Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
681 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.56% | — | Linux KernelDebian LinuxOpensuse LeapOpensuse Project Leap+4 | 20/12/2017 | 17/6/2026 | The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a… | |
| Modificada | Alta (7.8) | 0.44% | — | Linux KernelDebian LinuxOpensuse LeapOpensuse Project Leap+4 | 20/12/2017 | 17/6/2026 | The Salsa20 encryption algorithm in the Linux kernel before 4.14.8 does not correctly handle zero-length inputs, allowing a local attacker able to use the AF_ALG-based skcipher interface (CONFIG_CRYPTO_USER_API_SKCIPHER) to cause a denial of service (uninitialized-memory free and kernel crash) or have unspecified… | |
| Modificada | Media (6.6) | 0.48% | — | Linux KernelSuse Linux Enterprise Server | 12/12/2017 | 17/6/2026 | The usb_destroy_configuration function in drivers/usb/core/config.c in the USB core subsystem in the Linux kernel through 4.14.5 does not consider the maximum number of configurations and interfaces before attempting to release resources, which allows local users to cause a denial of service (out-of-bounds write… | |
| Modificada | Alta (7.8) | 0.47% | — | Linux KernelDebian LinuxSuse Linux Enterprise ServerCanonical Ubuntu Linux | 15/11/2017 | 17/6/2026 | The sctp_do_peeloff function in net/sctp/socket.c in the Linux kernel before 4.14 does not check whether the intended netns is used in a peel-off action, which allows local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via crafted system calls. | |
| Modificada | Media (5.3) | 1.8% | — | Canonical Ubuntu LinuxDebian LinuxFreebsdOpensuse Leap+8 | 17/10/2017 | 17/6/2026 | Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Integrity Group Temporal Key (IGTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients. | |
| Modificada | Media (5.3) | 1.7% | — | Canonical Ubuntu LinuxDebian LinuxFreebsdOpensuse Leap+8 | 17/10/2017 | 17/6/2026 | Wi-Fi Protected Access (WPA and WPA2) that support 802.11v allows reinstallation of the Group Temporal Key (GTK) when processing a Wireless Network Management (WNM) Sleep Mode Response frame, allowing an attacker within radio range to replay frames from access points to clients. | |
| Modificada | Media (6.8) | 2.0% | — | Canonical Ubuntu LinuxDebian LinuxFreebsdOpensuse Leap+8 | 17/10/2017 | 17/6/2026 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Tunneled Direct-Link Setup (TDLS) Peer Key (TPK) during the TDLS handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames. | |
| Modificada | Media (6.8) | 2.2% | — | Canonical Ubuntu LinuxDebian LinuxFreebsdOpensuse Leap+8 | 17/10/2017 | 17/6/2026 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Station-To-Station-Link (STSL) Transient Key (STK) during the PeerKey handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames. | |
| Modificada | Alta (8.1) | 4.6% | — | Canonical Ubuntu LinuxDebian LinuxFreebsdOpensuse Leap+8 | 17/10/2017 | 17/6/2026 | Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11r allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the fast BSS transmission (FT) handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames. | |
| Modificada | Media (5.3) | 2.0% | — | Canonical Ubuntu LinuxDebian LinuxFreebsdOpensuse Leap+8 | 17/10/2017 | 17/6/2026 | Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients. | |
| Modificada | Media (5.3) | 2.3% | — | Canonical Ubuntu LinuxDebian LinuxFreebsdOpensuse Leap+8 | 17/10/2017 | 17/6/2026 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients. | |
| Modificada | Media (5.3) | 2.1% | — | Canonical Ubuntu LinuxDebian LinuxFreebsdOpensuse Leap+8 | 17/10/2017 | 17/6/2026 | Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the four-way handshake, allowing an attacker within radio range to spoof frames from access points to clients. | |
| Modificada | Media (5.3) | 2.1% | — | Canonical Ubuntu LinuxDebian LinuxFreebsdOpensuse Leap+8 | 17/10/2017 | 17/6/2026 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Group Temporal Key (GTK) during the four-way handshake, allowing an attacker within radio range to replay frames from access points to clients. | |
| Modificada | Media (6.8) | 2.4% | — | Canonical Ubuntu LinuxDebian LinuxFreebsdOpensuse Leap+8 | 17/10/2017 | 17/6/2026 | Wi-Fi Protected Access (WPA and WPA2) allows reinstallation of the Pairwise Transient Key (PTK) Temporal Key (TK) during the four-way handshake, allowing an attacker within radio range to replay, decrypt, or spoof frames. | |
| Modificada | Crítica (9.8) | 85% | — | Thekelleys DnsmasqRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+17 | 4/10/2017 | 17/6/2026 | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | |
| Modificada | Alta (7.8) | 0.38% | — | Novell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse Leap | 8/9/2017 | 17/6/2026 | The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root. | |
| Modificada | Alta (7.5) | 5.3% | — | NTPDebian LinuxOpensuse Suse Linux Enterprise ServerOpensuse Project Suse Linux Enterprise Desktop+9 | 9/8/2017 | 17/6/2026 | ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute… | |
| Modificada | Alta (7.5) | 9.1% | — | Fedoraproject FedoraSuse Linux Enterprise DebuginfoOpensuse LeapOpensuse+16 | 21/7/2017 | 17/6/2026 | The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to… | |
| Modificada | Alta (7.5) | 5.8% | — | Fedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise ServerSuse Manager+14 | 21/7/2017 | 17/6/2026 | The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet. | |
| Modificada | Alta (7.5) | 5.5% | — | Fedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise ServerSuse Manager+9 | 21/7/2017 | 17/6/2026 | The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands. | |
| Modificada | Alta (7.8) | 2.7% | — | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+16 | 19/6/2017 | 17/6/2026 | glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these… | |
| Modificada | Crítica (9.8) | 4.4% | — | Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+3 | 6/6/2017 | 17/6/2026 | game-music-emu before 0.6.1 mishandles unspecified integer values. | |
| Modificada | Media (5.5) | 0.53% | — | Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+3 | 6/6/2017 | 17/6/2026 | game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash). | |
| Modificada | Baja (3.8) | 0.37% | — | XENSuse ManagerSuse Manager ProxySuse Openstack Cloud+2 | 3/5/2017 | 17/6/2026 | Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL. | |
| Modificada | Alta (7.7) | 5.6% | — | QemuCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Debuginfo+6 | 13/4/2017 | 17/6/2026 | Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption). |