Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
268 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.3% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 11/2/2019 | 17/6/2026 | In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it. | |
| Modificada | Crítica (9.8) | 2.7% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 11/2/2019 | 17/6/2026 | In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly callable by non-native user code. | |
| Modificada | Media (5.3) | 9.4% | — | LibpngDebian LinuxCanonical Ubuntu LinuxOracle Hyperion Infrastructure Technology+28 | 4/2/2019 | 17/6/2026 | png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute. | |
| Modificada | Alta (7.2) | 1.0% | — | Redhat Satellite | 22/1/2019 | 17/6/2026 | An improper authorization flaw was found in the Smart Class feature of Foreman. An attacker can use it to change configuration of any host registered in Red Hat Satellite, independent of the organization the host belongs to. This flaw affects all Red Hat Satellite 6 versions. | |
| Modificada | Baja (3.1) | 3.0% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+7 | 16/1/2019 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). The supported version that is affected is Java SE: 8u192. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human… | |
| Modificada | Baja (3.1) | 3.4% | — | Oracle JDKOracle JRECanonical Ubuntu LinuxNetapp Oncommand Unified Manager+14 | 16/1/2019 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 7u201, 8u192 and 11.0.1; Java SE Embedded: 8u191. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE.… | |
| Modificada | Media (5.4) | 1.00% | — | Redhat SatelliteTheforeman Katello | 13/1/2019 | 17/6/2026 | A cross-site scripting (XSS) flaw was found in the katello component of Satellite. An attacker with privilege to create/edit organizations and locations is able to execute a XSS attacks against other users through the Subscriptions or the Red Hat Repositories wizards. This can possibly lead to malicious code execution… | |
| Modificada | Media (5.3) | 6.9% | — | Oracle JDKOracle JREOracle JrockitRedhat Satellite+10 | 17/10/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Sound). Supported versions that are affected are Java SE: 6u201, 7u191 and 8u182; Java SE Embedded: 8u181; JRockit: R28.3.19. Easily exploitable vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Crítica (9) | 2.8% | — | Oracle JDKOracle JREOracle JrockitRedhat Satellite+10 | 17/10/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Scripting). Supported versions that are affected are Java SE: 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple… | |
| Modificada | Media (5.6) | 3.4% | — | Oracle JDKOracle JREOracle JrockitRedhat Satellite+10 | 17/10/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Alta (8.3) | 4.4% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+9 | 17/10/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Alta (8.3) | 7.2% | — | Oracle JDKOracle JREOracle JrockitRedhat Satellite+10 | 17/10/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JNDI). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181; JRockit: R28.3.19. Difficult to exploit vulnerability allows unauthenticated attacker with network access via… | |
| Modificada | Baja (3.1) | 5.1% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+9 | 17/10/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Baja (3.4) | 4.5% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+9 | 17/10/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u201, 7u191, 8u182 and 11; Java SE Embedded: 8u181. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (5.4) | 0.48% | — | Redhat Satellite | 22/8/2018 | 17/6/2026 | It was found that Satellite 5 configured with SSL/TLS for the PostgreSQL backend failed to correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a PostgreSQL server using a specially crafted X.509 certificate. | |
| Modificada | Media (6.5) | 4.5% | — | IBM SDKRedhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 20/8/2018 | 17/6/2026 | The IBM Java Runtime Environment's Diagnostic Tooling Framework for Java (DTFJ) (IBM SDK, Java Technology Edition 6.0 , 7.0, and 8.0) does not protect against path traversal attacks when extracting compressed dump files. IBM X-Force ID: 144882. | |
| Modificada | Alta (7.5) | 4.0% | — | IBM Software Development KITRedhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 20/8/2018 | 17/6/2026 | A flaw in the java.math component in IBM SDK, Java Technology Edition 6.0, 7.0, and 8.0 may allow an attacker to inflict a denial-of-service attack with specially crafted String data. IBM X-Force ID: 141681. | |
| Modificada | Alta (7.5) | 6.6% | — | Dom4j Project Dom4jDebian LinuxOracle Flexcube Investor ServicingOracle Primavera P6 Enterprise Project Portfolio Management+10 | 20/8/2018 | 17/6/2026 | dom4j version prior to version 2.1.1 contains a CWE-91: XML Injection vulnerability in Class: Element. Methods: addElement, addAttribute that can result in an attacker tampering with XML documents through XML injection. This attack appear to be exploitable via an attacker specifying attributes or elements in the XML… | |
| Modificada | Crítica (9.8) | 68% | — | Cobbler Project CobblerRedhat Satellite | 9/8/2018 | 17/6/2026 | It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon. | |
| Modificada | Media (5.4) | 1.2% | — | Theforeman ForemanRedhat SatelliteRedhat Satellite Capsule | 1/8/2018 | 17/6/2026 | It was found that foreman before 1.13.0 is vulnerable to a stored XSS via an organization or location name. This could allow an attacker with privileges to set the organization or location name to display arbitrary HTML including scripting code within the web interface. | |
| Modificada | Media (5.4) | 0.64% | — | Redhat Satellite | 30/7/2018 | 17/6/2026 | A cross-site scripting (XSS) flaw was found in how the failed action entry is processed in Red Hat Satellite before version 5.8.0. A user able to specify a failed action could exploit this flaw to perform XSS attacks against other Satellite users. | |
| Modificada | Media (5.5) | 0.40% | — | Theforeman KatelloRedhat SatelliteRedhat Satellite Capsule | 27/7/2018 | 17/6/2026 | A flaw was found in katello-debug before 3.4.0 where certain scripts and log files used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files. | |
| Modificada | Crítica (9.8) | 2.1% | — | Redhat SpacewalkRedhat Satellite | 27/7/2018 | 17/6/2026 | It was found that spacewalk-channel can be used by a non-admin user or disabled users to perform administrative tasks due to an incorrect authorization check in backend/server/rhnChannel.py. | |
| Modificada | Media (5.4) | 1.1% | — | Redhat Satellite | 26/7/2018 | 17/6/2026 | Red Hat Satellite before 6.5 is vulnerable to a XSS in discovery rule when you are entering filter and you use autocomplete functionality. | |
| Modificada | Media (5.4) | 0.75% | — | Redhat Satellite | 26/7/2018 | 17/6/2026 | A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an organization's name could exploit this flaw to perform XSS attacks against other Satellite users. |