Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
787 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.9% | — | Google ChromeFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+11 | 10/12/2019 | 17/6/2026 | Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Media (6.5) | 3.1% | — | Opensuse LeapFedoraproject FedoraSlackwareHP Apollo 4200 Firmware+156 | 14/11/2019 | 17/6/2026 | TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. | |
| Analizada | Alta (7.5) | 8.8% | — | ISC DhcpdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+15 | 1/11/2019 | 17/6/2026 | There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC… | |
| Modificada | Alta (7.5) | 21% | 💥 PoC | PythonOpensuse LeapDebian LinuxRedhat Enterprise Linux+3 | 31/10/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the X509 certificate parser of Python.org Python 2.7.11 / 3.6.6. A specially crafted X509 certificate can cause a NULL pointer dereference, resulting in a denial of service. An attacker can initiate or accept TLS connections using crafted certificates to trigger… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | PHPCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+19 | 28/10/2019 | 17/6/2026 | In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution. | |
| Modificada | Crítica (9.1) | 2.1% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+3 | 17/10/2019 | 17/6/2026 | From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks. | |
| Modificada | Alta (8.8) | 64% | 💥 Exploit | Sudo Project SudoFedoraproject FedoraDebian LinuxOpensuse Leap+11 | 17/10/2019 | 17/6/2026 | In Sudo before 1.8.28, an attacker with access to a Runas ALL sudoer account can bypass certain policy blacklists and session PAM modules, and can cause incorrect logging, by invoking sudo with a crafted user ID. For example, this allows bypass of !root configuration, and USER= logging, for a "sudo -u… | |
| Modificada | Media (4.7) | 2.6% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Javadoc). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require… | |
| Modificada | Media (4.2) | 2.2% | — | Oracle JDKOracle JRENetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage Manager+10 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Deployment). The supported version that is affected is Java SE: 8u221; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java… | |
| Modificada | Baja (3.7) | 3.5% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.7) | 3.3% | — | Oracle JDKOracle JRENetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage Manager+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.7) | 3.7% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Baja (3.7) | 3.7% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.7) | 3.3% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+16 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (4.8) | 3.3% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+14 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.7) | 3.7% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+16 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.7) | 3.5% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Baja (3.7) | 3.5% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.1) | 3.3% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.4) | 0.86% | — | JSS Cryptomanager Project JSS CryptomanagerRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+4 | 14/10/2019 | 17/6/2026 | A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to attacks such as Man in the… | |
| Modificada | Alta (7.5) | 5.3% | — | Golang GODebian LinuxOpensuse LeapFedoraproject Fedora+5 | 30/9/2019 | 17/6/2026 | Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. | |
| Modificada | Alta (7.5) | 4.4% | — | Linuxfoundation RuncDockerFedoraproject FedoraOpensuse Leap+6 | 25/9/2019 | 17/6/2026 | runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory. | |
| Modificada | Alta (7.8) | 0.91% | — | Linux KernelRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux Compute Node EUS+35 | 20/9/2019 | 17/6/2026 | There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.87% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Real Time+30 | 20/9/2019 | 17/6/2026 | There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | |
| Modificada | Alta (8.8) | 0.76% | — | Linux KernelRedhat Virtualization HostRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+24 | 19/9/2019 | 17/6/2026 | An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be… |