Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1353 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 15% | — | OpensslNodejs Node.js | 4/5/2017 | 17/6/2026 | There is a carry propagating bug in the x86_64 Montgomery squaring procedure in OpenSSL 1.0.2 before 1.0.2k and 1.1.0 before 1.1.0d. No EC algorithms are affected. Analysis suggests that attacks against RSA and DSA as a result of this defect would be very difficult to perform and are not believed likely. Attacks… | |
| Modificada | Alta (7.5) | 57% | — | OpensslNodejs Node.js | 4/5/2017 | 17/6/2026 | If an SSL/TLS server or client is running on a 32-bit host, and a specific cipher is being used, then a truncated packet can cause that server or client to perform an out-of-bounds read, usually resulting in a crash. For OpenSSL 1.1.0, the crash can be triggered when using CHACHA20/POLY1305; users should upgrade to… | |
| Modificada | Media (5.5) | 0.36% | — | FirewalldRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+1 | 19/4/2017 | 17/6/2026 | firewalld.py in firewalld before 0.4.3.3 allows local users to bypass authentication and modify firewall configurations via the (1) addPassthrough, (2) removePassthrough, (3) addEntry, (4) removeEntry, or (5) setEntries D-Bus API method. | |
| Modificada | Alta (7.5) | 5.0% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 14/4/2017 | 17/6/2026 | The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack. | |
| Modificada | Baja (3.3) | 0.43% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 14/4/2017 | 17/6/2026 | The Subscription Manager package (aka subscription-manager) before 1.17.7-1 for Candlepin uses weak permissions (755) for subscription-manager cache directories, which allows local users to obtain sensitive information by reading files in the directories. | |
| Modificada | Alta (7) | 0.46% | — | Setroubleshoot Project SetroubleshootRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+1 | 11/4/2017 | 17/6/2026 | setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux denial with a crafted file name, which is handled by the _set_tpath function in audit_data.py or via a crafted (2) local_id or (3) analysis_id field in a crafted XML… | |
| Modificada | Alta (7) | 0.47% | — | Setroubleshoot Project SetroubleshootRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+1 | 11/4/2017 | 17/6/2026 | The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafted filename, related to the commands.getoutput function. | |
| Modificada | Alta (7) | 0.47% | — | Setroubleshoot Project SetroubleshootRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+1 | 11/4/2017 | 17/6/2026 | The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file name, related to executing external commands with the commands.getstatusoutput function. | |
| Modificada | Alta (7) | 0.47% | — | Setroubleshoot Project SetroubleshootRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+1 | 11/4/2017 | 17/6/2026 | The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial with a crafted binary filename, related to the commands.getstatusoutput function. | |
| Modificada | Crítica (9.8) | 61% | 💥 Exploit | Node-serialize Project Node-serialize | 9/2/2017 | 17/6/2026 | An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE). | |
| Modificada | Crítica (9.8) | 8.4% | — | GstreamerRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+2 | 27/1/2017 | 17/6/2026 | Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'write count' that goes beyond the initialized buffer. | |
| Modificada | Crítica (9.8) | 8.9% | — | GstreamerRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+2 | 27/1/2017 | 17/6/2026 | Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by providing a 'skip count' that goes beyond initialized buffer. | |
| Modificada | Crítica (9.8) | 8.9% | — | GstreamerRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+2 | 27/1/2017 | 17/6/2026 | Heap-based buffer overflow in the flx_decode_delta_fli function in gst/flx/gstflxdec.c in the FLIC decoder in GStreamer before 1.10.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via the start_line parameter. | |
| Modificada | Alta (7.5) | 4.9% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive. | |
| Modificada | Alta (7.5) | 6.7% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The semver package before 4.3.2 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)." | |
| Modificada | Media (6.1) | 2.6% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The validator package before 2.0.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via hex-encoded characters. | |
| Modificada | Media (6.1) | 1.9% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings. | |
| Modificada | Media (6.1) | 1.9% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via vectors related to UI redressing. | |
| Modificada | Media (6.1) | 2.0% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via a crafted javascript URI. | |
| Modificada | Media (6.1) | 1.9% | — | Nodejs Node.js | 23/1/2017 | 17/6/2026 | The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag. | |
| Modificada | Alta (8.8) | 0.38% | — | Selinux Project SelinuxFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+3 | 19/1/2017 | 17/6/2026 | SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call. | |
| Modificada | Alta (7.5) | 41% | — | ISC BindDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+8 | 12/1/2017 | 17/6/2026 | named in ISC BIND 9.x before 9.9.9-P5, 9.10.x before 9.10.4-P5, and 9.11.x before 9.11.0-P2 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed response to an RTYPE ANY query. | |
| Modificada | Media (4.4) | 0.40% | — | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+1 | 22/12/2016 | 17/6/2026 | sudo: It was discovered that the default sudo configuration on Red Hat Enterprise Linux and possibly other Linux implementations preserves the value of INPUTRC which could lead to information disclosure. A local user with sudo access to a restricted program that uses readline could use this flaw to read content from… | |
| Modificada | Crítica (9.8) | 3.1% | — | TigervncRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+1 | 14/12/2016 | 17/6/2026 | XRegion in TigerVNC allows remote VNC servers to cause a denial of service (NULL pointer dereference) by leveraging failure to check a malloc return value, a similar issue to CVE-2014-6052. | |
| Analizada | Alta (7) | 84% | ⚠ Explotación activa💥 Exploit | Canonical Ubuntu LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux AUS+14 | 10/11/2016 | 17/6/2026 | Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping, as exploited in the wild in October 2016, aka "Dirty COW." |