Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2829▼ 255 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
4215 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 8.3% | 💥 PoC | Linux KernelNetapp Active IQ Unified ManagerDebian Linux | 30/6/2023 | 17/6/2026 | A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system. | |
| Modificada | Alta (7.8) | 0.91% | 💥 PoC | Linux KernelNetapp H300sNetapp H410cNetapp H410s+2 | 28/6/2023 | 22/7/2026 | Se encontró una vulnerabilidad de use-after-free en el subsistema netfilter del kernel de Linux en net/netfilter/nf_tables_api.c. El manejo de errores mal manejado con NFT_MSG_NEWRULE permite usar un puntero colgante en la misma transacción que causa una vulnerabilidad de use-after-free. Esta falla permite que un… | |
| Modificada | Alta (7) | 0.22% | — | Linux KernelNetapp H300sNetapp H410cNetapp H410s+2 | 28/6/2023 | 17/6/2026 | A time-of-check to time-of-use issue exists in io_uring subsystem's IORING_OP_CLOSE operation in the Linux kernel's versions 5.6 - 5.11 (inclusive), which allows a local user to elevate their privileges to root. Introduced in b5dba59e0cf7e2cc4d3b3b1ac5fe81ddf21959eb, patched in… | |
| Modificada | Media (4.4) | 0.26% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+5 | 23/6/2023 | 17/6/2026 | A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic. | |
| Modificada | Alta (7.5) | 2.5% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+5 | 21/6/2023 | 17/6/2026 | If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly due to a stack overflow. This issue affects BIND 9 versions 9.16.33… | |
| Modificada | Alta (7.5) | 0.88% | — | ISC BindNetapp Active IQ Unified ManagerNetapp H500s FirmwareNetapp H700s Firmware+3 | 21/6/2023 | 17/6/2026 | A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone with a malformed NSEC record. This issue affects BIND 9 versions 9.16.8-S1 through 9.16.41-S1 and… | |
| Modificada | Alta (7.5) | 3.6% | — | ISC BindDebian LinuxFedoraproject FedoraNetapp Active IQ Unified Manager+5 | 21/6/2023 | 17/6/2026 | Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-cache-size` statement in the configuration file; it defaults to 90% of… | |
| Modificada | Alta (8.8) | 1.3% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | Attackers with access to the "documentconverterws" API were able to inject serialized Java objects, that were not properly checked during deserialization. Access to this API endpoint is restricted to local networks by default. Arbitrary code could be injected that is being executed when processing the request. A check… | |
| Modificada | Media (5) | 0.78% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topology and services as well as including local files with read permissions of the open-xchange system user. This was limited to specific… | |
| Modificada | Media (4.3) | 1.1% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted POP3 server response to reasonable… | |
| Modificada | Media (4.3) | 1.1% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted IMAP server response to reasonable… | |
| Modificada | Media (4.3) | 1.1% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | When adding an external mail account, processing of SMTP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue SMTP service could trigger requests that lead to excessive resource usage and eventually service unavailability. We now limit accepted SMTP server response to reasonable… | |
| Modificada | Media (4.3) | 0.84% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | IPv4-mapped IPv6 addresses did not get recognized as "local" by the code and a connection attempt is made. Attackers with access to user accounts could use this to bypass existing deny-list functionality and trigger requests to restricted network infrastructure to gain insight about topology and running services. We… | |
| Modificada | Media (5.3) | 0.79% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | Control characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedback and potentially break the exported data structure. We now drop all control characters that are not whitespace character during the export. No publicly available exploits are… | |
| Modificada | Media (6.5) | 0.98% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | Attackers can successfully request arbitrary snippet IDs, including E-Mail signatures of other users within the same context. Signatures of other users could be read even though they are not explicitly shared. We improved permission handling when requesting snippets that are not explicitly shared with other users. No… | |
| Modificada | Baja (3.3) | 0.33% | — | Open-xchange Appsuite Backend | 20/6/2023 | 17/6/2026 | Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during package installation. No publicly available exploits are known. | |
| Modificada | Alta (7) | 0.43% | — | Linux KernelNetapp H300sNetapp H410sNetapp H500s+1 | 18/6/2023 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in rkvdec_remove in drivers/staging/media/rkvdec/rkvdec.c. | |
| Modificada | Alta (7) | 0.53% | 💥 PoC | Linux KernelNetapp H300sNetapp H410cNetapp H410s+2 | 18/6/2023 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in renesas_usb3_remove in drivers/usb/gadget/udc/renesas_usb3.c. | |
| Modificada | Alta (7) | 0.25% | — | Linux KernelNetapp H300sNetapp H410cNetapp H410s+2 | 18/6/2023 | 17/6/2026 | An issue was discovered in the Linux kernel before 6.3.2. A use-after-free was found in cedrus_remove in drivers/staging/media/sunxi/cedrus/cedrus.c. | |
| Modificada | Alta (7.8) | 0.53% | 💥 PoC | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+4 | 16/6/2023 | 17/6/2026 | Se descubrió un problema en fl_set_geneve_opt en net/sched/cls_flower.c en el kernel de Linux antes de 6.3.7. Permite una escritura fuera de los límites en el código flower classifier a través de paquetes TCA_FLOWER_KEY_ENC_OPTS_GENEVE. Esto puede resultar en denegación de servicio o escalada de privilegios. | |
| Modificada | Alta (7.1) | 0.44% | — | Linux KernelNetapp HCI Baseboard Management ControllerDebian Linux | 9/6/2023 | 17/6/2026 | A use-after-free flaw was found in r592_remove in drivers/memstick/host/r592.c in media access in the Linux Kernel. This flaw allows a local attacker to crash the system at device disconnect, possibly leading to a kernel information leak. | |
| Modificada | Alta (7.8) | 0.44% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H410c Firmware+3 | 5/6/2023 | 17/6/2026 | A use after free vulnerability was found in prepare_to_relocate in fs/btrfs/relocation.c in btrfs in the Linux Kernel. This possible flaw can be triggered by calling btrfs_ioctl_balance() before calling btrfs_ioctl_defrag(). | |
| Modificada | Alta (7.8) | 1.4% | 💥 PoC | Linux KernelNetapp HCI Baseboard Management Controller | 1/6/2023 | 17/6/2026 | Se encontró una falla en el código de registro de búfer fijo para io_uring (io_sqe_buffer_register en io_uring/rsrc.c) en el kernel de Linux que permite el acceso fuera de los límites a la memoria física más allá del final del búfer. Esta falla permite la escalada completa de privilegios locales. | |
| Modificada | Alta (7.1) | 0.52% | — | Linux KernelNetapp H300sNetapp H410cNetapp H410s+2 | 31/5/2023 | 17/6/2026 | Se ha descubierto un problema en el kernel de Linux en las versiones anteriores a v6.2. El subsistema "ntfs3" no comprueba correctamente la corrección durante las lecturas de disco, lo que provoca una lectura fuera de los límites en "ntfs_set_ea" en "fs/ntfs3/xattr.c". | |
| Modificada | Alta (7.5) | 1.9% | — | OpenldapRedhat Enterprise LinuxApple MacosNetapp Active IQ Unified Manager+7 | 30/5/2023 | 17/6/2026 | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. |