Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.3% | — | Opensuse Obs-service-source Validator | 1/3/2018 | 17/6/2026 | A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs. | |
| Modificada | Alta (7) | 0.48% | — | Redhat Hibernate ValidatorRedhat SatelliteRedhat Satellite CapsuleRedhat Jboss Enterprise Application Platform+2 | 10/1/2018 | 17/6/2026 | In Hibernate Validator 5.2.x before 5.2.5 final, 5.3.x, and 5.4.x, it was found that when the security manager's reflective permissions, which allows it to access the private members of the class, are granted to Hibernate Validator, a potential privilege escalation can occur. By allowing the calling code to access… | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The EBML_IntegerValue function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The UpdateDataSize function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The EBML_FindNextElement function in ebmlmain.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The ReadDataFloat function in ebmlnumber.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The ReadData function in ebmlmaster.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (assert fault) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The EBML_BufferToID function in ebmlelement.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.4% | — | Matroska Libebml2Matroska MkcleanMatroska Mkvalidator | 10/11/2017 | 17/6/2026 | The ReadData function in ebmlstring.c in libebml2 through 2012-08-26 allows remote attackers to cause a denial of service (invalid free and application crash) via a crafted mkv file. | |
| Modificada | Media (6.5) | 2.2% | — | Matroska Mkvalidator | 10/11/2017 | 17/6/2026 | The Node_GetData function in corec/corec/node/node.c in mkvalidator 0.5.1 allows remote attackers to cause a denial of service (Null pointer dereference and application crash) via a crafted mkv file. | |
| Modificada | Media (5) | 2.9% | — | Redhat Hibernate Validator | 30/9/2014 | 17/6/2026 | ReflectionHelper (org.hibernate.validator.util.ReflectionHelper) in Hibernate Validator 4.1.0 before 4.2.1, 4.3.x before 4.3.2, and 5.x before 5.1.2 allows attackers to bypass Java Security Manager (JSM) restrictions and execute restricted reflection calls via a crafted application. | |
| Modificada | Alta (7.8) | 1.7% | — | Broadcom Erwin Data Model Validator | 11/7/2007 | 16/6/2026 | CA ERwin Data Model Validator (formerly AllFusion Data Model Validator) allows remote attackers to (1) cause a denial of service (application hang) via a malformed .EXP database file and (2) cause a denial of service (aaplication crash) via a crafted .EXP database file, which triggers a NULL dereference. |