Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
4185 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.29% | — | Canonical Ubuntu Linux | 12/6/2021 | 17/6/2026 | It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could expose private data to other local users. | |
| Modificada | Media (5.5) | 0.30% | — | Canonical Ubuntu Linux | 12/6/2021 | 17/6/2026 | It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could expose private data to other local users. | |
| Modificada | Alta (8.8) | 0.64% | — | Linux KernelCanonical Ubuntu Linux | 4/6/2021 | 17/6/2026 | The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc/<PID>/mem. This could be used to create a heap overflow leading to arbitrary code execution in the kernel. It was addressed via… | |
| Modificada | Alta (7.8) | 27% | 💥 Exploit | Linux KernelCanonical Ubuntu Linux | 4/6/2021 | 17/6/2026 | The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue was fixed via commit 049c4e13714e ("bpf: Fix alu32 const subreg… | |
| Modificada | Alta (7.8) | 0.55% | — | Linux KernelCanonical Ubuntu Linux | 4/6/2021 | 17/6/2026 | The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue was fixed via commit 4b81ccebaeee ("bpf, ringbuf: Deny… | |
| Modificada | Alta (7.5) | 4.9% | — | OpenvpnFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux | 26/4/2021 | 17/6/2026 | OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks. | |
| Analizada | Alta (7.8) | 49% | ⚠ Explotación activa💥 Exploit | Canonical Ubuntu Linux | 17/4/2021 | 17/6/2026 | The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts,… | |
| Modificada | Alta (7.8) | 1.5% | 💥 PoC | Canonical Ubuntu Linux | 17/4/2021 | 17/6/2026 | Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory… | |
| Modificada | Media (4.3) | 1.3% | — | Canonical Unity-firefox-extensionCanonical Ubuntu Linux | 7/4/2021 | 16/6/2026 | The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher and updating it with new callbacks until the libunity-webapps rate limit was hit. Fixed in… | |
| Modificada | Media (6.5) | 1.3% | — | Canonical Unity-firefox-extensionCanonical Ubuntu Linux | 7/4/2021 | 16/6/2026 | The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the… | |
| Modificada | Alta (7.8) | 0.61% | — | Linux KernelDebian LinuxCanonical Ubuntu Linux | 23/3/2021 | 17/6/2026 | The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly… | |
| Modificada | Media (6) | 0.58% | — | Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux | 20/3/2021 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory,… | |
| Modificada | Media (4.7) | 0.56% | — | Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux | 20/3/2021 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types… | |
| Analizada | Alta (7.1) | 0.97% | — | Netapp Cloud BackupLinux KernelDebian LinuxNetapp Solidfire Baseboard Management Controller Firmware+2 | 7/3/2021 | 30/7/2026 | An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages. | |
| Modificada | Media (4.4) | 0.41% | — | Linux KernelCanonical Ubuntu Linux | 10/2/2021 | 17/6/2026 | Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were allowed. It was possible to have a file not readable by an unprivileged user to be copied to a mountpoint controlled by… | |
| Modificada | Alta (7.8) | 0.42% | — | Linux KernelCanonical Ubuntu LinuxDebian Linux | 14/1/2021 | 17/6/2026 | Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4.0-51.56, 5.3.0-68.63, 4.15.0-121.123, 4.4.0-193.224, 3.13.0.182.191 and 3.2.0-149.196. | |
| Analizada | Media (5.5) | 1.5% | — | Gnome Gdk-pixbufCanonical Ubuntu LinuxFedoraproject Fedora | 26/12/2020 | 17/6/2026 | GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the… | |
| Modificada | Media (5.5) | 0.29% | — | Canonical Ubuntu Linux | 9/12/2020 | 17/6/2026 | Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5. | |
| Modificada | Baja (3.8) | 0.34% | — | Canonical Ubuntu Linux | 9/12/2020 | 17/6/2026 | The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5. | |
| Modificada | Media (6.8) | 0.70% | — | Canonical SnapcraftCanonical Ubuntu Linux | 4/12/2020 | 17/6/2026 | In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and… | |
| Modificada | Media (4.7) | 0.32% | — | Canonical Ubuntu Linux | 4/12/2020 | 17/6/2026 | An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missing, allowing the snap to connect to PulseAudio without proper confinement. This could be exploited by an attacker to… | |
| Modificada | Media (4.7) | 0.40% | — | Linux KernelCanonical Ubuntu Linux | 28/11/2020 | 17/6/2026 | An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1e176e. | |
| Modificada | Media (5.7) | 0.56% | — | Intel Ax201 FirmwareIntel Ax200 FirmwareIntel AC 9560 FirmwareIntel AC 9462 Firmware+11 | 23/11/2020 | 17/6/2026 | Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.34% | — | Packagekit Project PackagekitCanonical Ubuntu Linux | 7/11/2020 | 17/6/2026 | PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages. | |
| Modificada | Baja (3.3) | 0.47% | — | Packagekit Project PackagekitCanonical Ubuntu Linux | 7/11/2020 | 17/6/2026 | PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own. |