Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

5546 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.29%—Linux KernelFedoraproject Fedora1/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: walk over current view on netlink dump The generation mask can be updated while netlink dump is in progress. The pipapo set backend walk iterator cannot rely on it to infer what view of the datastructure is to be used. Add…
ModificadaMedia (5.5)0.34%—Linux KernelFedoraproject Fedora1/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: validate pppoe header Ensure there is sufficient room to access the protocol field of the PPPoe header. Validate it once before the flowtable lookup, then use a helper function to access protocol field.
ModificadaMedia (5.5)0.23%—Linux KernelFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: incorrect pppoe tuple pppoe traffic reaching ingress path does not match the flowtable entry because the pppoe header is expected to be at the network header offset. This bug causes a mismatch in the flow table lookup, so pppoe…
ModificadaMedia (5.5)0.18%—Linux KernelFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Prevent deadlock while disabling aRFS When disabling aRFS under the `priv->state_lock`, any scheduled aRFS works are canceled using the `cancel_work_sync` function, which waits for the work to end if it has already started. However, while…
ModificadaMedia (5.5)0.27%—Linux KernelFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: tun: limit printing rate when illegal packet received by tun dev vhost_worker will call tun call backs to receive packets. If too many illegal packets arrives, tun_do_read will keep dumping packet contents. When console is enabled, it will costs much…
ModificadaMedia (5.5)0.27%—Linux KernelFedoraproject Fedora1/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: restore set elements when delete set fails From abort path, nft_mapelem_activate() needs to restore refcounters to the original state. Currently, it uses the set->ops->walk() to iterate over these set elements. The existing set…
AnalizadaAlta (7.8)0.30%—Linux KernelDebian LinuxFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: drm: nv04: Fix out of bounds access When Output Resource (dcb->or) value is assigned in fabricate_dcb_output(), there may be out of bounds access to dac_users array in case dcb->or is zero because ffs(dcb->or) is used as index there. The 'or' argument…
ModificadaMedia (5.5)0.21%—Linux KernelDebian LinuxFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: clk: Get runtime PM before walking tree during disable_unused Doug reported [1] the following hung task: The first thread is walking the clk tree and calling clk_pm_runtime_get() to power on devices required to read the clk hardware via struct…
AnalizadaMedia (5.5)0.28%—Linux KernelDebian LinuxFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: comedi: vmk80xx: fix incomplete endpoint checking While vmk80xx does have endpoint checking implemented, some things can fall through the cracks. Depending on the hardware model, URBs can have either bulk or interrupt type, and current version of…
AnalizadaAlta (7.8)0.33%—Linux KernelDebian LinuxFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: serial: mxs-auart: add spinlock around changing cts state The uart_handle_cts_change() function in serial_core expects the caller to hold uport->lock. For example, I have seen the below kernel splat, when the Bluetooth driver is loaded on an i.MX28…
ModificadaMedia (5.5)0.29%—Linux KernelDebian LinuxFedoraproject Fedora1/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: speakup: Avoid crash on very long word In case a console is set up really large and contains a really long word (> 256 characters), we have to stop before the length of the word buffer.
ModificadaAlta (7.8)0.28%—Linux KernelDebian LinuxFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: init/main.c: Fix potential static_command_line memory overflow We allocate memory of size 'xlen + strlen(boot_command_line) + 1' for static_command_line, but the strings copied into static_command_line are extra_command_line and command_line, rather…
ModificadaMedia (5.5)0.18%—Linux KernelFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix deadlock when hugetlb_optimize_vmemmap is enabled When I did hard offline test with hugetlb pages, below deadlock occurs: ====================================================== WARNING: possible circular locking dependency…
ModificadaMedia (5.5)0.23%—Linux KernelFedoraproject Fedora1/5/202417/6/2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix memory leak in create_process failure Fix memory leak due to a leaked mmget reference on an error handling code path that is triggered when attempting to create KFD processes while a GPU reset is in progress.
ModificadaCrítica (9.4)33%💥 PoCPHPFedoraproject Fedora29/4/202417/6/2026
In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.
ModificadaMedia (6.5)1.1%—Malaterre Grassroots DicomFedoraproject Fedora25/4/202417/6/2026
An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to an out-of-bounds read. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaCrítica (9.8)1.4%—Malaterre Grassroots DicomFedoraproject Fedora25/4/202417/6/2026
A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaCrítica (9.8)1.7%—Malaterre Grassroots DicomFedoraproject Fedora25/4/202410/9/2026
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
AnalizadaCrítica (9.8)0.77%—FreerdpFedoraproject Fedora23/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. This occurs when `WCHAR` string is read with twice the size it has and converted to `UTF-8`, `base64` decoded. The string is only used to compare against the redirection…
ModificadaAlta (7.5)1.2%—FreerdpFedoraproject Fedora23/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to a possible `NULL` access and crash. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
ModificadaAlta (7.5)1.2%—FreerdpFedoraproject Fedora23/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.5.1, a malicious server can crash the FreeRDP client by sending invalid huge allocation size. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
ModificadaCrítica (9.8)1.2%—FreerdpFedoraproject Fedora23/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read if `((nWidth == 0) and (nHeight == 0))`. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
ModificadaCrítica (9.8)1.4%—FreerdpFedoraproject Fedora23/4/202417/6/2026
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
AnalizadaMedia (6.5)1.5%—Matrix SynapseFedoraproject Fedora23/4/202417/6/2026
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the…
ModificadaMedia (5.5)0.32%—Linux KernelDebian LinuxFedoraproject Fedora23/4/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping operations more clearly Verify the parameters of amdgpu_vm_bo_(map/replace_map/clearing_mappings) in one common place.