Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2759▼ 357 respecto a la semana anterior
Críticas / altas1278▼ 254 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
5546 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.6) | 0.45% | — | Debian LinuxFedoraproject FedoraNeovimVIM | 4/3/2023 | 18/9/2026 | Incorrect Calculation of Buffer Size in GitHub repository vim/vim prior to 9.0.1378. | |
| Analizada | Media (6.6) | 0.50% | — | Fedoraproject FedoraNeovimVIM | 3/3/2023 | 18/9/2026 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1376. | |
| Modificada | Media (5.5) | 0.43% | — | Fedoraproject FedoraLibtiff | 3/3/2023 | 17/6/2026 | LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125. | |
| Modificada | Baja (3.7) | 0.62% | — | PostgresqlFedoraproject FedoraRedhat Integration Camel KRedhat Integration Camel Quarkus+2 | 3/3/2023 | 17/6/2026 | In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes. | |
| Modificada | Alta (8.8) | 1.1% | — | WebkitgtkFedoraproject Fedora | 2/3/2023 | 17/6/2026 | A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely. | |
| Modificada | Alta (7.8) | 0.46% | — | VIMFedoraproject Fedora | 1/3/2023 | 17/6/2026 | Divide By Zero in GitHub repository vim/vim prior to 9.0.1367. | |
| Modificada | Alta (7.2) | 1.7% | — | Sudo Project SudoFedoraproject Fedora | 28/2/2023 | 17/6/2026 | Sudo before 1.9.13p2 has a double free in the per-command chroot feature. | |
| Modificada | Media (5.5) | 0.31% | — | Golang ImageGolang TiffFedoraproject Fedora | 28/2/2023 | 17/6/2026 | An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service. | |
| Modificada | Media (5.5) | 0.19% | — | Redhat Directory ServerFedoraproject Fedora | 27/2/2023 | 17/6/2026 | A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed… | |
| Modificada | Media (6.5) | 1.7% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp H300s Firmware+5 | 23/2/2023 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain"… | |
| Modificada | Alta (7.5) | 1.2% | — | Gnome EpiphanyFedoraproject Fedora | 20/2/2023 | 17/6/2026 | In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts. | |
| Modificada | Alta (7.5) | 20% | 💥 PoC | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+2 | 17/2/2023 | 17/6/2026 | Un problema en el componente urllib.parse de Python anterior a 3.11.4 permite a los atacantes eludir los métodos de listas de bloqueo proporcionando una URL que comienza con caracteres en blanco. | |
| Modificada | Alta (7.4) | 1.4% | — | GnutlsRedhat Enterprise LinuxDebian LinuxFedoraproject Fedora+3 | 15/2/2023 | 17/6/2026 | A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount… | |
| Modificada | Media (6.5) | 1.3% | — | Paloaltonetworks Cortex XsoarFedoraproject Fedora | 8/2/2023 | 17/6/2026 | A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server. | |
| Modificada | Alta (7.5) | 1.4% | — | GNU LessFedoraproject Fedora | 7/2/2023 | 17/6/2026 | In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal. | |
| Modificada | Alta (7.5) | 1.8% | — | Harfbuzz Project HarfbuzzFedoraproject Fedora | 4/2/2023 | 17/6/2026 | hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks. | |
| Modificada | Media (6.5) | 90% | 💥 PoC | Openbsd OpensshFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp A250 Firmware+2 | 3/2/2023 | 17/6/2026 | OpenSSH server (sshd) v9.1 introdujo una vulnerabilidad de doble liberación durante el manejo de "options.key_algorithms". Esto se ha corregido en OpenSSH v9.2. La doble liberación puede ser aprovechada por un atacante remoto no autenticado en la configuración por defecto, para saltar a cualquier ubicación en el… | |
| Modificada | Media (5.5) | 0.25% | — | Pesign Project PesignFedoraproject FedoraRedhat Enterprise Linux | 2/2/2023 | 17/6/2026 | A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This… | |
| Modificada | Alta (8.8) | 0.95% | — | Fedoraproject SssdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+9 | 1/2/2023 | 17/6/2026 | sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters | |
| Modificada | Media (5.5) | 1.5% | — | GNU TARFedoraproject Fedora | 30/1/2023 | 17/6/2026 | GNU Tar hasta 1.34 tiene una lectura fuera de los límites de un byte que resulta en el uso de memoria no inicializada para un salto condicional. No se ha demostrado explotación para cambiar el flujo de control. El problema ocurre en from_header en list.c a través de un archivo V7 en el que mtime tiene aproximadamente… | |
| Modificada | Media (5.5) | 0.44% | — | GNU BinutilsFedoraproject FedoraRedhat Enterprise Linux | 27/1/2023 | 17/6/2026 | Se encontró una falla de acceso ilegal a la memoria en el paquete binutils. El parseo de un archivo ELF que contiene información de versión de símbolo corrupta puede resultar en una denegación de servicio. Este problema es el resultado de una solución incompleta para CVE-2020-16599. | |
| Analizada | Alta (7.8) | 0.52% | — | Apple MacosFedoraproject FedoraNeovimVIM | 21/1/2023 | 24/9/2026 | Desbordamiento de búfer de almacenamiento dinámico en el repositorio de GitHub vim/vim anterior a 9.0.1225. | |
| Modificada | Alta (7.8) | 0.39% | — | Xiph OpusfileFedoraproject Fedora | 20/1/2023 | 17/6/2026 | Se descubrió un problema de desreferencia de puntero null en las funciones op_get_data y op_open1 en opusfile.c en xiph opusfile 0.9 a 0.12 que permite a los atacantes causar denegación de servicio u otros impactos no especificados. | |
| Modificada | Alta (7.8) | 55% | 💥 Exploit | Sudo Project SudoDebian LinuxFedoraproject FedoraApple Macos | 18/1/2023 | 17/6/2026 | En Sudo anterior a 1.9.12p2, la función sudoedit (también conocida como -e) maneja mal argumentos adicionales pasados en las variables de entorno proporcionadas por el usuario (SUDO_EDITOR, VISUAL y EDITOR), permitiendo a un atacante local agregar entradas arbitrarias a la lista de archivos para procesar. . Esto puede… | |
| Analizada | Media (4.3) | 1.2% | — | SambaFedoraproject Fedora | 17/1/2023 | 17/6/2026 | Se descubrió una vulnerabilidad de fuga de información en el servidor LDAP de Samba. Debido a la falta de comprobaciones de control de acceso, un atacante autenticado pero sin privilegios podría descubrir los nombres y atributos conservados de los objetos eliminados en el almacén LDAP. |