Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
319 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 53% | — | Net-snmpDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+2 | 7/11/2022 | 17/6/2026 | handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | |
| Modificada | Media (6.5) | 52% | — | Net-snmpDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+2 | 7/11/2022 | 17/6/2026 | handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. | |
| Modificada | Alta (7.5) | 22% | — | Linux KernelNetapp Active IQ Unified ManagerNetapp H300s FirmwareNetapp H500s Firmware+3 | 4/11/2022 | 17/6/2026 | The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a single array of pages. A client can force the send buffer to shrink by… | |
| Modificada | Alta (8.1) | 2.9% | — | Haxx CurlFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+5 | 29/10/2022 | 17/6/2026 | curl before 7.86.0 has a double free. If curl is told to use an HTTP proxy for a transfer with a non-HTTP(S) URL, it sets up the connection to the remote server by issuing a CONNECT request to the proxy, and then tunnels the rest of the protocol through. An HTTP proxy might refuse this request (HTTP proxies often only… | |
| Modificada | Alta (7.5) | 2.5% | 💥 PoC | Libexpat Project LibexpatDebian LinuxFedoraproject FedoraNetapp H300s Firmware+8 | 24/10/2022 | 17/6/2026 | In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations. | |
| Modificada | Alta (7) | 0.87% | — | Linux KernelDebian LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+3 | 21/10/2022 | 17/6/2026 | A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue.… | |
| Modificada | Alta (7.1) | 1.3% | 💥 PoC | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+2 | 17/10/2022 | 17/6/2026 | A vulnerability classified as critical was found in Linux Kernel. Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The associated… | |
| Modificada | Alta (7.8) | 0.43% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+3 | 17/10/2022 | 17/6/2026 | A vulnerability has been found in Linux Kernel and classified as critical. Affected by this vulnerability is the function area_cache_get of the file drivers/net/ethernet/netronome/nfp/nfpcore/nfp_cppcore.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this… | |
| Modificada | Baja (3.7) | 2.4% | — | Haxx CurlNetapp Clustered Data OntapNetapp Element SoftwareNetapp HCI Management Node+9 | 23/9/2022 | 17/6/2026 | When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using control codes that when later are sent back to a HTTPserver might make the server return 400 responses. Effectively allowing a"sister site" to deny service to all siblings. | |
| Modificada | Alta (7.1) | 0.26% | — | Linux KernelNetapp H410c FirmwareNetapp H300s FirmwareNetapp H500s Firmware+2 | 14/9/2022 | 17/6/2026 | A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information. | |
| Modificada | Alta (7.8) | 0.31% | — | Linux KernelRedhat Enterprise LinuxNetapp H300s FirmwareNetapp H500s Firmware+3 | 9/9/2022 | 17/6/2026 | A flaw was found in the Linux kernel’s driver for the ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet Devices. The vulnerability contains multiple out-of-bounds reads and possible out-of-bounds writes. | |
| Modificada | Crítica (9.8) | 1.3% | — | Systemd Project SystemdNetapp Active IQ Unified ManagerNetapp H300s FirmwareNetapp H500s Firmware+2 | 9/9/2022 | 17/6/2026 | A use-after-free vulnerability was found in systemd. This issue occurs due to the on_stream_io() function and dns_stream_complete() function in 'resolved-dns-stream.c' not incrementing the reference counting for the DnsStream object. Therefore, other functions and callbacks called can dereference the DNSStream object,… | |
| Modificada | Media (5.3) | 1.8% | — | GNU GlibcNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+3 | 31/8/2022 | 17/6/2026 | An issue was discovered in the GNU C Library (glibc) 2.36. When the syslog function is passed a crafted input string larger than 1024 bytes, it reads uninitialized memory from the heap and prints it to the target log file, potentially revealing a portion of the contents of the heap. | |
| Modificada | Alta (7) | 0.32% | — | Linux KernelFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+3 | 29/8/2022 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system. | |
| Analizada | Alta (7.5) | 2.0% | — | Linux KernelRedhat Enterprise LinuxNetapp Active IQ Unified ManagerNetapp H300s Firmware+4 | 29/8/2022 | 11/9/2026 | A flaw was found in the Linux kernel. This flaw allows an attacker to crash the Linux kernel by simulating amateur radio from the user space, resulting in a null-ptr-deref vulnerability and a use-after-free vulnerability. | |
| Modificada | Alta (7.1) | 1.2% | 💥 PoC | Linux KernelDebian LinuxRedhat Enterprise LinuxNetapp H300s Firmware+4 | 24/8/2022 | 17/6/2026 | An out-of-bounds (OOB) memory access flaw was found in the Linux kernel's eBPF due to an Improper Input Validation. This flaw allows a local attacker with a special privilege to crash the system or leak internal information. | |
| Modificada | Alta (7.8) | 0.75% | — | GNU GlibcDebian LinuxNetapp E-series Performance AnalyzerNetapp NFS Plug-in+6 | 24/8/2022 | 17/6/2026 | A flaw was found in glibc. An off-by-one buffer overflow and underflow in getcwd() may lead to memory corruption when the size of the buffer is exactly 1. A local attacker who can control the input buffer and size passed to getcwd() in a setuid program could use this flaw to potentially execute arbitrary code and… | |
| Modificada | Alta (7.5) | 1.8% | — | GNU GlibcNetapp Ontap Select Deploy Administration UtilityNetapp H300s FirmwareNetapp H500s Firmware+3 | 24/8/2022 | 17/6/2026 | A flaw was found in glibc. The realpath() function can mistakenly return an unexpected value, potentially leading to information leakage and disclosure of sensitive data. | |
| Modificada | Alta (7.8) | 0.28% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxNetapp H300s Firmware+4 | 23/8/2022 | 17/6/2026 | A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects. | |
| Modificada | Media (5.5) | 0.31% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxNetapp H300s Firmware+5 | 22/8/2022 | 17/6/2026 | An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system. | |
| Modificada | Alta (7.1) | 0.29% | — | Linux KernelFedoraproject FedoraNetapp H300s FirmwareNetapp H500s Firmware+3 | 5/8/2022 | 17/6/2026 | A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attacker to crash the system and leads to a kernel information leak problem. | |
| Modificada | Alta (7.8) | 0.90% | — | Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+2 | 29/7/2022 | 17/6/2026 | The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges. | |
| Modificada | Media (5.5) | 0.32% | — | Linux KernelDebian LinuxNetapp A700s FirmwareNetapp Active IQ Unified Manager+20 | 27/7/2022 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice. | |
| Modificada | Alta (7.1) | 0.31% | — | Linux KernelNetapp H300s FirmwareNetapp H500s FirmwareNetapp H700s Firmware+2 | 26/7/2022 | 17/6/2026 | A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw allows a local attacker to crash the system or leak internal kernel information. | |
| Analizada | Alta (7.8) | 0.31% | — | Netapp H300s FirmwareNetapp H500s FirmwareNetapp H700s FirmwareNetapp H410s Firmware+2 | 22/7/2022 | 2/10/2026 | io_uring use work_flags to determine which identity need to grab from the calling process to make sure it is consistent with the calling process when executing IORING_OP. Some operations are missing some types, which can lead to incorrect reference counts which can then lead to a double free. We recommend upgrading… |