Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
64 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.90% | — | Redhat Enterprise Virtualization Manager | 4/1/2013 | 16/6/2026 | The vds_installer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, uses the -k curl parameter when downloading deployUtil.py and vds_bootstrap.py, which prevents SSL certificates from being validated and allows remote attackers to execute arbitrary Python code via a… | |
| Modificada | Media (6.2) | 0.40% | — | Redhat Enterprise Virtualization Manager | 4/1/2013 | 16/6/2026 | Multiple untrusted search path vulnerabilities in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, when adding a host, allow local users to gain privileges via a Trojan horse (1) deployUtil.py or (2) vds_bootstrap.py Python module in /tmp/. | |
| Modificada | Baja (3.7) | 0.33% | — | Redhat Enterprise Virtualization Manager | 4/1/2013 | 16/6/2026 | Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the desktop screen between SPICE sessions, which allows local users with access to a virtual machine to gain access to other users' desktop sessions via unspecified vectors. | |
| Modificada | Media (5.7) | 0.99% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Virtualization Hypervisor | 31/8/2011 | 16/6/2026 | The Generic Receive Offload (GRO) implementation in the Linux kernel 2.6.18 on Red Hat Enterprise Linux 5 and 2.6.32 on Red Hat Enterprise Linux 6, as used in Red Hat Enterprise Virtualization (RHEV) Hypervisor and other products, allows remote attackers to cause a denial of service via crafted VLAN packets that are… | |
| Modificada | Media (6.8) | 1.0% | — | Redhat Spice-activexRedhat Enterprise Virtualization Manager | 8/12/2010 | 16/6/2026 | Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of… | |
| Modificada | Media (5.7) | 1.00% | — | Redhat Enterprise Virtualization | 24/8/2010 | 16/6/2026 | Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization (RHEV) 2.2 does not properly accept TCP connections for SSL sessions, which allows remote attackers to cause a denial of service (daemon outage) via crafted SSL traffic. | |
| Modificada | Media (6.6) | 0.28% | — | Redhat Enterprise VirtualizationRedhat KVM | 24/8/2010 | 16/6/2026 | The subpage MMIO initialization functionality in the subpage_register function in exec.c in QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly select the index for access to the callback array, which allows guest OS users to cause a… | |
| Modificada | Media (4.6) | 0.36% | — | Redhat Enterprise VirtualizationRedhat KVM | 24/8/2010 | 16/6/2026 | The Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2, and KVM 83, when the Intel VT-x extension is enabled, allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via vectors related to instruction emulation. | |
| Modificada | Media (6.6) | 0.31% | — | Redhat Enterprise VirtualizationRedhat KVM | 24/8/2010 | 16/6/2026 | QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain privileges via… | |
| Modificada | Media (6.6) | 0.31% | — | Redhat Enterprise VirtualizationRedhat Qspice | 24/8/2010 | 16/6/2026 | libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly restrict the addresses upon which memory-management actions are performed, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain… | |
| Modificada | Media (6.6) | 0.31% | — | Redhat Enterprise VirtualizationRedhat Qspice | 24/8/2010 | 16/6/2026 | libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain… | |
| Modificada | Baja (2.1) | 0.33% | — | Redhat Enterprise Virtualization Manager | 24/6/2010 | 16/6/2026 | The snapshot merging functionality in Red Hat Enterprise Virtualization Manager (aka RHEV-M) before 2.2 does not properly pass the postzero parameter during operations on deleted volumes, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine. | |
| Modificada | Baja (2.1) | 0.37% | — | Redhat Enterprise Virtualization Hypervisor | 24/6/2010 | 16/6/2026 | Virtual Desktop Server Manager (VDSM) in Red Hat Enterprise Virtualization Hypervisor (aka RHEV-H or rhev-hypervisor) before 5.5-2.2 does not properly perform VM post-zeroing after the removal of a virtual machine's data, which allows guest OS users to obtain sensitive information by examining the disk blocks… | |
| Modificada | Alta (10) | 4.5% | — | Redhat Enterprise VirtualizationJasper Project Jasper | 2/10/2008 | 16/6/2026 | Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf. |