Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
375 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.7% | — | Openbsd | 5/12/2019 | 17/6/2026 | libc in OpenBSD 6.6 allows authentication bypass via the -schallenge username, as demonstrated by smtpd, ldapd, or radiusd. This is related to gen/auth_subr.c and gen/authenticate.c in libc (and login/login.c and xenocara/app/xenodm/greeter/verify.c). | |
| Modificada | Alta (7.8) | 1.3% | 💥 PoC | Openbsd | 5/12/2019 | 17/6/2026 | xlock in OpenBSD 6.6 allows local users to gain the privileges of the auth group by providing a LIBGL_DRIVERS_PATH environment variable, because xenocara/lib/mesa/src/loader/loader.c mishandles dlopen. | |
| Modificada | Alta (7.8) | 0.39% | — | Openbsd | 5/12/2019 | 17/6/2026 | In OpenBSD 6.6, local users can use the su -L option to achieve any login class (often excluding root) because there is a logic error in the main function in su/su.c. | |
| Modificada | Alta (7.8) | 2.2% | — | Openbsd OpensshNetapp Cloud BackupNetapp Steelstore Cloud Integrated StorageSiemens Scalance X204rna Firmware+1 | 9/10/2019 | 17/6/2026 | OpenSSH 7.7 through 7.9 and 8.x before 8.1, when compiled with an experimental key type, has a pre-authentication integer overflow if a client or server is configured to use a crafted XMSS key. This leads to memory corruption and local code execution because of an error in the XMSS key parsing algorithm. NOTE: the… | |
| Modificada | Alta (7.5) | 2.3% | — | Openbsd | 26/8/2019 | 17/6/2026 | OpenBSD kernel version <= 6.5 can be forced to create long chains of TCP SACK holes that causes very expensive calls to tcp_sack_option() for every incoming SACK packet which can lead to a denial of service. | |
| Modificada | Media (5.9) | 58% | 💥 Exploit | Openbsd OpensshWinscpCanonical Ubuntu LinuxDebian Linux+15 | 31/1/2019 | 17/6/2026 | An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp… | |
| Modificada | Media (6.8) | 21% | 💥 Exploit | Openbsd OpensshWinscpNetapp Element SoftwareNetapp Ontap Select Deploy+3 | 31/1/2019 | 17/6/2026 | In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred. | |
| Modificada | Media (6.8) | 3.8% | — | Openbsd OpensshWinscpCanonical Ubuntu LinuxDebian Linux+16 | 31/1/2019 | 17/6/2026 | An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects… | |
| Modificada | Media (5.3) | 3.7% | — | Openbsd OpensshWinscpNetapp Cloud BackupNetapp Element Software+18 | 10/1/2019 | 17/6/2026 | In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. | |
| Modificada | Media (5.3) | 3.6% | — | Openbsd OpensshNetapp Cloud BackupNetapp Data Ontap EdgeNetapp Ontap Select Deploy+2 | 28/8/2018 | 17/6/2026 | Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a… | |
| Modificada | Media (5.3) | 99% | 💥 Exploit | Openbsd OpensshDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+18 | 17/8/2018 | 17/6/2026 | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c. | |
| Modificada | Media (5.5) | 0.34% | — | Openbsd | 1/8/2018 | 17/6/2026 | tss_alloc in sys/arch/i386/i386/gdt.c in OpenBSD 6.2 and 6.3 has a Local Denial of Service (system crash) due to incorrect I/O port access control on the i386 architecture. | |
| Modificada | Media (4.7) | 0.32% | — | Openbsd Libressl | 15/6/2018 | 17/6/2026 | LibreSSL before 2.6.5 and 2.7.x before 2.7.4 allows a memory-cache side-channel attack on DSA and ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover a key, the attacker needs access to either the local machine or a different virtual machine on the same physical host. | |
| Modificada | Alta (7.4) | 1.0% | 💥 PoC | Openbsd Libressl | 24/3/2018 | 17/6/2026 | The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle attackers to spoof servers and obtain sensitive… | |
| Modificada | Alta (7.5) | 16% | 💥 PoC | Openbsd OpensshDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+8 | 21/1/2018 | 17/6/2026 | sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c. | |
| Modificada | Media (5.3) | 3.4% | — | Openbsd OpensshOracle SUN ZFS Storage Appliance KITDebian LinuxNetapp Active IQ Unified Manager+17 | 26/10/2017 | 17/6/2026 | The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files. | |
| Modificada | Crítica (9.8) | 4.0% | — | Openbsd OpensmtpdFedoraproject Fedora | 16/10/2017 | 17/6/2026 | Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta. | |
| Modificada | Media (6.5) | 13% | 💥 Exploit | Openbsd | 19/6/2017 | 17/6/2026 | The OpenBSD qsort() function is recursive, and not randomized, an attacker can construct a pathological input array of N elements that causes qsort() to deterministically recurse N/4 times. This allows attackers to consume arbitrary amounts of stack memory and manipulate stack memory to assist in arbitrary code… | |
| Modificada | Crítica (9.8) | 4.0% | — | Openbsd | 19/6/2017 | 17/6/2026 | A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using setuid binaries such as /usr/bin/at. This affects OpenBSD 6.1 and possibly earlier versions. | |
| Modificada | Media (5.3) | 1.0% | — | Openbsd Libressl | 27/4/2017 | 17/6/2026 | LibreSSL 2.5.1 to 2.5.3 lacks TLS certificate verification if SSL_get_verify_result is relied upon for a later check of a verification result, in a use case where a user-provided verification callback returns 1, as demonstrated by acceptance of invalid certificates by nginx. | |
| Modificada | Crítica (9.8) | 14% | — | Openbsd OpensshDebian LinuxOracle LinuxRedhat Enterprise Linux Desktop+5 | 11/4/2017 | 17/6/2026 | The client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for access-control decisions, which allows remote X11 clients to trigger a fallback and obtain trusted X11 forwarding privileges by leveraging configuration issues on this X11 server, as… | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | Openbsd | 27/3/2017 | 17/6/2026 | httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for a large file using an HTTP Range header. | |
| Modificada | Media (5.5) | 0.45% | — | Openbsd | 7/3/2017 | 17/6/2026 | Integer overflow in the uvm_map_isavail function in uvm/uvm_map.c in OpenBSD 5.9 allows local users to cause a denial of service (kernel panic) via a crafted mmap call, which triggers the new mapping to overlap with an existing mapping. | |
| Modificada | Media (5.5) | 0.43% | — | Openbsd | 7/3/2017 | 17/6/2026 | OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointer dereference and panic) via a sysctl call with a path starting with 10,9. | |
| Modificada | Media (5.5) | 0.43% | — | Openbsd | 7/3/2017 | 17/6/2026 | OpenBSD 5.8 and 5.9 allows certain local users to cause a denial of service (kernel panic) by unmounting a filesystem with an open vnode on the mnt_vnodelist. |