.8)0.45%—Canonical Ubuntu LinuxApport Project Apport8/2/202017/6/2026
Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, with unknown consequences.
ModificadaMedia (6.5)2.4%—CephRedhat Openshift Container StorageOpensuse LeapCanonical Ubuntu Linux7/2/202017/6/2026
A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket connection by radosgw. This flaw could lead to a denial of service condition by pile up of CLOSE_WAIT…
ModificadaAlta (8.8)11%💥 ExploitImagemagickCanonical Ubuntu LinuxOpensuse6/2/202017/6/2026
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-1947.
ModificadaAlta (8.8)3.5%—ImagemagickCanonical Ubuntu LinuxOpensuse6/2/202017/6/2026
Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-2030.
ModificadaAlta (7.4)4.5%—McabberCanonical Ubuntu LinuxDebian Linux6/2/202017/6/2026
MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associated privileges, via crafted XMPP packets.
ModificadaAlta (7.1)0.66%—Linux KernelDebian LinuxOpensuse LeapNetapp Active IQ Unified Manager+56/2/202017/6/2026
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c.
ModificadaAlta (7.5)2.6%—ClamavCanonical Ubuntu Linux5/2/202017/6/2026
A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to an out-of-bounds read affecting users that have enabled the…
ModificadaAlta (7.5)10%—Squid-cache SquidFedoraproject FedoraDebian LinuxOpensuse Leap+14/2/202017/6/2026
An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.
ModificadaAlta (7.5)6.8%—Squid-cache SquidOpensuse LeapCanonical Ubuntu Linux4/2/202017/6/2026
An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can result in the helper process being terminated unexpectedly. This leads…