Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

3733 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.35%—Buildah Project BuildahRedhat Openshift Container PlatformRedhat Enterprise Linux13/9/202217/6/2026
An incorrect handling of the supplementary groups in the Buildah container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary…
ModificadaAlta (7.1)0.32%—Podman Project PodmanRedhat Openshift Container PlatformRedhat Enterprise Linux13/9/202217/6/2026
An incorrect handling of the supplementary groups in the Podman container engine might lead to the sensitive information disclosure or possible data modification if an attacker has direct access to the affected container where supplementary groups are used to set access permissions and is able to execute a binary code…
ModificadaAlta (7.8)0.31%—Linux KernelRedhat Enterprise LinuxNetapp H300s FirmwareNetapp H500s Firmware+39/9/202217/6/2026
A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes.
ModificadaMedia (5.5)0.36%—Linux KernelRedhat Enterprise LinuxDebian Linux9/9/202217/6/2026
An out-of-bounds memory read flaw was found in the Linux kernel's BPF subsystem in how a user calls the bpf_tail_call function with a key larger than the max_entries of the map. This flaw allows a local user to gain unauthorized access to data.
ModificadaAlta (7.5)7.2%—PythonRedhat QuayRedhat Software CollectionsFedoraproject Fedora+19/9/20227/10/2026
A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected).…
ModificadaMedia (5.5)0.48%—GNU FribidiRedhat Enterprise Linux6/9/202217/6/2026
A segmentation fault (SEGV) flaw was found in the Fribidi package and affects the fribidi_remove_bidi_marks() function of the lib/fribidi.c file. This flaw allows an attacker to pass a specially crafted file to Fribidi, leading to a crash and causing a denial of service.
ModificadaMedia (5.5)0.50%—GNU FribidiRedhat Enterprise Linux6/9/202217/6/2026
A heap-based buffer overflow flaw was found in the Fribidi package and affects the fribidi_cap_rtl_to_unicode() function of the fribidi-char-sets-cap-rtl.c file. This flaw allows an attacker to pass a specially crafted file to the Fribidi application with the '--caprtl' option, leading to a crash and causing a denial…
ModificadaAlta (7.8)0.53%—GNU FribidiRedhat Enterprise Linux6/9/202217/6/2026
A stack-based buffer overflow flaw was found in the Fribidi package. This flaw allows an attacker to pass a specially crafted file to the Fribidi application, which leads to a possible memory leak or a denial of service.
ModificadaMedia (5.3)0.51%—Redhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationPodman Project Podman1/9/202217/6/2026
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-14370, which was previously fixed via RHSA-2020:5056. This issue could possibly allow an attacker to gain access to sensitive information stored in…
ModificadaAlta (7.5)0.91%—Redhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationPodman Project Podman1/9/202217/6/2026
The version of podman as released for Red Hat Enterprise Linux 7 Extras via RHSA-2022:2190 advisory included an incorrect version of podman missing the fix for CVE-2020-8945, which was previously fixed via RHSA-2020:2117. This issue could possibly be used to crash or cause potential code execution in Go applications…
ModificadaAlta (7.8)0.92%💥 PoCLinux KernelRedhat Enterprise Linux1/9/202217/6/2026
An integer coercion error was found in the openvswitch kernel module. Given a sufficiently large number of actions, while copying and reserving memory for a new action of a new flow, the reserve_sfa_size() function does not return -EMSGSIZE as expected, potentially leading to an out-of-bounds write access. This flaw…
ModificadaMedia (5.5)0.47%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux31/8/202217/6/2026
A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition…
ModificadaAlta (8.6)2.2%—Dpdk Data Plane Development KITFedoraproject FedoraDebian LinuxRedhat Enterprise Linux Fast Datapath+431/8/202217/6/2026
A permissive list of allowed inputs flaw was found in DPDK. This issue allows a remote attacker to cause a denial of service triggered by sending a crafted Vhost header to DPDK.
ModificadaMedia (6.1)0.56%—LibtiffFedoraproject FedoraRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility+131/8/202217/6/2026
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
ModificadaMedia (5.5)0.56%—LibtiffFedoraproject FedoraRedhat Enterprise LinuxNetapp Ontap Select Deploy Administration Utility+131/8/202217/6/2026
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
ModificadaMedia (5.5)0.44%—Linux KernelRedhat Enterprise Linux31/8/202217/6/2026
A NULL pointer dereference issue was found in KVM when releasing a vCPU with dirty ring support enabled. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of service.
ModificadaAlta (7)0.27%—Linux KernelRedhat Enterprise LinuxFedoraproject Fedora31/8/202217/6/2026
An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to represent how many objects are using the rose_neigh. When a user wants to delete a rose_route via rose_ioctl(), the rose driver calls rose_del_node() and removes neighbours only if their “count” and…
AnalizadaAlta (7.5)2.0%—Linux KernelRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+429/8/202211/9/2026
A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability.
ModificadaMedia (5.5)0.43%—Linux KernelRedhat Enterprise Linux29/8/202217/6/2026
A use-after-free vulnerabilitity was discovered in drivers/net/hamradio/6pack.c of linux that allows an attacker to crash linux kernel by simulating ax25 device using 6pack driver from user space.
ModificadaMedia (5.5)0.29%—Linux KernelRedhat Enterprise LinuxDebian LinuxCanonical Ubuntu Linux29/8/202217/6/2026
A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a local attacker with a user privilege to cause a denial of service.
ModificadaMedia (5.5)0.43%—Linux KernelRedhat Enterprise Linux29/8/202217/6/2026
A flaw was found in the Linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free. This issue needs to handle 'return' with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker.
ModificadaAlta (7.5)2.5%—Thekelleys DnsmasqRedhat Enterprise Linux29/8/202217/6/2026
A single-byte, non-arbitrary write/use-after-free flaw was found in dnsmasq. This flaw allows an attacker who sends a crafted packet processed by dnsmasq, potentially causing a denial of service.
ModificadaMedia (5.5)0.37%—Convert2rhel Project Convert2rhelRedhat Enterprise Linux29/8/202217/6/2026
There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the password via the process command line via e.g. htop or ps. The specific impact varies upon the privileges of the Red…
ModificadaMedia (5.5)0.32%—Convert2rhel Project Convert2rhelRedhat Enterprise Linux29/8/202217/6/2026
There is a flaw in convert2rhel. When the --activationkey option is used with convert2rhel, the activation key is subsequently passed to subscription-manager via the command line, which could allow unauthorized users locally on the machine to view the activation key via the process command line via e.g. htop or ps.…
ModificadaMedia (4.8)0.97%—Redhat LibnbdRedhat Enterprise Linux29/8/202217/6/2026
A flaw was found in the copying tool `nbdcopy` of libnbd. When performing multi-threaded copies using asynchronous nbd calls, nbdcopy was blindly treating the completion of an asynchronous command as successful, rather than checking the *error parameter. This could result in the silent creation of a corrupted…