Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
6097 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.43% | — | Artifex GhostscriptRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 1/8/2023 | 23/6/2026 | Se ha encontrado un fallo de desbordamiento de búfer en base/gdevdevn.c:1973 en devn_pcx_write_rle() en ghostscript. Este problema puede permitir a un atacante local provocar una denegación de servicio mediante la salida de un archivo PDF manipulado para un dispositivo DEVN con gs. | |
| Modificada | Alta (7.8) | 0.92% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxNetapp H300s+4 | 31/7/2023 | 17/6/2026 | Se encontró una falla de use-after-free en el netfilter del kernel de Linux en la forma en que un usuario activa la función nft_pipapo_remove con el elemento, sin un NFT_SET_EXT_KEY_END. Este problema podría permitir que un usuario local bloquee el sistema o potencialmente aumente sus privilegios en el sistema. | |
| Modificada | Media (4.4) | 0.25% | — | Redhat Enterprise LinuxFedoraproject FedoraLinux KernelDebian Linux | 25/7/2023 | 17/6/2026 | A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to… | |
| Modificada | Media (4.4) | 0.45% | — | Redhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFVFedoraproject Fedora+2 | 25/7/2023 | 17/6/2026 | A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service. | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Openstack Platform | 25/7/2023 | 17/6/2026 | An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests,… | |
| Modificada | Alta (7.8) | 0.34% | — | Linux KernelRedhat Enterprise Linux | 24/7/2023 | 17/6/2026 | An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Modificada | Media (5.3) | 0.76% | — | Redhat LibvirtRedhat Enterprise Linux | 24/7/2023 | 17/6/2026 | A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon. | |
| Modificada | Alta (7.8) | 0.76% | 💥 PoC | Linux KernelRedhat Enterprise Linux | 24/7/2023 | 21/7/2026 | A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in… | |
| Modificada | Alta (7.1) | 0.42% | — | Linux KernelRedhat Enterprise LinuxCanonical Ubuntu Linux | 24/7/2023 | 17/6/2026 | A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information. | |
| Modificada | Media (5.4) | 0.49% | — | Redhat Quay | 24/7/2023 | 6/8/2026 | A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an image. This flaw allows an attacker to publish a malicious image to a public registry… | |
| Modificada | Media (6.5) | 0.32% | — | QemuRedhat Enterprise Linux | 24/7/2023 | 17/6/2026 | A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. | |
| Modificada | Alta (7.5) | 1.4% | — | KeylimeRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+5 | 24/7/2023 | 17/6/2026 | Se encontró una falla en Keylime. Debido a su naturaleza de bloqueo, el registrador de Keylime está sujeto a una denegación de servicio remota contra sus conexiones SSL. Esta falla permite a un atacante agotar todas las conexiones disponibles. | |
| Modificada | Media (6.7) | 0.46% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV | 24/7/2023 | 17/6/2026 | Se encontró una vulnerabilidad de double free en el manejo de objetos vmw_buffer_object en el controlador vmwgfx en el kernel de Linux. Este problema se produce debido a la falta de validación de la existencia de un objeto antes de realizar más operaciones libres en el objeto, lo que puede permitir a un usuario… | |
| Modificada | Media (5.3) | 0.34% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV | 24/7/2023 | 17/6/2026 | Se encontró una vulnerabilidad de condición de ejecución en el controlador vmwgfx del kernel de Linux. El fallo existe en el manejo de objetos GEM. El problema se debe a un bloqueo inadecuado al realizar operaciones en un objeto. Este fallo permite que un usuario local privilegiado revele información en el contexto… | |
| Modificada | Media (5.9) | 0.44% | — | SambaRedhat StorageRedhat Enterprise LinuxFedoraproject Fedora | 20/7/2023 | 17/6/2026 | A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a… | |
| Modificada | Media (5.3) | 1.3% | — | SambaFedoraproject FedoraRedhat StorageRedhat Enterprise Linux+1 | 20/7/2023 | 17/6/2026 | A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part… | |
| Modificada | Media (5.3) | 61% | — | SambaFedoraproject FedoraRedhat Enterprise LinuxDebian Linux | 20/7/2023 | 17/6/2026 | A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the mdssvc protocol. Due to a lack of… | |
| Modificada | Alta (7.5) | 62% | — | SambaFedoraproject FedoraRedhat Enterprise LinuxDebian Linux | 20/7/2023 | 17/6/2026 | An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing… | |
| Modificada | Media (5.9) | 1.7% | — | SambaRedhat Enterprise LinuxFedoraproject FedoraDebian Linux | 20/7/2023 | 17/6/2026 | An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length.… | |
| Modificada | Alta (7.8) | 0.33% | — | Redhat Shim | 20/7/2023 | 17/6/2026 | There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not… | |
| Modificada | Media (5.5) | 0.36% | — | Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 14/7/2023 | 17/6/2026 | An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file. | |
| Modificada | Media (5.5) | 0.36% | — | Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux | 14/7/2023 | 17/6/2026 | An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file. | |
| Modificada | Media (6.5) | 1.2% | — | LibtiffDebian LinuxRedhat Enterprise Linux | 12/7/2023 | 17/6/2026 | A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service. | |
| Modificada | Alta (7.5) | 1.6% | — | QemuRedhat Openstack PlatformRedhat Enterprise LinuxFedoraproject Fedora | 11/7/2023 | 17/6/2026 | A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the… | |
| Modificada | Alta (7.8) | 1.3% | 💥 PoC | Linux KernelFedoraproject FedoraRedhat Enterprise Linux | 11/7/2023 | 17/6/2026 | A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root… |