Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

92 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)5.9%—Linux KernelSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time ExtensionSuse Linux Enterprise Server+23/7/201417/6/2026
The sctp_association_free function in net/sctp/associola.c in the Linux kernel before 3.15.2 does not properly manage a certain backlog value, which allows remote attackers to cause a denial of service (socket outage) via a crafted SCTP packet.
ModificadaAlta (7.3)5.4%—Linux KernelOpensuseSuse Linux Enterprise Real Time ExtensionSuse Linux Enterprise Server+13/7/201417/6/2026
Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Literal Run. NOTE: the author of the LZO algorithms says "the…
ModificadaBaja (2.3)0.65%—Linux KernelRedhat Enterprise LinuxCanonical Ubuntu LinuxSuse Linux Enterprise Desktop+2223/6/201417/6/2026
The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator.
AnalizadaAlta (7.8)37%⚠ Explotación activa💥 ExploitLinux KernelRedhat Enterprise Linux Server AUSOpensuseSuse Linux Enterprise Desktop+57/6/201417/6/2026
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two different futex addresses, which allows local users to gain privileges via a crafted FUTEX_REQUEUE command that facilitates unsafe waiter modification.
ModificadaBaja (2.1)0.51%—Linux KernelRedhat Enterprise Linux EUSDebian LinuxOracle Linux+411/5/201417/6/2026
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.
ModificadaAlta (7.2)0.45%—Linux KernelOracle LinuxDebian LinuxSuse Linux Enterprise Desktop+411/5/201417/6/2026
The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.
ModificadaBaja (2.1)0.54%—Linux KernelOpensuse EvergreenRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+327/4/201417/6/2026
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a…
ModificadaAlta (7.8)4.3%—Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+33/1/201116/6/2026
Multiple integer underflows in the x25_parse_facilities function in net/x25/x25_facilities.c in the Linux kernel before 2.6.36.2 allow remote attackers to cause a denial of service (system crash) via malformed X.25 (1) X25_FAC_CLASS_A, (2) X25_FAC_CLASS_B, (3) X25_FAC_CLASS_C, or (4) X25_FAC_CLASS_D facility data, a…
ModificadaMedia (4.7)0.39%—Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+13/1/201116/6/2026
The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.36.2 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device.
ModificadaMedia (4.7)0.39%—Linux KernelFedoraproject FedoraOpensuseSuse Linux Enterprise Desktop+33/1/201116/6/2026
Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device.
ModificadaBaja (1.9)0.38%—Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+33/1/201116/6/2026
net/packet/af_packet.c in the Linux kernel before 2.6.37-rc2 does not properly initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory by leveraging the CAP_NET_RAW capability to read copies of the applicable structures.
ModificadaMedia (6.2)2.7%💥 ExploitLinux KernelFedoraproject FedoraOpensuseSuse Linux Enterprise Desktop+330/12/201016/6/2026
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3)…
ModificadaBaja (2.1)0.87%💥 ExploitLinux KernelFedoraproject FedoraOpensuseSuse Linux Enterprise Desktop+330/12/201016/6/2026
The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users to obtain potentially sensitive information from kernel stack memory…
ModificadaBaja (2.1)0.80%💥 ExploitLinux KernelSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time ExtensionSuse Linux Enterprise Server+330/12/201016/6/2026
The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADMIN capability, which allows local users to bypass intended access restrictions and configure econet addresses via an SIOCSIFADDR ioctl call.
ModificadaMedia (4.7)0.71%💥 ExploitLinux KernelSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time ExtensionSuse Linux Enterprise Server+330/12/201016/6/2026
The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a sendmsg call that specifies a NULL value for the remote address field.
ModificadaMedia (6.9)0.70%💥 ExploitLinux KernelSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time ExtensionSuse Linux Enterprise Server+330/12/201016/6/2026
Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2, when an econet address is configured, allows local users to gain privileges by providing a large number of iovec structures.
ModificadaMedia (4)0.40%—Linux KernelFedoraproject FedoraOpensuseSuse Linux Enterprise Desktop+329/12/201016/6/2026
Heap-based buffer overflow in the bcm_connect function in net/can/bcm.c (aka the Broadcast Manager) in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.36.2 on 64-bit platforms might allow local users to cause a denial of service (memory corruption) via a connect operation.
ModificadaMedia (6.9)2.2%💥 ExploitLinux KernelOpensuseSuse Linux Enterprise Real Time Extension22/12/201016/6/2026
The ACPI subsystem in the Linux kernel before 2.6.36.2 uses 0222 permissions for the debugfs custom_method file, which allows local users to gain privileges by placing a custom ACPI method in the ACPI interpreter tables, related to the acpi_debugfs_init function in drivers/acpi/debugfs.c.
ModificadaMedia (6.2)0.54%—Linux KernelFedoraproject FedoraOpensuseSuse Linux Enterprise Desktop+310/12/201016/6/2026
Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argument in an ioctl call.
ModificadaBaja (2.1)0.41%—Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+210/12/201016/6/2026
The ethtool_get_rxnfc function in net/core/ethtool.c in the Linux kernel before 2.6.36 does not initialize a certain block of heap memory, which allows local users to obtain potentially sensitive information via an ETHTOOL_GRXCLSRLALL ethtool command with a large info.rule_cnt value, a different vulnerability than…
AnalizadaAlta (7.8)16%⚠ Explotación activa💥 ExploitLinux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+46/12/201016/6/2026
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel before 2.6.36 does not properly validate addresses obtained from user space, which allows local users to gain privileges via crafted use of the sendmsg and recvmsg system calls.
ModificadaBaja (1.9)0.39%—Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+330/11/201016/6/2026
The copy_semid_to_user function in ipc/sem.c in the Linux kernel before 2.6.36 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via a (1) IPC_INFO, (2) SEM_INFO, (3) IPC_STAT, or (4) SEM_STAT command in a semctl system call.
ModificadaBaja (1.9)0.38%—Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+130/11/201016/6/2026
The viafb_ioctl_get_viafb_info function in drivers/video/via/ioctl.c in the Linux kernel before 2.6.36-rc5 does not properly initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via a VIAFB_GET_INFO ioctl call.
ModificadaBaja (1.9)0.39%—Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+330/11/201016/6/2026
The snd_hdspm_hwdep_ioctl function in sound/pci/rme9652/hdspm.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HDSPM_IOCTL_GET_CONFIG_INFO ioctl call.
ModificadaBaja (2.1)0.42%—Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+330/11/201016/6/2026
The snd_hdsp_hwdep_ioctl function in sound/pci/rme9652/hdsp.c in the Linux kernel before 2.6.36-rc6 does not initialize a certain structure, which allows local users to obtain potentially sensitive information from kernel stack memory via an SNDRV_HDSP_IOCTL_GET_CONFIG_INFO ioctl call.
Orbitaley — Vulnerabilidades