Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

375 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.7%—Openbsd5/12/201917/6/2026
libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c).
ModificadaAlta (7.8)1.3%💥 PoCOpenbsd5/12/201917/6/2026
xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen.
ModificadaAlta (7.8)0.39%—Openbsd5/12/201917/6/2026
In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c.
ModificadaAlta (7.8)2.2%—Openbsd OpensshNetapp Cloud BackupNetapp Steelstore Cloud Integrated StorageSiemens Scalance X204rna Firmware+19/10/201917/6/2026
OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the…
ModificadaAlta (7.5)2.3%—Openbsd26/8/201917/6/2026
OpenBSD kernel version <= 6.5 can be forced to create long chains of TCP SACK holes that causes very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service.
ModificadaMedia (5.9)58%💥 ExploitOpenbsd OpensshWinscpCanonical Ubuntu LinuxDebian Linux+1531/1/201917/6/2026
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp…
ModificadaMedia (6.8)21%💥 ExploitOpenbsd OpensshWinscpNetapp Element SoftwareNetapp Ontap Select Deploy+331/1/201917/6/2026
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
ModificadaMedia (6.8)3.8%—Openbsd OpensshWinscpCanonical Ubuntu LinuxDebian Linux+1631/1/201917/6/2026
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects…
ModificadaMedia (5.3)3.7%—Openbsd OpensshWinscpNetapp Cloud BackupNetapp Element Software+1810/1/201917/6/2026
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
ModificadaMedia (5.3)3.6%—Openbsd OpensshNetapp Cloud BackupNetapp Data Ontap EdgeNetapp Ontap Select Deploy+228/8/201817/6/2026
Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a…
ModificadaMedia (5.3)99%💥 ExploitOpenbsd OpensshDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1817/8/201817/6/2026
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
ModificadaMedia (5.5)0.34%—Openbsd1/8/201817/6/2026
tss_alloc in sys/arch/i386/i386/gdt.c in OpenBSD 6.2 and 6.3 has a Local Denial of Service (system crash) due to incorrect I/O port access control on the i386 architecture.
ModificadaMedia (4.7)0.32%—Openbsd Libressl15/6/201817/6/2026
LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
ModificadaAlta (7.4)1.0%💥 PoCOpenbsd Libressl24/3/201817/6/2026
The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle attackers to spoof servers and obtain sensitive…
ModificadaAlta (7.5)16%💥 PoCOpenbsd OpensshDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+821/1/201817/6/2026
sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c.
ModificadaMedia (5.3)3.4%—Openbsd OpensshOracle SUN ZFS Storage Appliance KITDebian LinuxNetapp Active IQ Unified Manager+1726/10/201717/6/2026
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
ModificadaCrítica (9.8)4.0%—Openbsd OpensmtpdFedoraproject Fedora16/10/201717/6/2026
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.
ModificadaMedia (6.5)13%💥 ExploitOpenbsd19/6/201717/6/2026
The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code…
ModificadaCrítica (9.8)4.0%—Openbsd19/6/201717/6/2026
A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using setuid binaries such as /usr/bin/at. This affects OpenBSD 6.1 and possibly earlier versions.
ModificadaMedia (5.3)1.0%—Openbsd Libressl27/4/201717/6/2026
LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx.
ModificadaCrítica (9.8)14%—Openbsd OpensshDebian LinuxOracle LinuxRedhat Enterprise Linux Desktop+511/4/201717/6/2026
The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as…
ModificadaAlta (7.5)17%💥 ExploitOpenbsd27/3/201717/6/2026
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using an HTTP Range header.
ModificadaMedia (5.5)0.45%—Openbsd7/3/201717/6/2026
Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of service (kernel panic) via a crafted mmap call, which triggers the new mapping to overlap with an existing mapping.
ModificadaMedia (5.5)0.43%—Openbsd7/3/201717/6/2026
OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointer dereference and panic) via a sysctl call with a path starting with 10,9.
ModificadaMedia (5.5)0.43%—Openbsd7/3/201717/6/2026
OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_vnodelist.
Orbitaley — Vulnerabilidades