Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
368 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.0% | — | Redhat Ovirt-engineRedhat Virtualization | 22/11/2019 | 17/6/2026 | oVirt users with MANIPULATE_STORAGE_DOMAIN permissions can attach a storage domain to any data-center | |
| Modificada | Media (6.5) | 3.1% | — | Opensuse LeapFedoraproject FedoraSlackwareHP Apollo 4200 Firmware+156 | 14/11/2019 | 17/6/2026 | TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. | |
| Modificada | Alta (7.5) | 2.8% | — | Dpdk Data Plane Development KITRedhat Enterprise Linux Fast DatapathRedhat OpenstackRedhat Virtualization EUS+1 | 14/11/2019 | 17/6/2026 | A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This… | |
| Modificada | Media (5.9) | 0.73% | — | Redhat Enterprise VirtualizationRedhat VdsclientRedhat Virtual Desktop Server Manager | 13/11/2019 | 17/6/2026 | vdsm and vdsclient does not validate certficate hostname from another vdsm which could facilitate a man-in-the-middle attack | |
| Modificada | Baja (3.1) | 0.35% | — | Redhat Enterprise Virtualization Manager | 9/11/2019 | 16/6/2026 | In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterprise Virtualization Manager. An attacker on the local network… | |
| Modificada | Media (5.5) | 0.42% | — | Redhat Virtual Desktop Server ManagerRedhat Enterprise VirtualizationRedhat Storage | 4/11/2019 | 16/6/2026 | Insecure temporary file vulnerability in RedHat vsdm 4.9.6. | |
| Modificada | Media (6.1) | 0.91% | — | Redhat CloudformsRedhat Manageiq Enterprise Virtualization Manager | 1/11/2019 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in ManageIQ EVM allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (8.8) | 64% | — | Sudo Project SudoFedoraproject FedoraDebian LinuxOpensuse Leap+11 | 17/10/2019 | 17/6/2026 | In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u… | |
| Modificada | Alta (7.8) | 0.91% | — | Linux KernelRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux Compute Node EUS+35 | 20/9/2019 | 17/6/2026 | There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | |
| Modificada | Alta (8.8) | 0.76% | — | Linux KernelRedhat Virtualization HostRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+24 | 19/9/2019 | 17/6/2026 | An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be… | |
| Modificada | Alta (7.8) | 0.62% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+30 | 17/9/2019 | 17/6/2026 | A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could… | |
| Modificada | Media (5.6) | 4.5% | — | Microsoft Windows 10Microsoft Windows 7Microsoft Windows 8.1Microsoft Windows RT 8.1+11 | 3/9/2019 | 17/6/2026 | An information disclosure vulnerability exists when certain central processing units (CPU) speculatively access memory. An attacker who successfully exploited the vulnerability could read privileged data across trust boundaries. To exploit this vulnerability, an attacker would have to log on to an affected system and… | |
| Modificada | Media (6.5) | 1.6% | — | Cisco Enterprise Network Function Virtualization Infrastructure Sofware | 21/8/2019 | 17/6/2026 | A vulnerability in Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker with administrator privileges to overwrite files on the underlying operating system (OS) of an affected device. The vulnerability is due to improper input validation in an… | |
| Modificada | Media (4.3) | 1.2% | — | Cisco Enterprise Network Functions Virtualization Infrastructure | 21/8/2019 | 17/6/2026 | A vulnerability in the web server functionality of Cisco Enterprise Network Functions Virtualization Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform file enumeration on an affected system. The vulnerability is due to the web server responding with different error codes for… | |
| Modificada | Alta (7.3) | 28% | — | Apache Commons BeanutilsApache NifiDebian LinuxOpensuse Leap+56 | 20/8/2019 | 25/8/2026 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, however were not using this by default characteristic of the PropertyUtilsBean. | |
| Modificada | Alta (8.1) | 2.7% | — | Google AndroidApple Iphone OSApple MAC OS XApple Tvos+143 | 14/8/2019 | 17/6/2026 | The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the… | |
| Modificada | Alta (7.8) | 0.55% | — | Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+5 | 2/8/2019 | 17/6/2026 | The virConnectBaselineHypervisorCPU() and virConnectCompareHypervisorCPU() libvirt APIs, 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accept an "emulator" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only… | |
| Modificada | Alta (7.8) | 0.52% | — | Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+5 | 2/8/2019 | 17/6/2026 | The virConnectGetDomainCapabilities() libvirt API, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, accepts an "emulatorbin" argument to specify the program providing emulation for a domain. Since v1.2.19, libvirt will execute that program to probe the domain's capabilities. Read-only clients could specify an… | |
| Modificada | Alta (7.8) | 0.47% | — | Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+5 | 2/8/2019 | 17/6/2026 | It was discovered that libvirtd, versions 4.x.x before 4.10.1 and 5.x.x before 5.4.1, would permit readonly clients to use the virDomainManagedSaveDefineXML() API, which would permit them to modify managed save state files. If a managed save had already been created by a privileged user, a local attacker could modify… | |
| Modificada | Alta (7.8) | 0.52% | — | Redhat LibvirtRedhat Enterprise LinuxRedhat VirtualizationRedhat Virtualization Host+1 | 30/7/2019 | 17/6/2026 | It was discovered that libvirtd before versions 4.10.1 and 5.4.1 would permit read-only clients to use the virDomainSaveImageGetXMLDesc() API, specifying an arbitrary path which would be accessed with the permissions of the libvirtd process. An attacker with access to the libvirtd socket could use this to probe the… | |
| Modificada | Crítica (9.1) | 5.0% | — | LodashNetapp Active IQ Unified ManagerNetapp Service Level ManagerRedhat Virtualization Manager+17 | 26/7/2019 | 17/6/2026 | Versions of lodash lower than 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep could be tricked into adding or modifying properties of Object.prototype using a constructor payload. | |
| Modificada | Media (5.5) | 0.34% | — | OvirtRedhat Virtualization Manager | 11/7/2019 | 17/6/2026 | Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could be disclosed in log files (if playbooks are run with -v) or in playbooks stored on Metrics or Bastion hosts. | |
| Modificada | Media (5.3) | 1.6% | — | AMD Secure Encrypted Virtualization FirmwareOpensuse Leap | 25/6/2019 | 17/6/2026 | Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation. | |
| Modificada | Alta (7.5) | 92% | — | Linux KernelF5 Big-ip Advanced Firewall ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Application Acceleration Manager+17 | 19/6/2019 | 17/6/2026 | Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182,… | |
| Modificada | Crítica (9.8) | 6.8% | — | Linux KernelRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux AUS+19 | 14/6/2019 | 17/6/2026 | A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences. |