Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
–

62 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.3%—Opensuse Obs-service-source Validator1/3/201817/6/2026
A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs.
ModificadaAlta (7)0.48%—Redhat Hibernate ValidatorRedhat SatelliteRedhat Satellite CapsuleRedhat Jboss Enterprise Application Platform+210/1/201817/6/2026
In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access…
ModificadaMedia (6.5)2.4%—Matroska Libebml2Matroska MkcleanMatroska Mkvalidator10/11/201717/6/2026
The EBML_IntegerValue function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.
ModificadaMedia (6.5)2.4%—Matroska Libebml2Matroska MkcleanMatroska Mkvalidator10/11/201717/6/2026
The UpdateDataSize function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.
ModificadaMedia (6.5)2.4%—Matroska Libebml2Matroska MkcleanMatroska Mkvalidator10/11/201717/6/2026
The EBML_FindNextElement function in ebmlmain.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.
ModificadaMedia (6.5)2.4%—Matroska Libebml2Matroska MkcleanMatroska Mkvalidator10/11/201717/6/2026
The ReadDataFloat function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.
ModificadaMedia (6.5)2.4%—Matroska Libebml2Matroska MkcleanMatroska Mkvalidator10/11/201717/6/2026
The ReadData function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file.
ModificadaMedia (6.5)2.4%—Matroska Libebml2Matroska MkcleanMatroska Mkvalidator10/11/201717/6/2026
The EBML_BufferToID function in ebmlelement.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.
ModificadaMedia (6.5)2.4%—Matroska Libebml2Matroska MkcleanMatroska Mkvalidator10/11/201717/6/2026
The ReadData function in ebmlstring.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted mkv file.
ModificadaMedia (6.5)2.2%—Matroska Mkvalidator10/11/201717/6/2026
The Node_GetData function in corec/corec/node/node.c in mkvalidator 0.5.1 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file.
ModificadaMedia (5)2.9%—Redhat Hibernate Validator30/9/201417/6/2026
ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application.
ModificadaAlta (7.8)1.7%—Broadcom Erwin Data Model Validator11/7/200716/6/2026
CA ERwin Data Model Validator (formerly AllFusion Data Model Validator) allows remote attackers to (1) cause a denial of service (application hang) via a malformed .EXP database file and (2) cause a denial of service (aaplication crash) via a crafted .EXP database file, which triggers a NULL dereference.