Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
136 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.38% | — | Joyent Smartos | 21/2/2018 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Alta (7) | 0.50% | — | Joyent SmartosOracle SolarisOracle ZFS Storage Appliance | 21/2/2018 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Media (5.5) | 0.52% | — | Joyent Smartos | 31/1/2017 | 17/6/2026 | An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploited this will result in memory… | |
| Modificada | Alta (7) | 0.54% | — | Joyent Smartos | 14/12/2016 | 17/6/2026 | An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a buffer overflow in the path variable… | |
| Modificada | Alta (7) | 0.53% | — | Joyent Smartos | 14/12/2016 | 17/6/2026 | An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with 32-bit file systems. An attacker can craft an input that can cause a buffer overflow in the nm variable… | |
| Modificada | Alta (7) | 0.53% | — | Joyent Smartos | 14/12/2016 | 17/6/2026 | An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a buffer overflow in the path variable… | |
| Modificada | Alta (7) | 0.53% | — | Joyent Smartos | 14/12/2016 | 17/6/2026 | An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a buffer overflow in the nm variable… | |
| Modificada | Alta (7.8) | 0.49% | — | Joyent Smartos | 14/12/2016 | 17/6/2026 | An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with 32-bit file systems. An attacker can craft an input that can cause a kernel panic and potentially be… | |
| Modificada | Alta (8.8) | 0.55% | — | Joyent Smartos | 14/12/2016 | 17/6/2026 | An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a kernel panic and potentially be… | |
| Modificada | Media (4.9) | 0.95% | 💥 Exploit | Blackberry QNX Neutrino Rtos | 18/3/2014 | 17/6/2026 | /sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow. | |
| Modificada | Alta (7.2) | 2.9% | 💥 Exploit | Blackberry QNX Neutrino Rtos | 18/3/2014 | 17/6/2026 | /sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arbitrary program name as a command-line argument. | |
| Modificada | Media (5.4) | 6.7% | — | Blackberry QNX Software Development PlatformBlackberry QNX Neutrino Rtos | 12/7/2013 | 16/6/2026 | Buffer overflow in phrelay in BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP port 4868 that leverage improper handling of the /dev/photon… | |
| Modificada | Alta (7.8) | 8.2% | — | Blackberry QNX Momentics Tool SuiteBlackberry QNX Software Development PlatformBlackberry QNX Neutrino Rtos | 12/7/2013 | 16/6/2026 | Stack-based buffer overflow in the bpe_decompress function in (1) BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 and (2) QNX Momentics Tool Suite through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via… | |
| Modificada | Alta (7.2) | 40% | 💥 Exploit | FreebsdIllumosJoyent SmartosXEN+7 | 12/6/2012 | 16/6/2026 | The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008… | |
| Modificada | Baja (3.3) | 0.30% | — | QNX Neutrino Rtos | 18/10/2011 | 16/6/2026 | The runtime linker in QNX Neutrino RTOS 6.5.0 before Service Pack 1 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environment variables when a program is spawned from a setuid program, which allows local users to overwrite files via a symlink attack. | |
| Modificada | Media (6.2) | 0.80% | 💥 Exploit | QNX Rtos | 9/2/2006 | 16/6/2026 | Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows local users to execute arbitrary code via unspecified manipulations of the PHFONT and PHOTON2_PATH environment variables. | |
| Modificada | Media (4.6) | 0.50% | — | QNX Rtos | 9/2/2006 | 16/6/2026 | Multiple stack-based buffer overflows in QNX Neutrino RTOS 6.3.0 allow local users to execute arbitrary code via long (1) ABLPATH or (2) ABLANG environment variables in the libAP library (libAp.so.2) or (3) a long PHOTON_PATH environment variable to the setitem function in the libph library. | |
| Modificada | Media (4.9) | 0.48% | — | QNX Rtos | 9/2/2006 | 16/6/2026 | QNX Neutrino RTOS 6.3.0 allows local users to cause a denial of service (hang) by supplying a "break *0xb032d59f" command to gdb. | |
| Modificada | Alta (7.2) | 0.50% | — | QNX Rtos | 9/2/2006 | 16/6/2026 | Multiple buffer overflows in QNX Neutrino RTOS 6.2.0 allow local users to execute arbitrary code via a long first argument to the (1) su or (2) passwd commands. | |
| Modificada | Alta (7.2) | 0.91% | 💥 Exploit | QNX Rtos | 9/2/2006 | 16/6/2026 | QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the file and execute arbitrary code at system startup. | |
| Modificada | Media (4.6) | 0.41% | — | QNX Neutrino Rtos | 9/2/2006 | 16/6/2026 | Format string vulnerability in fontsleuth in QNX Neutrino RTOS 6.3.0 allows local users to execute arbitrary code via format string specifiers in the zeroth argument (program name). | |
| Modificada | Alta (7.2) | 0.84% | 💥 Exploit | QNX Rtos | 31/12/2005 | 16/6/2026 | Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LD_LIBRARY_PATH environment variable that references a malicious library. | |
| Modificada | Media (4.6) | 1.2% | 💥 Exploit | QNX Rtos | 30/11/2005 | 16/6/2026 | Buffer overflow in phgrafx in QNX 6.2.1 and 6.3.0 allows local users to execute arbitrary code via a long command line argument. | |
| Modificada | Baja (2.1) | 0.83% | 💥 Exploit | QNX Rtos | 30/8/2005 | 16/6/2026 | The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the -t flag is specified, which allows local users to read arbitrary files. | |
| Modificada | Media (4.6) | 0.56% | — | QNX RtosQNX RTP | 31/12/2004 | 16/6/2026 | Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program. |