Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

853 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—ISC BindNetapp Active IQ Unified Manager13/2/202417/6/2026
To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that can be cleaned up is first allocated and then queued for later…
ModificadaMedia (5.3)0.63%—ISC BindNetapp Active IQ Unified Manager13/2/202417/6/2026
If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
ModificadaAlta (7.5)1.2%—Netapp Active IQ Unified ManagerFedoraproject FedoraISC Bind13/2/202417/6/2026
A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and…
ModificadaAlta (7.5)1.2%—Netapp Active IQ Unified ManagerFedoraproject FedoraISC Bind13/2/202417/6/2026
A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when:
ModificadaAlta (7.5)1.4%—GnutlsFedoraproject FedoraNetapp Active IQ Unified ManagerDebian Linux16/1/202417/6/2026
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to initiate a denial of service attack.
ModificadaAlta (7.8)57%—7-zipNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation3/11/202317/6/2026
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
ModificadaAlta (8.8)9.1%💥 PoCLinux KernelRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp Solidfire & HCI Management Node+11/11/202317/6/2026
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local…
ModificadaCrítica (9.8)78%💥 PoCHaxx LibcurlFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Oncommand Insight+918/10/202317/6/2026
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be…
ModificadaMedia (5.5)0.28%—Linux KernelNetapp Active IQ Unified ManagerNetapp H410c Firmware14/10/202317/6/2026
An issue was discovered in drivers/usb/storage/ene_ub6250.c for the ENE UB6250 reader driver in the Linux kernel before 6.2.5. An object could potentially extend beyond the end of an allocation.
ModificadaMedia (6.5)1.4%—LibtiffNetapp Active IQ Unified ManagerFedoraproject FedoraRedhat Enterprise Linux5/10/202317/6/2026
LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.
AnalizadaAlta (8.8)24%⚠ Explotación activa💥 PoCApple IpadosApple Iphone OSApple MacosFedoraproject Fedora+1021/9/202317/6/2026
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS before iOS 16.7.
ModificadaMedia (5.9)1.9%💥 PoCGNU GlibcRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems EUS S390x+1212/9/202317/6/2026
A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or…
AnalizadaAlta (8.8)100%⚠ Explotación activa💥 PoCGoogle ChromeFedoraproject FedoraDebian LinuxMozilla Firefox+812/9/202317/6/2026
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
ModificadaAlta (7.5)2.6%—PythonNetapp Active IQ Unified Manager23/8/202317/6/2026
An issue was discovered in Python 3.11 through 3.11.4. If a path containing '\0' bytes is passed to os.path.normpath(), the path will be truncated unexpectedly at the first '\0' byte. There are plausible cases in which an application would have rejected a filename for security reasons in Python 3.10.x or earlier, but…
ModificadaMedia (5.9)1.3%—PythonDebian LinuxNetapp Active IQ Unified ManagerNetapp Converged Systems Advisor Agent22/8/202317/6/2026
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
ModificadaMedia (6.5)1.7%—PythonNetapp Active IQ Unified Manager22/8/202317/6/2026
read_ints in plistlib.py in Python through 3.9.1 is vulnerable to a potential DoS attack via CPU and RAM exhaustion when processing malformed Apple Property List files in binary format.
AnalizadaCrítica (9.8)1.3%—Netapp Active IQ Unified ManagerJson-c22/8/202317/6/2026
An issue was discovered in json-c from 20200420 (post 0.14 unreleased code) through 0.15-20200726. A stack-buffer-overflow exists in the auxiliary sample program json_parse which is located in the function parseit.
ModificadaMedia (6.5)1.8%—Invisible-island NcursesNetapp Active IQ Unified Manager22/8/202323/7/2026
Buffer Overflow vulnerability in _nc_find_entry in tinfo/comp_hash.c:70 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
ModificadaMedia (6.5)2.2%—Invisible-island NcursesNetapp Active IQ Unified ManagerDebian Linux22/8/202323/7/2026
Buffer Overflow vulnerability in postprocess_terminfo function in tinfo/parse_entry.c:997 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
ModificadaMedia (6.5)1.8%—Invisible-island NcursesNetapp Active IQ Unified Manager22/8/202323/7/2026
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
ModificadaMedia (6.5)1.8%—Invisible-island NcursesNetapp Active IQ Unified Manager22/8/202323/7/2026
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
ModificadaMedia (6.5)1.8%—Invisible-island NcursesNetapp Active IQ Unified Manager22/8/202323/7/2026
Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
ModificadaMedia (6.5)1.8%—Invisible-island NcursesNetapp Active IQ Unified Manager22/8/202323/7/2026
Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
ModificadaMedia (6.5)2.8%—MIT Kerberos 5Debian LinuxNetapp Active IQ Unified ManagerNetapp Clustered Data Ontap+37/8/202317/6/2026
lib/kadm5/kadm_rpc_xdr.c in MIT Kerberos 5 (aka krb5) before 1.20.2 and 1.21.x before 1.21.1 frees an uninitialized pointer. A remote authenticated user can trigger a kadmind crash. This occurs because _xdr_kadm5_principal_ent_rec does not validate the relationship between n_key_data and the key_data array count.
AnalizadaCrítica (9.8)0.57%—CertifiFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp Management Services FOR Element Software+425/7/202317/6/2026
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of…
Orbitaley — Vulnerabilidades