Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
88 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.6) | 2.6% | — | Oracle JDKOracle JREDebian LinuxRedhat Satellite+22 | 8/8/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Crítica (9.6) | 2.1% | — | Oracle JDKOracle JREDebian LinuxNetapp Active IQ Unified Manager+15 | 8/8/2017 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u141 and 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human… | |
| Modificada | Media (4.3) | 2.2% | — | Oracle JDKOracle JREDebian LinuxNetapp Active IQ Unified Manager+15 | 8/8/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (8.1) | 2.4% | — | Oracle JDKOracle JREDebian LinuxRedhat Satellite+23 | 8/8/2017 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Scripting). The supported version that is affected is Java SE: 8u131. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can… | |
| Modificada | Alta (8.3) | 3.1% | — | Oracle JDKOracle JREDebian LinuxRedhat Enterprise Linux Desktop+21 | 8/8/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.5) | 3.3% | — | Oracle JDKOracle JREDebian LinuxRedhat Satellite+22 | 8/8/2017 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require… | |
| Modificada | Media (5.3) | 3.5% | — | Oracle JDKOracle JREOracle JrockitDebian Linux+24 | 8/8/2017 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: 2D). Supported versions that are affected are Java SE: 6u151, 7u141 and 8u131; Java SE Embedded: 8u131; JRockit: R28.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple… | |
| Modificada | Crítica (9.8) | 82% | — | NTPDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+3 | 7/8/2017 | 17/6/2026 | Crypto-NAK packets in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to bypass authentication. | |
| Modificada | Media (6.5) | 31% | 💥 Exploit | NTPDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+5 | 7/8/2017 | 17/6/2026 | The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (assertion failure) via a 6 or mode 7 packet containing a long data value. | |
| Modificada | Alta (8.8) | 15% | — | NTPNetapp Oncommand BalanceNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+2 | 7/8/2017 | 17/6/2026 | Buffer overflow in the password management functionality in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted key file. | |
| Modificada | Crítica (9.8) | 12% | — | NTPNetapp Oncommand BalanceNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+2 | 7/8/2017 | 17/6/2026 | The datalen parameter in the refclock driver in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a negative input value. | |
| Modificada | Media (5.9) | 12% | — | NTPDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+10 | 7/8/2017 | 17/6/2026 | ntpq in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted mode 6 response packets. | |
| Modificada | Media (6.5) | 5.6% | — | NTPDebian LinuxNetapp Oncommand BalanceNetapp Oncommand Performance Manager+3 | 7/8/2017 | 17/6/2026 | ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to cause a denial of service (infinite loop or crash) by pointing the key file at the log file. | |
| Modificada | Alta (8.8) | 17% | — | NTPNetapp Oncommand BalanceNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+2 | 7/8/2017 | 17/6/2026 | Use-after-free vulnerability in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote authenticated users to possibly execute arbitrary code or cause a denial of service (crash) via crafted packets. | |
| Modificada | Crítica (9.8) | 12% | — | NTPNetapp Oncommand Performance ManagerNetapp Oncommand Unified ManagerNetapp Clustered Data Ontap+4 | 7/8/2017 | 17/6/2026 | The rate limiting feature in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to have unspecified impact via a large number of crafted requests. | |
| Modificada | Alta (7.5) | 11% | — | NTPDebian LinuxNetapp Oncommand Performance ManagerNetapp Oncommand Unified Manager+10 | 7/8/2017 | 17/6/2026 | The ntpd client in NTP 4.x before 4.2.8p4 and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service via a number of crafted "KOD" messages. | |
| Modificada | Media (6.5) | 5.2% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 7/8/2017 | 17/6/2026 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750. | |
| Modificada | Alta (7.5) | 6.5% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 7/8/2017 | 17/6/2026 | Memory leak in the CRYPTO_ASSOC function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (memory consumption). | |
| Modificada | Alta (7.5) | 6.5% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 7/8/2017 | 17/6/2026 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash). NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750. | |
| Modificada | Alta (7.5) | 7.1% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 7/8/2017 | 17/6/2026 | The crypto_xmit function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause a denial of service (crash) via crafted packets containing particular autokey operations. NOTE: This vulnerability exists due to an incomplete fix for CVE-2014-9750. | |
| Modificada | Alta (7.5) | 3.8% | — | NTPOracle LinuxDebian LinuxNetapp Oncommand Performance Manager+9 | 24/7/2017 | 17/6/2026 | The "pidfile" or "driftfile" directives in NTP ntpd 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77, when ntpd is configured to allow remote configuration, allows remote attackers with an IP address that is allowed to send configuration requests, and with knowledge of the remote configuration password to write to… | |
| Modificada | Crítica (9.8) | 7.5% | — | ZlibOpensuse LeapOpensuseDebian Linux+35 | 23/5/2017 | 14/7/2026 | inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic. | |
| Modificada | Alta (7.1) | 2.8% | — | Littlecms Little CMS Color EngineCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+15 | 3/2/2017 | 17/6/2026 | The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read. | |
| Modificada | Media (5.3) | 15% | — | NTPDebian LinuxNetapp Clustered Data OntapNetapp Data Ontap+13 | 30/1/2017 | 17/6/2026 | The MATCH_ASSOC function in NTP before version 4.2.8p9 and 4.3.x before 4.3.92 allows remote attackers to cause an out-of-bounds reference via an addpeer request with a large hmode value. | |
| Analizada | Alta (7.5) | 6.1% | — | Netapp Clustered Data OntapNetapp Data Ontap Operating IN 7-modeNetapp Oncommand BalanceNetapp Oncommand Performance Manager+2 | 6/1/2017 | 17/6/2026 | An integer overflow can occur in NTP-dev.4.3.70 leading to an out-of-bounds memory copy operation when processing a specially crafted private mode packet. The crafted packet needs to have the correct message authentication code and a valid timestamp. When processed by the NTP daemon, it leads to an immediate crash. |