Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2837▲ 84 respecto a la semana anterior
Críticas / altas1317▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)246▲ 228 respecto a la semana anterior
10.010 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.74% | — | Debian LinuxFedoraproject FedoraQT | 5/6/2023 | 17/6/2026 | An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate. | |
| Modificada | Media (5.5) | 1.5% | — | Openprinting CupsDebian Linux | 1/6/2023 | 17/6/2026 | OpenPrinting CUPS is an open source printing system. In versions 2.4.2 and prior, a heap buffer overflow vulnerability would allow a remote attacker to launch a denial of service (DoS) attack. A buffer overflow vulnerability in the function `format_log_line` could allow remote attackers to cause a DoS on the affected… | |
| Modificada | Media (5.5) | 0.25% | — | Linux KernelSuse Linux EnterpriseDebian Linux | 31/5/2023 | 17/6/2026 | Se ha descubierto un problema en el kernel de Linux en las versiones anteriores a 6.3.3. Hay una lectura fuera de límites en crc16 en "lib/crc16.c" cuando se llama dese "fs/ext4/super.c" porque "ext4_group_desc_csum" no comprueba correctamente un desplazamiento. | |
| Modificada | Media (6.5) | 1.1% | — | WiresharkDebian Linux | 30/5/2023 | 17/6/2026 | El bucle infinito del disector XRA en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio mediante la inyección de paquetes o un archivo de captura manipulado | |
| Analizada | Media (5.5) | 0.95% | — | ImagemagickFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraRedhat Enterprise Linux+1 | 30/5/2023 | 17/6/2026 | A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546). | |
| Modificada | Media (6.5) | 75% | — | OpensslDebian Linux | 30/5/2023 | 17/6/2026 | Issue summary: Processing some specially crafted ASN.1 object identifiers or data containing them may be very slow. Impact summary: Applications that use OBJ_obj2txt() directly, or use any of the OpenSSL subsystems OCSP, PKCS7/SMIME, CMS, CMP/CRMF or TS with no message size limit may experience notable to very long… | |
| Analizada | Media (5.3) | 0.88% | — | Debian LinuxQT | 28/5/2023 | 17/6/2026 | An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly prohibited by the server. This happens if the case used for this… | |
| Modificada | Alta (7.5) | 1.1% | — | Signalwire Sofia-sipDebian Linux | 26/5/2023 | 17/6/2026 | Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8599-x7rq-fr54), several other potential heap-over-flow and integer-overflow in stun_parse_attr_error_code and… | |
| Modificada | Media (4.7) | 0.19% | — | Linux KernelDebian LinuxNetapp H300s FirmwareNetapp H500s Firmware+3 | 26/5/2023 | 17/6/2026 | There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem. | |
| Modificada | Alta (7.5) | 1.6% | — | WiresharkDebian Linux | 26/5/2023 | 17/6/2026 | GDSDB bucle infinito en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio a través de inyección de paquetes o archivo de captura manipulado | |
| Modificada | Media (6.5) | 1.8% | — | WiresharkDebian Linux | 26/5/2023 | 17/6/2026 | El fallo del analizador de archivos BLF en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio a través de un archivo de captura manipulado. | |
| Modificada | Media (6.5) | 0.88% | — | WiresharkDebian Linux | 26/5/2023 | 17/6/2026 | El fallo del analizador de archivos BLF en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio a través de un archivo de captura manipulado. | |
| Modificada | Media (6.5) | 1.8% | — | WiresharkDebian Linux | 26/5/2023 | 17/6/2026 | El fallo del analizador de archivos VMS TCPIPtrace en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio a través de un archivo de captura manipulado. | |
| Modificada | Media (6.5) | 1.6% | — | WiresharkDebian Linux | 26/5/2023 | 17/6/2026 | La falla del analizador de registros de Candump en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio a través de un archivo de captura manipulado | |
| Modificada | Media (6.5) | 0.88% | — | WiresharkDebian Linux | 26/5/2023 | 17/6/2026 | El fallo del analizador de archivos BLF en Wireshark 4.0.0 a 4.0.5 y 3.6.0 a 3.6.13 permite la denegación de servicio a través de un archivo de captura manipulado. | |
| Modificada | Media (5.9) | 1.8% | — | Haxx CurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+6 | 26/5/2023 | 17/6/2026 | An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one provided by a TLS library. This private… | |
| Modificada | Media (6.5) | 1.3% | — | LibsshFedoraproject FedoraDebian LinuxRedhat Enterprise Linux | 26/5/2023 | 17/6/2026 | A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service. | |
| Modificada | Media (6.8) | 1.5% | 💥 PoC | Linux KernelDebian Linux | 26/5/2023 | 17/6/2026 | A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution of management commands, compromising the confidentiality, integrity, and availability of Bluetooth communication. | |
| Modificada | Alta (7.5) | 1.6% | — | C-ares Project C-aresFedoraproject FedoraDebian Linux | 25/5/2023 | 17/6/2026 | c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target resolver. The target resolver erroneously interprets the 0 length as a graceful shutdown of the… | |
| Modificada | Media (6.4) | 0.38% | — | C-ares Project C-aresFedoraproject FedoraDebian Linux | 25/5/2023 | 17/6/2026 | c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an… | |
| Modificada | Media (5.3) | 2.2% | 💥 PoC | LibreofficeDebian Linux | 25/5/2023 | 17/6/2026 | Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of… | |
| Modificada | Alta (7.8) | 0.30% | — | LibreofficeDebian Linux | 25/5/2023 | 17/6/2026 | Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as… | |
| Modificada | Alta (7.5) | 48% | — | Apache TomcatDebian LinuxNetapp 7-mode Transition Tool | 22/5/2023 | 17/6/2026 | The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly… | |
| Modificada | Alta (7.8) | 0.33% | — | Sysstat Project SysstatFedoraproject FedoraDebian Linux | 18/5/2023 | 17/6/2026 | sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377. | |
| Modificada | Alta (8.8) | 3.7% | — | Linuxfoundation Cups-filtersFedoraproject FedoraDebian Linux | 17/5/2023 | 17/6/2026 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote code execution. `beh.c` contains the line… |