Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

269 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.75%—Redhat Satellite26/7/201817/6/2026
A cross-site scripting (XSS) flaw was found in how an organization name is displayed in Satellite 5, before 5.8. A user able to change an organization's name could exploit this flaw to perform XSS attacks against other Satellite users.
ModificadaMedia (5.9)4.7%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+1618/7/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JSSE). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise…
ModificadaBaja (3.7)4.4%—Oracle JDKOracle JREOracle JrockitDebian Linux+2218/7/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171; JRockit: R28.3.18. Difficult to exploit vulnerability allows unauthenticated attacker with network…
ModificadaMedia (4.3)3.1%—Oracle JDKOracle JREHP XP7 Command ViewRedhat Satellite+1618/7/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries). Supported versions that are affected are Java SE: 6u191, 7u181, 8u172 and 10.0.1; Java SE Embedded: 8u171. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaAlta (8.8)1.2%—Theforeman ForemanRedhat Satellite21/6/201817/6/2026
A flaw was found in foreman before version 1.15 in the logging of adding and registering images. An attacker with access to the foreman log file would be able to view passwords for provisioned systems in the log file, allowing them to access those systems.
ModificadaAlta (7.5)1.3%—Pulpproject PulpFedoraproject FedoraRedhat Satellite18/6/201817/6/2026
In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view these secrets.
AnalizadaAlta (7.5)1.8%—Bouncycastle Legion-of-the-bouncy-castle-java-crytography-apiRedhat SatelliteRedhat Satellite CapsuleCanonical Ubuntu Linux+11/6/201817/6/2026
In Bouncy Castle JCE Provider version 1.55 and earlier the DSA does not fully validate ASN.1 encoding of signature on verification. It is possible to inject extra elements in the sequence making up the signature and still have it validate, which in some cases may allow the introduction of 'invisible' data into a…
ModificadaMedia (6.5)4.8%—IJG LibjpegDebian LinuxCanonical Ubuntu LinuxNetapp Oncommand Unified Manager+916/5/201817/6/2026
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
ModificadaMedia (5.9)5.1%—Google GuavaRedhat Openshift Container PlatformRedhat OpenstackRedhat Satellite+1326/4/201817/6/2026
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray class (when serialized with Java serialization) and the…
ModificadaMedia (4.2)5.2%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+1019/4/201817/6/2026
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE,…
ModificadaMedia (5.3)15%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+1119/4/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple…
ModificadaMedia (5.3)7.4%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+1019/4/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: AWT). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via…
ModificadaMedia (5.3)7.4%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+1019/4/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JMX). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via…
ModificadaMedia (5.3)6.5%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+1019/4/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Concurrency). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via…
ModificadaMedia (5.3)7.4%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+1019/4/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access…
ModificadaAlta (7.7)0.72%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+1019/4/201817/6/2026
Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162, 10 and JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, JRockit…
ModificadaBaja (3.1)4.8%—Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+919/4/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to…
ModificadaAlta (7.4)3.9%—Oracle JDKOracle JREOracle JrockitRedhat Satellite+519/4/201817/6/2026
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Security). Supported versions that are affected are Java SE: 6u181, 7u161 and 8u152; Java SE Embedded: 8u152; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via…
ModificadaAlta (8.8)0.97%—Theforeman ForemanRedhat Satellite16/4/201817/6/2026
foreman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file would be able to view passwords, allowing them to access those systems.
ModificadaMedia (4.4)0.26%—Bouncycastle Bc-javaRedhat SatelliteRedhat Satellite Capsule16/4/201817/6/2026
The default BKS keystore use an HMAC that is only 16 bits long, which can allow an attacker to compromise the integrity of a BKS keystore. Bouncy Castle release 1.47 changes the BKS format to a format which uses a 160 bit HMAC instead. This applies to any BKS keystore generated prior to BC 1.47. For situations where…
ModificadaMedia (6.5)1.3%—Theforeman ForemanRedhat Satellite5/4/201817/6/2026
An input sanitization flaw was found in the id field in the dashboard controller of Foreman before 1.16.1. A user could use this flaw to perform an SQL injection attack on the back end database.
ModificadaAlta (8.8)1.7%—Theforeman ForemanRedhat Satellite4/4/201817/6/2026
A flaw was found in foreman before 1.16.1. The issue allows users with limited permissions for powering oVirt/RHV hosts on and off to discover the username and password used to connect to the compute resource.
ModificadaAlta (7.5)1.0%—Redhat SpacewalkRedhat Satellite14/3/201817/6/2026
Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.
ModificadaAlta (8.1)0.69%—Theforeman Hammer CLIRedhat SatelliteRedhat Satellite Capsule12/3/201817/6/2026
Hammer CLI, a CLI utility for Foreman, before version 0.10.0, did not explicitly set the verify_ssl flag for apipie-bindings that disable it by default. As a result the server certificates are not checked and connections are prone to man-in-the-middle attacks.
ModificadaBaja (2.7)0.96%—Redhat Satellite27/2/201817/6/2026
When registering and activating a new system with Red Hat Satellite 6 if the new systems hostname is then reset to the hostname of a previously registered system the previously registered system will lose access to updates including security updates.
Orbitaley — Vulnerabilidades