Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

73 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.3%—Condor Project CondorRedhat Enterprise MRG14/3/201316/6/2026
aviary/jobcontrol.py in Condor, as used in Red Hat Enterprise MRG 2.3, when removing a job, allows remote attackers to cause a denial of service (condor_schedd restart) via square brackets in the cproc option.
ModificadaMedia (4)0.39%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRG28/2/201316/6/2026
The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.
ModificadaMedia (6.2)1.0%💥 ExploitLinux KernelRedhat Enterprise LinuxRedhat Enterprise MRG28/2/201316/6/2026
Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileges or cause a denial of service (system crash) via a VFAT write operation on a filesystem with the utf8 mount option, which is not properly handled during UTF-8 to UTF-16 conversion.
ModificadaMedia (4.9)1.6%—Trevor Mckay CuminRedhat Enterprise MRG28/9/201216/6/2026
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to modify Condor attributes and possibly gain privileges via crafted additional parameters in an HTTP POST request, which triggers a job attribute change request to Condor.
ModificadaMedia (4.9)1.6%—Trevor Mckay CuminRedhat Enterprise MRG28/9/201216/6/2026
Session fixation vulnerability in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote attackers to hijack web sessions via a crafted session cookie.
ModificadaMedia (6.8)0.92%—Trevor Mckay CuminRedhat Enterprise MRG28/9/201216/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to hijack the authentication of arbitrary users for requests that execute commands via unspecified vectors.
ModificadaMedia (4)2.2%—Trevor Mckay CuminRedhat Enterprise MRG28/9/201216/6/2026
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allows remote authenticated users to cause a denial of service (memory consumption) via a large size in an image request.
ModificadaAlta (7.5)2.1%—Trevor Mckay CuminRedhat Enterprise MRG28/9/201216/6/2026
Multiple SQL injection vulnerabilities in the get_sample_filters_by_signature function in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to execute arbitrary SQL commands via the (1) agent or (2) object id.
ModificadaMedia (4.3)2.1%—Trevor Mckay CuminRedhat Enterprise MRG28/9/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) "error message displays" or (2) "in source HTML on certain pages."
ModificadaMedia (5.8)2.2%—Trevor Mckay CuminRedhat Enterprise MRG28/9/201216/6/2026
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, uses predictable random numbers to generate session keys, which makes it easier for remote attackers to guess the session key.
ModificadaMedia (5)2.3%—Trevor Mckay CuminRedhat Enterprise MRG28/9/201216/6/2026
Cumin before 0.1.5444, as used in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0, does not properly restrict access to resources, which allows remote attackers to obtain sensitive information via unspecified vectors related to (1) "web pages," (2) "export functionality," and (3) "image viewing."
ModificadaAlta (7.5)5.6%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRG24/5/201216/6/2026
The IPv6 implementation in the Linux kernel before 3.1 does not generate Fragment Identification values separately for each destination, which makes it easier for remote attackers to cause a denial of service (disrupted networking) by predicting these values and sending crafted packets.
ModificadaAlta (7.8)0.35%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRGSuse Linux Enterprise Desktop+217/5/201216/6/2026
The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace…
ModificadaMedia (5.5)0.40%—Linux KernelRedhat Enterprise MRGSuse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+117/5/201216/6/2026
The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO.
ModificadaAlta (7.5)18%💥 ExploitLinux KernelRedhat Enterprise LinuxRedhat Enterprise MRGCanonical Ubuntu Linux+110/10/201116/6/2026
net/core/net_namespace.c in the Linux kernel 2.6.32 and earlier does not properly handle a high rate of creation and cleanup of network namespaces, which makes it easier for remote attackers to cause a denial of service (memory consumption) via requests to a daemon that requires a separate namespace per connection, as…
ModificadaMedia (4.6)0.39%—Redhat Enterprise MRG20/9/201116/6/2026
Cumin in Red Hat Enterprise Messaging, Realtime, and Grid (MRG) 2.0 records broker authentication credentials in a log file, which allows local users to bypass authentication and perform unauthorized actions on jobs and message queues via a direct connection to the broker.
ModificadaAlta (7.1)2.5%—Linux KernelRedhat Enterprise MRGVmware ESX11/1/201116/6/2026
Race condition in the sctp_icmp_proto_unreachable function in net/sctp/input.c in Linux kernel 2.6.11-rc2 through 2.6.33 allows remote attackers to cause a denial of service (panic) via an ICMP unreachable message to a socket that is already locked by a user, which causes the socket to be freed and triggers list…
ModificadaAlta (7.5)1.8%—Redhat Enterprise MRG7/12/201016/6/2026
The installation documentation for Red Hat Enterprise Messaging, Realtime and Grid (MRG) 1.3 recommends that Condor should be configured so that the MRG Management Console (cumin) can submit jobs for users, which creates a trusted channel with insufficient access control that allows local users with the ability to…
ModificadaMedia (4)4.1%—Apache QpidRedhat Enterprise MRG18/10/201016/6/2026
The SessionAdapter::ExchangeHandlerImpl::checkAlternate function in broker/SessionAdapter.cpp in the C++ Broker component in Apache Qpid before 0.6, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote authenticated users to cause a denial of service (NULL pointer dereference, daemon crash,…
ModificadaMedia (5)5.9%—Apache QpidRedhat Enterprise MRG18/10/201016/6/2026
The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a denial of service (daemon crash and cluster outage) via invalid AMQP data.
ModificadaMedia (4)1.5%—Redhat Enterprise MRG12/10/201016/6/2026
lib/MessageStoreImpl.cpp in Red Hat Enterprise MRG before 1.2.2 allows remote authenticated users to cause a denial of service (stack memory exhaustion and broker crash) via a large persistent message.
ModificadaMedia (4.3)4.7%—Apache QpidRedhat Enterprise MRG12/10/201016/6/2026
sys/ssl/SslSocket.cpp in qpidd in Apache Qpid, as used in Red Hat Enterprise MRG before 1.2.2 and other products, when SSL is enabled, allows remote attackers to cause a denial of service (daemon outage) by connecting to the SSL port but not participating in an SSL handshake.
ModificadaMedia (6.5)2.1%—Condor Project CondorRedhat Enterprise MRG23/12/200916/6/2026
Condor 6.5.4 through 7.2.4, 7.3.x, and 7.4.0, as used in MRG, Grid for MRG, and Grid Execute Node for MRG, allows remote authenticated users to queue jobs as an arbitrary user, and thereby gain privileges, by using a Condor command-line tool to modify an unspecified job attribute.
Orbitaley — Vulnerabilidades