Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

87 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)2.8%—Debian LinuxRedhat Enterprise Linux ServerGlusterfsRedhat Virtualization Host+14/9/201817/6/2026
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.
ModificadaAlta (8.8)2.6%—Redhat Virtualization HostDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Server+24/9/201817/6/2026
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs server node.
ModificadaAlta (8.1)1.7%—GlusterfsRedhat Virtualization HostDebian LinuxRedhat Enterprise Linux Server+14/9/201817/6/2026
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.
ModificadaMedia (6.5)2.4%—GlusterfsRedhat Virtualization HostRedhat Enterprise Linux ServerDebian Linux+14/9/201817/6/2026
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.
ModificadaMedia (6.5)2.1%—GlusterfsRedhat Virtualization HostDebian LinuxRedhat Enterprise Linux Server+14/9/201817/6/2026
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
ModificadaAlta (7.5)3.1%—GlusterfsRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+34/9/201817/6/2026
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
ModificadaAlta (8.8)3.4%—GlusterfsRedhat Virtualization HostRedhat Enterprise Linux ServerDebian Linux+14/9/201817/6/2026
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause…
ModificadaAlta (8.8)3.0%—GlusterfsRedhat Virtualization HostRedhat Enterprise Linux ServerDebian Linux+14/9/201817/6/2026
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the…
ModificadaAlta (8.8)4.3%—Debian LinuxCanonical Ubuntu LinuxSambaRedhat Virtualization+422/8/201817/6/2026
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
ModificadaAlta (8.8)3.9%—Spice Project SpiceDebian LinuxCanonical Ubuntu LinuxRedhat Virtualization+717/8/201817/6/2026
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
ModificadaAlta (7.8)0.59%—Redhat Ansible EngineRedhat Ceph StorageRedhat Gluster StorageRedhat Openshift+613/7/201817/6/2026
A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.
ModificadaAlta (7.8)0.49%—Redhat Ansible EngineRedhat OpenstackRedhat VirtualizationRedhat Virtualization Host2/7/201817/6/2026
In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.
ModificadaMedia (5.3)7.2%—Linux KernelRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+320/6/201817/6/2026
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from psutils or procps (such as ps, w) or any other program which makes a read() call to the…
ModificadaMedia (5.3)1.9%—Ovirt-engineRedhat VirtualizationRedhat Virtualization Host19/6/201817/6/2026
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts.
ModificadaAlta (7.8)0.35%—Google AndroidRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+212/6/201817/6/2026
In the function wmi_set_ie(), the length validation code does not handle unsigned integer overflow properly. As a result, a large value of the 'ie_len' argument can cause a buffer overflow in all Android releases from CAF (Android for MSM, Firefox OS for MSM, QRD Android) using the Linux Kernel.
ModificadaMedia (5.5)0.84%—Linux KernelDebian LinuxRedhat Virtualization HostRedhat Enterprise Linux Desktop+212/6/201817/6/2026
In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash.
ModificadaMedia (6.1)1.8%—Redhat UndertowRedhat Jboss Enterprise Application PlatformRedhat Virtualization Host21/5/201817/6/2026
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an…
ModificadaAlta (7.8)0.88%—GNU GlibcRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+618/5/201817/6/2026
An AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data beyond the target buffer, leading to a buffer overflow in __mempcpy_avx512_no_vzeroupper.
ModificadaCrítica (9.8)7.1%—GNU GlibcRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+518/5/201817/6/2026
stdlib/canonicalize.c in the GNU C Library (aka glibc or libc6) 2.27 and earlier, when processing very long pathname arguments to the realpath function, could encounter an integer overflow on 32-bit architectures, leading to a stack-based buffer overflow and, potentially, arbitrary code execution.
ModificadaAlta (7.5)98%—Fedoraproject FedoraRedhat Enterprise VirtualizationRedhat Enterprise Virtualization HostRedhat Enterprise Linux+317/5/201817/6/2026
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an attacker on the local network able to spoof DHCP responses, could use this flaw to execute arbitrary…
ModificadaMedia (5.5)0.38%—Linux KernelDebian LinuxCanonical Ubuntu LinuxRedhat Virtualization Host+310/5/201817/6/2026
Linux kernel vhost since version 4.8 does not properly initialize memory in messages passed between virtual guests and the host operating system in the vhost/vhost.c:vhost_new_msg() function. This can allow local privileged users to read some kernel memory contents when reading from the /dev/vhost-net device file.
ModificadaAlta (7.8)0.45%—Linux KernelRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+52/5/201817/6/2026
The do_get_mempolicy function in mm/mempolicy.c in the Linux kernel before 4.12.9 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted system calls.
ModificadaMedia (5.9)5.1%—Google GuavaRedhat Openshift Container PlatformRedhat OpenstackRedhat Satellite+1326/4/201817/6/2026
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the…
ModificadaMedia (5.5)0.48%—Linux KernelRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+124/4/201817/6/2026
The xfs_dinode_verify function in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_ilock_attr_map_shared invalid pointer dereference) via a crafted xfs image.
ModificadaAlta (8.1)5.5%—Redhat Gluster StorageRedhat VirtualizationRedhat Virtualization HostRedhat Enterprise Linux Server+218/4/201817/6/2026
A privilege escalation flaw was found in gluster 3.x snapshot scheduler. Any gluster client allowed to mount gluster volumes could also mount shared gluster storage volume and escalate privileges by scheduling malicious cronjob via symlink.