Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

2286 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.6)2.8%—C-ares Project C-aresFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux Computer Node+1323/11/202117/6/2026
A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system…
AnalizadaCrítica (9)100%⚠ Explotación activaResf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+3516/9/20216/8/2026
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
ModificadaMedia (6.5)1.2%—Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+927/5/202117/6/2026
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.
ModificadaBaja (3.7)1.6%—Nbdkit Project NbdkitRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux Server18/3/202117/6/2026
A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and…
ModificadaAlta (8.2)0.60%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each…
ModificadaMedia (6.7)1.0%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as…
ModificadaAlta (7.5)0.39%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this…
ModificadaMedia (6.7)0.57%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack buffer for temporary storage, without sufficient bounds checking. If the function is called with a command line that references a variable…
ModificadaAlta (7.6)0.79%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an attacker could trigger memory corruption leading to arbitrary code execution allowing a bypass of…
ModificadaAlta (8.2)1.2%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+43/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections.…
ModificadaAlta (7.5)1.7%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+53/3/202117/6/2026
A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the Linux kernel lockdown variable content…
ModificadaAlta (7.8)0.40%—Apple IcloudApple ItunesApple SafariApple Ipados+527/10/202017/6/2026
A logic issue was addressed with improved validation. This issue is fixed in iCloud for Windows 7.17, iTunes 12.10.4 for Windows, iCloud for Windows 10.9.2, tvOS 13.3.1, Safari 13.0.5, iOS 13.3.1 and iPadOS 13.3.1. A DOM object context may not have had a unique security origin.
ModificadaAlta (8.8)2.3%—Apple IcloudApple ItunesApple SafariApple Ipados+527/10/202017/6/2026
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.
ModificadaAlta (8.8)2.3%—Apple IcloudApple ItunesApple SafariApple Ipados+627/10/202017/6/2026
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, watchOS 6.1.1, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code…
ModificadaAlta (8.8)2.1%—Apple IcloudApple ItunesApple SafariApple Ipados+527/10/202017/6/2026
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in tvOS 13.3, iCloud for Windows 10.9, iOS 13.3 and iPadOS 13.3, Safari 13.0.4, iTunes 12.10.3 for Windows, iCloud for Windows 7.16. Processing maliciously crafted web content may lead to arbitrary code execution.
ModificadaAlta (7.5)89%—Apache Http ServerOracle Communications Element ManagerOracle Communications Session Report ManagerOracle Communications Session Route Manager+217/8/202017/6/2026
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.
ModificadaMedia (6)0.46%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+331/7/202017/6/2026
There is an issue with grub2 before version 2.06 while handling symlink on ext filesystems. A filesystem containing a symbolic link with an inode size of UINT32_MAX causes an arithmetic overflow leading to a zero-sized memory allocation with subsequent heap-based buffer overflow.
ModificadaMedia (6)0.48%—GNU Grub2Redhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux Server AUS+331/7/202017/6/2026
There is an issue on grub2 before version 2.06 at function read_section_as_string(). It expects a font name to be at max UINT32_MAX - 1 length in bytes but it doesn't verify it before proceed with buffer allocation to read the value from the font value. An attacker may leverage that by crafting a malicious font file…
ModificadaAlta (8.8)0.38%—DockerRedhat Enterprise Linux Server13/7/202017/6/2026
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in that update was the…
ModificadaAlta (8.8)0.32%—DockerRedhat Openshift Container PlatformRedhat Enterprise Linux Server13/7/202017/6/2026
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the container host and…
ModificadaMedia (6.1)0.35%—Kernel SelinuxRedhat Enterprise Linux Server26/5/202017/6/2026
A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where it incorrectly assumed that an skb would only contain a single netlink message. The hook would incorrectly only validate the first netlink message in the skb and allow or deny the rest of the messages within the skb with…
ModificadaMedia (5.9)3.1%—Linux KernelRedhat 3scaleRedhat OpenstackRedhat Virtualization Host+722/5/202017/6/2026
A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SELinux extensible bitmap via the' ebitmap_netlbl_import' routine. While processing the CIPSO…
ModificadaAlta (8.8)2.7%—Icu-project International Components FOR UnicodeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+712/3/202017/6/2026
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.
AnalizadaAlta (8.8)79%⚠ Explotación activaGoogle ChromeFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+227/2/202017/6/2026
Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)1.7%—Google ChromeFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+227/2/202017/6/2026
Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.