Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

4241 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)27%💥 ExploitLinux KernelCanonical Ubuntu Linux4/6/202117/6/2026
The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue was fixed via commit 049c4e13714e ("bpf: Fix alu32 const subreg…
ModificadaAlta (7.8)0.55%—Linux KernelCanonical Ubuntu Linux4/6/202117/6/2026
The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue was fixed via commit 4b81ccebaeee ("bpf, ringbuf: Deny…
ModificadaAlta (7.5)4.9%—OpenvpnFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux26/4/202117/6/2026
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
AnalizadaAlta (7.8)49%⚠ Explotación activa💥 ExploitCanonical Ubuntu Linux17/4/202117/6/2026
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivileged overlay mounts,…
ModificadaAlta (7.8)1.5%💥 PoCCanonical Ubuntu Linux17/4/202117/6/2026
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (kernel memory…
ModificadaMedia (4.3)1.3%—Canonical Unity-firefox-extensionCanonical Ubuntu Linux7/4/202116/6/2026
The unity-firefox-extension package could be tricked into dropping a C callback which was still in use, which Firefox would then free, causing Firefox to crash. This could be achieved by adding an action to the launcher and updating it with new callbacks until the libunity-webapps rate limit was hit. Fixed in…
ModificadaMedia (6.5)1.3%—Canonical Unity-firefox-extensionCanonical Ubuntu Linux7/4/202116/6/2026
The unity-firefox-extension package could be tricked into destroying the Unity webapps context, causing Firefox to crash. This could be achieved by spinning the event loop inside the webapps initialization callback. Fixed in 3.0.0+14.04.20140416-0ubuntu1.14.04.1 by shipping an empty package, thus disabling the…
ModificadaAlta (7.8)0.61%—Linux KernelDebian LinuxCanonical Ubuntu Linux23/3/202117/6/2026
The bpf verifier in the Linux kernel did not properly handle mod32 destination register truncation when the source register was known to be 0. A local attacker with the ability to load bpf programs could use this gain out-of-bounds reads in kernel memory leading to information disclosure (kernel memory), and possibly…
ModificadaMedia (6)0.58%—Linux KernelFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux20/3/202117/6/2026
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory,…
ModificadaMedia (4.7)0.56%—Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux20/3/202117/6/2026
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types…
AnalizadaAlta (7.1)0.97%—Netapp Cloud BackupLinux KernelDebian LinuxNetapp Solidfire Baseboard Management Controller Firmware+27/3/202130/7/2026
An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages.
ModificadaMedia (4.4)0.41%—Linux KernelCanonical Ubuntu Linux10/2/202117/6/2026
Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were allowed. It was possible to have a file not readable by an unprivileged user to be copied to a mountpoint controlled by…
ModificadaAlta (7.8)0.42%—Linux KernelCanonical Ubuntu LinuxDebian Linux14/1/202117/6/2026
Use-after-free vulnerability in the Linux kernel exploitable by a local attacker due to reuse of a DCCP socket with an attached dccps_hc_tx_ccid object as a listener after being released. Fixed in Ubuntu Linux kernel 5.4.0-51.56, 5.3.0-68.63, 4.15.0-121.123, 4.4.0-193.224, 3.13.0.182.191 and 3.2.0-149.196.
AnalizadaMedia (5.5)1.5%—Gnome Gdk-pixbufCanonical Ubuntu LinuxFedoraproject Fedora26/12/202017/6/2026
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the…
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux9/12/202017/6/2026
Aptdaemon performed policykit checks after interacting with potentially untrusted files with elevated privileges. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
ModificadaBaja (3.8)0.34%—Canonical Ubuntu Linux9/12/202017/6/2026
The aptdaemon DBus interface disclosed file existence disclosure by setting Terminal/DebconfSocket properties, aka GHSL-2020-192 and GHSL-2020-196. This affected versions prior to 1.1.1+bzr982-0ubuntu34.1, 1.1.1+bzr982-0ubuntu32.3, 1.1.1+bzr982-0ubuntu19.5, 1.1.1+bzr982-0ubuntu14.5.
ModificadaMedia (6.8)0.70%—Canonical SnapcraftCanonical Ubuntu Linux4/12/202017/6/2026
In some conditions, a snap package built by snapcraft includes the current directory in LD_LIBRARY_PATH, allowing a malicious snap to gain code execution within the context of another snap if both plug the home interface or similar. This issue affects snapcraft versions prior to 4.4.4, prior to 2.43.1+16.04.1, and…
ModificadaMedia (4.7)0.32%—Canonical Ubuntu Linux4/12/202017/6/2026
An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missing, allowing the snap to connect to PulseAudio without proper confinement. This could be exploited by an attacker to…
ModificadaMedia (4.7)0.40%—Linux KernelCanonical Ubuntu Linux28/11/202017/6/2026
An issue was discovered in do_madvise in mm/madvise.c in the Linux kernel before 5.6.8. There is a race condition between coredump operations and the IORING_OP_MADVISE implementation, aka CID-bc0c4d1e176e.
ModificadaMedia (5.7)0.56%—Intel Ax201 FirmwareIntel Ax200 FirmwareIntel AC 9560 FirmwareIntel AC 9462 Firmware+1123/11/202017/6/2026
Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.34%—Packagekit Project PackagekitCanonical Ubuntu Linux7/11/202017/6/2026
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is based on repository trust and not on the contents of individual files. On sites with configured PolicyKit rules this may allow users to install malicious packages.
ModificadaBaja (3.3)0.47%—Packagekit Project PackagekitCanonical Ubuntu Linux7/11/202017/6/2026
PackageKit provided detailed error messages to unprivileged callers that exposed information about file presence and mimetype of files that the user would be unable to determine on its own.
ModificadaAlta (7.8)0.40%—Canonical Ubuntu Linux6/11/202017/6/2026
Ubuntu's packaging of libvirt in 20.04 LTS created a control socket with world read and write permissions. An attacker could use this to overwrite arbitrary files or execute arbitrary code.
ModificadaMedia (4.3)1.1%—WordpressDebian LinuxCanonical Ubuntu Linux2/11/202017/6/2026
WordPress before 5.5.2 allows CSRF attacks that change a theme's background image.
ModificadaCrítica (9.1)4.1%—WordpressDebian LinuxCanonical Ubuntu Linux2/11/202017/6/2026
is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.