Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.6) | 16% | 💥 Exploit | Automatedsolutions Modbus/tcp Master OPC Server | 28/1/2011 | 16/6/2026 | Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a MODBUS response packet with a crafted length field. | |
| Modificada | Baja (3.6) | 0.39% | — | Freedesktop Dbus-glib | 20/8/2010 | 16/6/2026 | DBus-GLib 0.73 disregards the access flag of exported GObject properties, which allows local users to bypass intended access restrictions and possibly cause a denial of service by modifying properties, as demonstrated by properties of the (1) DeviceKit-Power, (2) NetworkManager, and (3) ModemManager services. | |
| Modificada | Baja (3.6) | 1.3% | — | Freedesktop Dbus | 27/4/2009 | 16/6/2026 | The _dbus_validate_signature_with_reason function (dbus-marshal-validate.c) in D-Bus (aka DBus) before 1.2.14 uses incorrect logic to validate a basic type, which allows remote attackers to spoof a signature via a crafted key. NOTE: this is due to an incorrect fix for CVE-2008-3834. | |
| Modificada | Media (4.6) | 0.41% | — | Freedesktop Dbus | 10/12/2008 | 16/6/2026 | The default configuration of system.conf in D-Bus (aka DBus) before 1.2.6 omits the send_type attribute in certain rules, which allows local users to bypass intended access restrictions by (1) sending messages, related to send_requested_reply; and possibly (2) receiving messages, related to receive_requested_reply. | |
| Modificada | Baja (2.1) | 4.6% | 💥 Exploit | Freedesktop DbusFreedesktop Dbus1.0Freedesktop Dbus1.1.0 | 7/10/2008 | 16/6/2026 | The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a denial of service (application abort) via a message containing a malformed signature, which triggers a failed assertion error. | |
| Modificada | Media (4.6) | 0.40% | — | Fedoraproject FedoraMandrakesoft Mandrake LinuxRedhat Enterprise LinuxFreedesktop Dbus | 29/2/2008 | 16/6/2026 | dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface. | |
| Modificada | Alta (7.5) | 4.7% | — | Automated Solutions Modbus Slave Activex Control | 19/9/2007 | 16/6/2026 | Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502. |