Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
97 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.92% | — | Intel Core I3-10110u FirmwareIntel Core I3-10110y FirmwareIntel Core I3-1005g1 FirmwareIntel Core I3-9300t Firmware+774 | 14/11/2019 | 17/6/2026 | Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access. | |
| Modificada | Media (6.5) | 3.1% | — | Opensuse LeapFedoraproject FedoraSlackwareHP Apollo 4200 Firmware+156 | 14/11/2019 | 17/6/2026 | TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. | |
| Modificada | Media (5.5) | 0.35% | — | Intel Core I7-6970hq FirmwareIntel Core I7-6920hq FirmwareIntel Core I7-6870hq FirmwareIntel Core I7-6822eq Firmware+138 | 14/11/2019 | 17/6/2026 | Insufficient access control in protected memory subsystem for SMM for 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor families; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 families; Intel(R) Xeon(R) E-2100 and E-2200 Processor families with Intel(R) Processor Graphics may allow a privileged user to… | |
| Modificada | Alta (7.8) | 0.67% | — | Redhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUSRedhat Enterprise Linux Server TUSIntel Graphics Driver+353 | 14/11/2019 | 17/6/2026 | Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series;… | |
| Modificada | Alta (7.6) | 0.55% | — | Intel Core I3Intel Core I5Intel Core I7Intel Core I9+28 | 21/9/2018 | 17/6/2026 | Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware… | |
| Modificada | Media (5.6) | 8.6% | — | Intel Core I3Intel Core I5Intel Core I7Intel Core M+4 | 14/8/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis. | |
| Modificada | Media (5.6) | 5.6% | — | Intel Core I3Intel Core I5Intel Core I7Intel Core M+4 | 14/8/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis. | |
| Modificada | Alta (7.3) | 6.3% | — | Intel Core I3Intel Core I5Intel Core I7Intel Xeon E3+26 | 14/8/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis. | |
| Modificada | Media (5.6) | 8.6% | — | Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+221 | 10/7/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis. | |
| Modificada | Media (4.6) | 0.21% | — | Intel Core I7Intel Core I5Intel Core I3Intel Core I9+13 | 10/7/2018 | 17/6/2026 | Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encryption may allow an attacker to recover data via physical access. | |
| Modificada | Media (6.7) | 0.29% | — | Intel Core I3Intel Core I5Intel Core I7 | 10/7/2018 | 17/6/2026 | Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Intel Core Processor potentially exposes password information in memory to a local attacker with administrative privileges. | |
| Modificada | Media (5.6) | 0.63% | — | Intel Core I3Intel Core I5Intel Core I7Intel Core M+10 | 21/6/2018 | 17/6/2026 | System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel. | |
| Modificada | Media (5.6) | 7.5% | — | Intel Atom CIntel Atom EIntel Atom ZIntel Celeron J+195 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a. | |
| Modificada | Media (5.5) | 61% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… | |
| Modificada | Media (5.6) | 0.67% | — | Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+205 | 27/3/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (PHT), aka BranchScope. | |
| Modificada | Media (5.6) | 84% | 💥 PoC | Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+205 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache. | |
| Modificada | Media (5.6) | 94% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Media (5.6) | 74% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+216 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Alta (7.5) | 1.9% | — | Cisco IOS XEIntel Core I5-9400f FirmwareNetgear Jr6150 FirmwareSamsung X14j Firmware+3 | 26/3/2016 | 17/6/2026 | The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410. |