Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
–

6097 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.43%—Artifex GhostscriptRedhat Enterprise LinuxFedoraproject FedoraDebian Linux1/8/202323/6/2026
Se ha encontrado un fallo de desbordamiento de búfer en base/gdevdevn.c:1973 en devn_pcx_write_rle() en ghostscript. Este problema puede permitir a un atacante local provocar una denegación de servicio mediante la salida de un archivo PDF manipulado para un dispositivo DEVN con gs.
ModificadaAlta (7.8)0.92%—Linux KernelFedoraproject FedoraRedhat Enterprise LinuxNetapp H300s+431/7/202317/6/2026
Se encontró una falla de use-after-free en el netfilter del kernel de Linux en la forma en que un usuario activa la función nft_pipapo_remove con el elemento, sin un NFT_SET_EXT_KEY_END. Este problema podría permitir que un usuario local bloquee el sistema o potencialmente aumente sus privilegios en el sistema.
ModificadaMedia (4.4)0.25%—Redhat Enterprise LinuxFedoraproject FedoraLinux KernelDebian Linux25/7/202317/6/2026
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRESH when parsing netlink attributes, leading to potential leakage of sensitive heap data to…
ModificadaMedia (4.4)0.45%—Redhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFVFedoraproject Fedora+225/7/202317/6/2026
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_params(), leading to a possible kernel crash and denial of service.
ModificadaMedia (6.5)1.3%—Redhat Openstack Platform25/7/202317/6/2026
An uncontrolled resource consumption flaw was found in openstack-neutron. This flaw allows a remote authenticated user to query a list of security groups for an invalid project. This issue creates resources that are unconstrained by the user's quota. If a malicious user were to submit a significant number of requests,…
ModificadaAlta (7.8)0.34%—Linux KernelRedhat Enterprise Linux24/7/202317/6/2026
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user generates a malicious (too big) networking packet when napi frags is enabled. This flaw allows a local user to crash or potentially escalate their privileges on the system.
ModificadaMedia (5.3)0.76%—Redhat LibvirtRedhat Enterprise Linux24/7/202317/6/2026
A flaw was found in libvirt. The virStoragePoolObjListSearch function does not return a locked pool as expected, resulting in a race condition and denial of service when attempting to lock the same object from another thread. This issue could allow clients connecting to the read-only socket to crash the libvirt daemon.
ModificadaAlta (7.8)0.76%💥 PoCLinux KernelRedhat Enterprise Linux24/7/202321/7/2026
A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to memory, where a user may guess the location of exception stacks or other important data. Based on the previous CVE-2023-0597, the 'Randomize per-cpu entry area' feature was implemented in…
ModificadaAlta (7.1)0.42%—Linux KernelRedhat Enterprise LinuxCanonical Ubuntu Linux24/7/202317/6/2026
A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue may allow an attacker with local user access to cause a system crash or leak internal kernel information.
ModificadaMedia (5.4)0.49%—Redhat Quay24/7/20236/8/2026
A flaw was found in the Quay registry. While the image labels created through Quay undergo validation both in the UI and backend by applying a regex (validation.py), the same validation is not performed when the label comes from an image. This flaw allows an attacker to publish a malicious image to a public registry…
ModificadaMedia (6.5)0.32%—QemuRedhat Enterprise Linux24/7/202317/6/2026
A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could allow a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
ModificadaAlta (7.5)1.4%—KeylimeRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+524/7/202317/6/2026
Se encontró una falla en Keylime. Debido a su naturaleza de bloqueo, el registrador de Keylime está sujeto a una denegación de servicio remota contra sus conexiones SSL. Esta falla permite a un atacante agotar todas las conexiones disponibles.
ModificadaMedia (6.7)0.46%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV24/7/202317/6/2026
Se encontró una vulnerabilidad de double free en el manejo de objetos vmw_buffer_object en el controlador vmwgfx en el kernel de Linux. Este problema se produce debido a la falta de validación de la existencia de un objeto antes de realizar más operaciones libres en el objeto, lo que puede permitir a un usuario…
ModificadaMedia (5.3)0.34%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux FOR Real TimeRedhat Enterprise Linux FOR Real Time FOR NFV24/7/202317/6/2026
Se encontró una vulnerabilidad de condición de ejecución en el controlador vmwgfx del kernel de Linux. El fallo existe en el manejo de objetos GEM. El problema se debe a un bloqueo inadecuado al realizar operaciones en un objeto. Este fallo permite que un usuario local privilegiado revele información en el contexto…
ModificadaMedia (5.9)0.44%—SambaRedhat StorageRedhat Enterprise LinuxFedoraproject Fedora20/7/202317/6/2026
A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a…
ModificadaMedia (5.3)1.3%—SambaFedoraproject FedoraRedhat StorageRedhat Enterprise Linux+120/7/202317/6/2026
A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part…
ModificadaMedia (5.3)61%—SambaFedoraproject FedoraRedhat Enterprise LinuxDebian Linux20/7/202317/6/2026
A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character strings, and the values can be any of the supported types in the mdssvc protocol. Due to a lack of…
ModificadaAlta (7.5)62%—SambaFedoraproject FedoraRedhat Enterprise LinuxDebian Linux20/7/202317/6/2026
An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a field in the network packet that contains the count of elements in an array-like structure. By passing…
ModificadaMedia (5.9)1.7%—SambaRedhat Enterprise LinuxFedoraproject FedoraDebian Linux20/7/202317/6/2026
An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server. These replies have variable lengths, and Winbind fails to check the lan manager response length.…
ModificadaAlta (7.8)0.33%—Redhat Shim20/7/202317/6/2026
There's a possible overflow in handle_image() when shim tries to load and execute crafted EFI executables; The handle_image() function takes into account the SizeOfRawData field from each section to be loaded. An attacker can leverage this to perform out-of-bound writes into memory. Arbitrary code execution is not…
ModificadaMedia (5.5)0.36%—Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux14/7/202317/6/2026
An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
ModificadaMedia (5.5)0.36%—Tats W3MFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux14/7/202317/6/2026
An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
ModificadaMedia (6.5)1.2%—LibtiffDebian LinuxRedhat Enterprise Linux12/7/202317/6/2026
A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.
ModificadaAlta (7.5)1.6%—QemuRedhat Openstack PlatformRedhat Enterprise LinuxFedoraproject Fedora11/7/202317/6/2026
A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the…
ModificadaAlta (7.8)1.3%💥 PoCLinux KernelFedoraproject FedoraRedhat Enterprise Linux11/7/202317/6/2026
A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating virtual memory areas (VMAs) is incorrect, leading to use-after-free problems. This issue can be successfully exploited to execute arbitrary kernel code, escalate containers, and gain root…