Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

175 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.19%—Philips Veradius Unity FirmwarePhilips Pulsera FirmwarePhilips Endura Firmware20/12/201917/6/2026
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018), Pulsera (718095) and Endura (718075) with wireless option (shipped…
ModificadaMedia (6.5)1.8%—FreeradiusRedhat Enterprise LinuxOpensuse Leap3/12/201917/6/2026
In FreeRADIUS 3.0 through 3.0.19, on average 1 in every 2048 EAP-pwd handshakes fails because the password element cannot be found within 10 iterations of the hunting and pecking loop. This leaks information that an attacker can use to recover the password of any user. This information leakage is similar to the…
ModificadaMedia (6.1)4.0%—Pfsense-pkg-freeradius32/11/201917/6/2026
/usr/local/www/freeradius_view_config.php in the freeradius3 package before 0.15.7_3 for pfSense on FreeBSD allows a user with an XSS payload as password or username to execute arbitrary javascript code on a victim browser.
ModificadaAlta (7)0.34%—FreeradiusFedoraproject FedoraRedhat Enterprise Linux24/5/201917/6/2026
It was discovered freeradius up to and including version 3.0.19 does not correctly configure logrotate, allowing a local attacker who already has control of the radiusd user to escalate his privileges to root, by tricking logrotate into writing a radiusd-writable file to a directory normally inaccessible by the…
ModificadaCrítica (9.8)3.6%—FreeradiusFedoraproject FedoraRedhat Enterprise LinuxRedhat Enterprise Linux EUS+622/4/201917/6/2026
FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499.
ModificadaCrítica (9.8)7.6%—FreeradiusFedoraproject FedoraRedhat Enterprise LinuxCanonical Ubuntu Linux22/4/201917/6/2026
FreeRADIUS before 3.0.19 does not prevent use of reflection for authentication spoofing, aka a "Dragonblood" issue, a similar issue to CVE-2019-9497.
ModificadaAlta (8.1)2.2%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+517/4/201917/6/2026
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both…
ModificadaAlta (8.1)2.2%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+517/4/201917/6/2026
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and…
ModificadaBaja (3.7)3.5%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+517/4/201917/6/2026
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access…
ModificadaMedia (5.9)3.9%—W1.fi HostapdW1.fi WPA SupplicantFedoraproject FedoraOpensuse Backports SLE+417/4/201917/6/2026
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information from a side channel attack that can be used for full password recovery. Both hostapd with SAE…
ModificadaAlta (7.5)3.0%—Freeradius17/7/201717/6/2026
An FR-GV-304 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Buffer over-read in fr_dhcp_decode_suboptions()" and a denial of service.
ModificadaAlta (7.5)3.0%—Freeradius17/7/201717/6/2026
An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcp_attr2vp()" and a denial of service.
ModificadaAlta (7.5)3.3%—Freeradius17/7/201717/6/2026
An FR-GV-302 issue in FreeRADIUS 3.x before 3.0.15 allows "Infinite loop and memory exhaustion with 'concat' attributes" and a denial of service.
ModificadaCrítica (9.8)6.4%—Freeradius17/7/201717/6/2026
An FR-GV-301 issue in FreeRADIUS 3.x before 3.0.15 allows "Write overflow in data2vp_wimax()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.
ModificadaAlta (7.5)3.4%—Freeradius17/7/201717/6/2026
An FR-GV-206 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "DHCP - Read overflow when decoding option 63" and a denial of service.
ModificadaAlta (7.5)3.8%—Freeradius17/7/201717/6/2026
An FR-GV-205 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Buffer over-read in fr_dhcp_decode_options()" and a denial of service.
ModificadaAlta (7.5)3.4%—Freeradius17/7/201717/6/2026
An FR-GV-204 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in fr_dhcp_decode()" and a denial of service.
ModificadaAlta (7.5)3.4%—Freeradius17/7/201717/6/2026
An FR-GV-203 issue in FreeRADIUS 2.x before 2.2.10 allows "DHCP - Memory leak in decode_tlv()" and a denial of service.
ModificadaCrítica (9.8)7.0%—Freeradius17/7/201717/6/2026
An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.
ModificadaAlta (7.5)3.8%—FreeradiusDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+417/7/201717/6/2026
An FR-GV-201 issue in FreeRADIUS 2.x before 2.2.10 and 3.x before 3.0.15 allows "Read / write overflow in make_secret()" and a denial of service.
ModificadaCrítica (9.8)3.9%—Freeradius29/5/201717/6/2026
The TLS session cache in FreeRADIUS 2.1.1 through 2.1.7, 3.0.x before 3.0.14, 3.1.x before 2017-02-04, and 4.0.x before 2017-02-04 fails to reliably prevent resumption of an unauthenticated session, which allows remote attackers (such as malicious 802.1X supplicants) to bypass authentication via PEAP or TTLS.
ModificadaAlta (7.5)1.8%—FreeradiusSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT5/4/201717/6/2026
FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.
ModificadaAlta (8.1)1.1%—Freeradius27/3/201717/6/2026
Off-by-one error in the EAP-PWD module in FreeRADIUS 3.0 through 3.0.8, which triggers a buffer overflow.
ModificadaAlta (8.1)1.2%—Freeradius27/3/201717/6/2026
The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to have unspecified impact via a crafted (1) commit or (2) confirm message, which triggers an out-of-bounds read.
ModificadaMedia (5.9)1.6%—Freeradius27/3/201717/6/2026
The EAP-PWD module in FreeRADIUS 3.0 through 3.0.8 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a zero-length EAP-PWD packet.
Orbitaley — Vulnerabilidades