Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.6) | 0.31% | — | Redhat Enterprise VirtualizationRedhat KVM | 24/8/2010 | 16/6/2026 | QEMU-KVM, as used in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and KVM 83, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain privileges via… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | D-link Dkvm-ip8 | 8/3/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in auth.asp on the D-LINK DKVM-IP8 with firmware 2282_dlinkA4_p8_20071213 allows remote attackers to inject arbitrary web script or HTML via the nickname parameter. | |
| Modificada | Media (4.4) | 0.35% | — | KVM Qumranet KVM | 5/3/2010 | 16/6/2026 | The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not properly restrict writing of segment selectors to segment registers, which might allow guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by leveraging access to a (1) IO… | |
| Modificada | Media (4.1) | 0.38% | — | KVM Qumranet KVM | 12/2/2010 | 16/6/2026 | The x86 emulator in KVM 83, when a guest is configured for Symmetric Multiprocessing (SMP), does not use the Current Privilege Level (CPL) and I/O Privilege Level (IOPL) to restrict instruction execution, which allows guest OS users to cause a denial of service (guest OS crash) or gain privileges on the guest OS by… | |
| Modificada | Alta (10) | 2.1% | — | Aten Kh1516i IP KVM SwitchAten Kn9116 IP KVM SwitchAten Pn9108 Power Over THE NET | 27/5/2009 | 16/6/2026 | The https web interfaces on the ATEN KH1516i IP KVM switch with firmware 1.0.063, the KN9116 IP KVM switch with firmware 1.1.104, and the PN9108 power-control unit have a hardcoded SSL private key, which makes it easier for remote attackers to decrypt https sessions by extracting this key from their own switch and… | |
| Modificada | Alta (7.6) | 1.7% | — | Aten Kh1516i IP KVM SwitchAten Kn9116 IP KVM Switch | 27/5/2009 | 16/6/2026 | The ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not (1) encrypt mouse events, which makes it easier for man-in-the-middle attackers to perform mouse operations on machines connected to the switch by injecting network traffic; and do not (2) set the secure flag… | |
| Modificada | Alta (10) | 3.2% | — | Aten Kh1516i IP KVM SwitchAten Kn9116 IP KVM Switch | 27/5/2009 | 16/6/2026 | The (1) Windows and (2) Java client programs for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 do not properly use RSA cryptography for a symmetric session-key negotiation, which makes it easier for remote attackers to (a) decrypt network traffic, or (b)… | |
| Modificada | Alta (10) | 1.1% | — | Aten Kh1516i IP KVM SwitchAten Kn9116 IP KVM Switch | 27/5/2009 | 16/6/2026 | The Java client program for the ATEN KH1516i IP KVM switch with firmware 1.0.063 and the KN9116 IP KVM switch with firmware 1.1.104 has a hardcoded AES encryption key, which makes it easier for man-in-the-middle attackers to (1) execute arbitrary Java code, or (2) gain access to machines connected to the switch, by… | |
| Modificada | Alta (7.2) | 0.54% | — | KVM Qumranet KVMQemuCanonical Ubuntu LinuxDebian Linux | 29/12/2008 | 16/6/2026 | Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for… | |
| Modificada | Media (5) | 6.6% | 💥 Exploit | QemuKVM Qumranet KVM | 24/12/2008 | 16/6/2026 | The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier allows remote attackers to cause a denial of service (infinite loop) via a certain message. |