Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1353 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 12% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js+15 | 30/10/2018 | 17/6/2026 | The OpenSSL DSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.1a (Affected 1.1.1). Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.0.2q (Affected… | |
| Modificada | Media (5.9) | 4.7% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js+18 | 29/10/2018 | 17/6/2026 | The OpenSSL ECDSA signature algorithm has been shown to be vulnerable to a timing side channel attack. An attacker could use variations in the signing algorithm to recover the private key. Fixed in OpenSSL 1.1.0j (Affected 1.1.0-1.1.0i). Fixed in OpenSSL 1.1.1a (Affected 1.1.1). | |
| Modificada | Alta (7.5) | 2.8% | — | Nodejs Node.js | 21/8/2018 | 17/6/2026 | In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory. This method is intended to be safe and only return initialized, or cleared, memory. The third argument specifying `encoding` can be passed as a number, this is misinterpreted by… | |
| Modificada | Alta (7.5) | 8.1% | — | Nodejs Node.jsRedhat Openshift Container Platform | 21/8/2018 | 17/6/2026 | In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to write outside of the bounds of a single `Buffer`. Writes that start from the second-to-last position… | |
| Modificada | Media (5.4) | 0.81% | — | HP Network Node Manager I | 6/8/2018 | 17/6/2026 | A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS). | |
| Modificada | Media (5.4) | 0.81% | — | HP Network Node Manager I | 6/8/2018 | 17/6/2026 | A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS). | |
| Modificada | Alta (8.8) | 4.8% | — | HP Network Node Manager I | 6/8/2018 | 17/6/2026 | A remote arbitrary code execution vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10 using Java Deserialization. | |
| Modificada | Alta (7.8) | 1.0% | — | HP Network Node Manager I | 6/8/2018 | 17/6/2026 | A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software. | |
| Modificada | Media (5.6) | 8.6% | — | Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+221 | 10/7/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis. | |
| Modificada | Alta (8.2) | 0.56% | — | Intel Converged Security Management Engine FirmwareNetapp Element Software Management Node | 10/7/2018 | 17/6/2026 | Logic bug in Intel Converged Security Management Engine 11.x may allow an attacker to execute arbitrary code via local privileged access. | |
| Modificada | Crítica (9.8) | 6.7% | 💥 PoC | Node-macaddress Project Node-macaddress | 10/7/2018 | 17/6/2026 | The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call. | |
| Modificada | Crítica (9.8) | 19% | — | Eclipse JettyDebian LinuxOracle Rest Data ServicesOracle Retail Xstore Payment+15 | 26/6/2018 | 17/6/2026 | In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC… | |
| Modificada | Crítica (9.8) | 15% | — | Eclipse JettyDebian LinuxNetapp E-series Santricity ManagementNetapp E-series Santricity OS Controller+13 | 26/6/2018 | 17/6/2026 | In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk… | |
| Modificada | Alta (7.5) | 0.89% | — | Intchain Node Token | 25/6/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tradeTrap" issue. | |
| Modificada | Alta (7.5) | 0.89% | — | Intchain Node Token | 25/6/2018 | 17/6/2026 | The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the… | |
| Modificada | Alta (7.5) | 7.1% | — | Nodejs Node.js | 13/6/2018 | 17/6/2026 | Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x… | |
| Modificada | Alta (7.5) | 6.4% | — | Nodejs Node.js | 13/6/2018 | 17/6/2026 | Node.js versions 9.7.0 and later and 10.x are vulnerable and the severity is MEDIUM. A bug introduced in 9.7.0 increases the memory consumed when reading from the network into JavaScript using the net.Socket object directly as a stream. An attacker could use this cause a denial of service by sending tiny chunks of… | |
| Modificada | Alta (7.5) | 6.9% | — | Nodejs Node.js | 13/6/2018 | 17/6/2026 | All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http server supporting TLS server to crash. This can be accomplished by sending duplicate/unexpected messages during the handshake. This… | |
| Modificada | Alta (7.5) | 7.8% | — | Nodejs Node.js | 13/6/2018 | 17/6/2026 | All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 server to crash. This can be accomplished by interacting with the http2 server in a manner that triggers a cleanup bug where objects are used… | |
| Modificada | Alta (7.5) | 49% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js | 12/6/2018 | 17/6/2026 | During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. This could be exploited… | |
| Modificada | Media (6.5) | 8.6% | 💥 Exploit | Node-srv Project Node-srv | 7/6/2018 | 17/6/2026 | node-srv node module suffers from a Path Traversal vulnerability due to lack of validation of url, which allows a malicious user to read content of any file with known path. | |
| Modificada | Alta (7.5) | 2.0% | — | Nodeaaaaa Project Nodeaaaaa | 7/6/2018 | 17/6/2026 | nodeaaaaa is a static file server. nodeaaaaa is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (7.5) | 2.0% | — | Caolilinode Project Caolilinode | 7/6/2018 | 17/6/2026 | caolilinode is a simple file server. caolilinode is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (7.5) | 2.0% | — | Node-server-forfront Project Node-server-forfront | 7/6/2018 | 17/6/2026 | node-server-forfront is a simple static file server. node-server-forfront is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Alta (7.5) | 2.0% | — | Node-simple-router | 7/6/2018 | 17/6/2026 | node-simple-router is a minimalistic router for Node. node-simple-router is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the URL. |