Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.82% | — | Netapp Clustered Data Ontap | 9/10/2019 | 17/6/2026 | Clustered Data ONTAP versions 9.0 and higher do not enforce hostname verification under certain circumstances making them susceptible to impersonation via man-in-the-middle attacks. | |
| Modificada | Media (6.1) | 81% | 💥 Exploit | Apache Http ServerOpensuse LeapDebian LinuxRedhat Software Collection+6 | 26/9/2019 | 17/6/2026 | In Apache HTTP Server 2.4.0-2.4.39, a limited cross-site scripting issue was reported affecting the mod_proxy error page. An attacker could cause the link on the error page to be malformed and instead point to a page of their choice. This would only be exploitable where a server was set up with proxying enabled but… | |
| Modificada | Alta (7.5) | 0.91% | — | FreebsdNetapp Clustered Data Ontap | 30/8/2019 | 17/6/2026 | In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, the kernel driver for /dev/midistat implements a read handler that is not thread-safe. A multi-threaded program can exploit races in… | |
| Modificada | Alta (7.5) | 4.4% | — | FreebsdNetapp Clustered Data Ontap | 30/8/2019 | 17/6/2026 | In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, a missing check in the function to arrange data in a chain of mbufs could cause data returned not to be contiguous. Extra checks in the… | |
| Modificada | Alta (7.5) | 3.8% | — | FreebsdNetapp Clustered Data Ontap | 30/8/2019 | 17/6/2026 | In FreeBSD 12.0-STABLE before r350637, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350638, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the bsnmp library is not properly validating the submitted length from a type-length-value encoding. A remote user could cause an… | |
| Modificada | Crítica (9.8) | 2.1% | — | FreebsdNetapp Clustered Data Ontap | 30/8/2019 | 17/6/2026 | In FreeBSD 12.0-STABLE before r350648, 12.0-RELEASE before 12.0-RELEASE-p9, 11.3-STABLE before r350650, 11.3-RELEASE before 11.3-RELEASE-p2, and 11.2-RELEASE before 11.2-RELEASE-p13, the ICMPv6 input path incorrectly handles cases where an MLDv2 listener query packet is internally fragmented across multiple mbufs. A… | |
| Modificada | Alta (7.5) | 28% | — | Apple SwiftnioApache Http ServerApache Traffic ServerCanonical Ubuntu Linux+19 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The… | |
| Modificada | Crítica (9.1) | 0.91% | — | Netapp Data Ontap | 5/8/2019 | 17/6/2026 | SMB in Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 has weak cryptography which when exploited could lead to information disclosure or addition or modification of data. | |
| Modificada | Alta (7.5) | 2.0% | — | Netapp Data Ontap | 2/8/2019 | 17/6/2026 | Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 may disclose sensitive LDAP account information to unauthenticated remote attackers. | |
| Modificada | Alta (7.5) | 1.4% | — | Netapp Data Ontap | 2/8/2019 | 17/6/2026 | Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information to an unauthenticated attacker. A successful attack requires that multiple non-default options be enabled. | |
| Modificada | Crítica (9.8) | 2.9% | — | Netapp AFF A700s FirmwareNetapp Clustered Data Ontap | 1/7/2019 | 17/6/2026 | NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were shipped with a default account enabled that could allow unauthorized arbitrary command execution. | |
| Modificada | Media (5.3) | 5.2% | — | Xmlsoft LibxsltOpensuse LeapNetapp Active IQ Unified ManagerNetapp Cloud Backup+21 | 1/7/2019 | 17/6/2026 | In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data. | |
| Modificada | Alta (7.5) | 5.7% | 💥 PoC | Netapp Clustered Data OntapNetapp Data OntapFedoraproject FedoraOpensuse Leap+2 | 15/5/2019 | 17/6/2026 | NTP through 4.2.8p12 has a NULL Pointer Dereference. | |
| Modificada | Alta (8.1) | 4.5% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+10 | 8/5/2019 | 17/6/2026 | An issue was discovered in rds_tcp_kill_sock in net/rds/tcp.c in the Linux kernel before 5.0.8. There is a race condition leading to a use-after-free, related to net namespace cleanup. | |
| Modificada | Alta (8.1) | 5.1% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxF5 Traffix Signaling Delivery Controller+9 | 7/5/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free. | |
| Modificada | Alta (7.7) | 4.3% | — | Linux KernelFedoraproject FedoraRedhat Enterprise LinuxDebian Linux+10 | 25/4/2019 | 17/6/2026 | An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net… | |
| Modificada | Media (5.5) | 0.54% | — | Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+9 | 24/4/2019 | 17/6/2026 | A flaw was found in the Linux kernel's vfio interface implementation that permits violation of the user's locked memory limit. If a device is bound to a vfio driver, such as vfio-pci, and the local attacker is administratively granted ownership of the device, it may cause a system memory exhaustion and thus a denial… | |
| Modificada | Alta (7) | 0.37% | — | Linux KernelDebian LinuxOpensuse LeapNetapp Active IQ+6 | 23/4/2019 | 17/6/2026 | The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c in the Linux kernel before 5.0.8 has multiple race conditions. | |
| Modificada | Media (5.3) | 5.9% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+22 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path.… | |
| Modificada | Media (5.3) | 4.1% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+21 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in… | |
| Modificada | Media (4.7) | 0.34% | — | Linux KernelDebian LinuxNetapp Active IQ Unified Manager FOR Vmware VsphereNetapp HCI Management Node+6 | 22/4/2019 | 17/6/2026 | A race condition in perf_event_open() allows local attackers to leak sensitive data from setuid programs. As no relevant locks (in particular the cred_guard_mutex) are held during the ptrace_may_access() call, it is possible for the specified target task to perform an execve() syscall with setuid execution before… | |
| Modificada | Alta (7.5) | 17% | 💥 PoC | Apache Http ServerDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+10 | 8/4/2019 | 17/6/2026 | In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions. | |
| Modificada | Media (5.9) | 17% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+78 | 27/2/2019 | 17/6/2026 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid… | |
| Modificada | Alta (7.5) | 1.9% | — | Netapp Clustered Data Ontap | 27/2/2019 | 17/6/2026 | Clustered Data ONTAP versions prior to 9.1P15 and 9.3 prior to 9.3P7 are susceptible to a vulnerability which discloses sensitive information to an unauthenticated user. | |
| Modificada | Alta (7.5) | 4.3% | — | Haxx LibcurlCanonical Ubuntu LinuxDebian LinuxNetapp Clustered Data Ontap+3 | 6/2/2019 | 17/6/2026 | libcurl versions from 7.34.0 to before 7.64.0 are vulnerable to a heap out-of-bounds read in the code handling the end-of-response for SMTP. If the buffer passed to `smtp_endofresp()` isn't NUL terminated and contains no character ending the parsed number, and `len` is set to 5, then the `strtol()` call reads beyond… |