Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2003 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.8% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in kwajd_read_headers in mspack/kwajd.c in libmspack before 0.7alpha. Bad KWAJ file header extensions could cause a one or two byte overwrite. | |
| Modificada | Media (6.5) | 3.7% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. It does not reject blank CHM filenames. | |
| Modificada | Media (6.5) | 3.3% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash). | |
| Modificada | Crítica (9.9) | 4.4% | — | QemuCitrix XenserverRedhat OpenstackDebian Linux+5 | 27/7/2018 | 17/6/2026 | A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU… | |
| Modificada | Alta (7.5) | 2.5% | — | Spice Project SpiceDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 27/7/2018 | 17/6/2026 | A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash. | |
| Modificada | Crítica (9.8) | 1.5% | — | LiblouisRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+2 | 27/7/2018 | 17/6/2026 | A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution. | |
| Modificada | Media (6.7) | 0.54% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+1 | 27/7/2018 | 17/6/2026 | Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine. | |
| Modificada | Alta (8.8) | 3.8% | — | Spice Project SpiceDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 27/7/2018 | 17/6/2026 | A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution. | |
| Modificada | Alta (7.5) | 5.2% | — | Linux KernelRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+1 | 27/7/2018 | 17/6/2026 | It was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation before 2.6.22.17 used the IPv4-only inet_sk_rebuild_header() function for both IPv4 and IPv6 DCCP connections, which could result in memory corruptions. A remote attacker could use this flaw to crash the system. | |
| Modificada | Media (6.5) | 3.0% | — | QemuRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+2 | 27/7/2018 | 17/6/2026 | An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process. | |
| Modificada | Media (5.5) | 0.46% | — | Freedesktop LibiceRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+2 | 27/7/2018 | 17/6/2026 | It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list. | |
| Modificada | Crítica (9.9) | 3.6% | — | QemuCitrix XenserverRedhat OpenstackDebian Linux+6 | 27/7/2018 | 17/6/2026 | Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary… | |
| Modificada | Media (5.5) | 0.46% | — | Linux KernelDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+4 | 27/7/2018 | 17/6/2026 | A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory. | |
| Modificada | Media (4.7) | 0.28% | — | Util-linux Project Util-linuxDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 27/7/2018 | 17/6/2026 | A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions. | |
| Modificada | Crítica (9.8) | 6.2% | — | PidginDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 27/7/2018 | 17/6/2026 | An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute arbitrary code in the context of the pidgin process. | |
| Modificada | Media (5.5) | 0.53% | — | X.org LibxdmcpRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 27/7/2018 | 17/6/2026 | It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions. | |
| Modificada | Alta (8.1) | 1.3% | — | FreeipaRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 27/7/2018 | 17/6/2026 | A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing various denial of service problems with… | |
| Modificada | Alta (8.8) | 1.5% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+2 | 27/7/2018 | 17/6/2026 | It was found that sssd's sysdb_search_user_by_upn_res() function before 1.16.0 did not sanitize requests when querying its local cache and was vulnerable to injection. In a centralized login environment, if a password hash was locally cached for a given user, an authenticated attacker could use this flaw to retrieve… | |
| Modificada | Alta (7.4) | 4.1% | — | SambaDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+4 | 27/7/2018 | 17/6/2026 | A flaw was found in the way samba client before samba 4.4.16, samba 4.5.14 and samba 4.6.8 used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a… | |
| Modificada | Media (5.5) | 3.4% | — | Linux KernelCanonical Ubuntu LinuxRedhat MRG RealtimeRedhat Enterprise Linux Desktop+5 | 26/7/2018 | 17/6/2026 | The timer_create syscall implementation in kernel/time/posix-timers.c in the Linux kernel before 4.14.8 doesn't properly validate the sigevent->sigev_notify field, which leads to out-of-bounds access in the show_timer function (called when /proc/$PID/timers is read). This allows userspace applications to read… | |
| Modificada | Media (5.5) | 0.77% | — | Canonical Ubuntu LinuxDebian LinuxLinux KernelRedhat Enterprise Linux Desktop+4 | 26/7/2018 | 17/6/2026 | A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bound access in ext4_get_group_info function, a denial of service, and a system crash by mounting and operating on a crafted ext4 filesystem image. | |
| Modificada | Alta (7.8) | 0.86% | — | Canonical Ubuntu LinuxLinux KernelDebian LinuxRedhat Enterprise Linux+3 | 26/7/2018 | 17/6/2026 | A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause a use-after-free in ext4_xattr_set_entry function and a denial of service or unspecified other impact may occur by renaming a file in a crafted ext4 filesystem image. | |
| Modificada | Alta (7.8) | 0.75% | — | Canonical Ubuntu LinuxLinux KernelDebian LinuxRedhat Enterprise Linux Desktop+2 | 26/7/2018 | 17/6/2026 | A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image. | |
| Modificada | Alta (7.4) | 13% | — | SambaRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 26/7/2018 | 17/6/2026 | It was found that samba before 4.4.16, 4.5.x before 4.5.14, and 4.6.x before 4.6.8 did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man-in-the-middle attack and retrieve information in plain-text. | |
| Modificada | Alta (7.8) | 0.52% | — | Linux KernelRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+1 | 26/7/2018 | 17/6/2026 | A flaw was found in Linux kernel's KVM virtualization subsystem. The VMX code does not restore the GDT.LIMIT to the previous host value, but instead sets it to 64KB. With a corrupted GDT limit a host's userspace code has an ability to place malicious entries in the GDT, particularly to the per-cpu variables. An… |