Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2834▲ 197 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
10.010 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 4.1% | — | WiresharkDebian LinuxFedoraproject Fedora | 12/4/2023 | 17/6/2026 | El bucle grande del disector LISP en Wireshark 4.0.0 a 4.0.4 y 3.6.0 a 3.6.12 permite la denegación de servicio mediante inyección de paquetes o archivo de captura manipulado | |
| Modificada | Alta (7.5) | 4.6% | — | WiresharkDebian LinuxFedoraproject Fedora | 12/4/2023 | 17/6/2026 | El fallo del disector RPCoRDMA en Wireshark 4.0.0 a 4.0.4 y 3.6.0 a 3.6.12 permite la denegación de servicio mediante la inyección de paquetes o un archivo de captura manipulado. | |
| Modificada | Alta (7) | 0.29% | — | Linux KernelDebian Linux | 12/4/2023 | 17/6/2026 | A use-after-free vulnerability in the Linux Kernel io_uring system can be exploited to achieve local privilege escalation. The io_file_get_fixed function lacks the presence of ctx->uring_lock which can lead to a Use-After-Free vulnerability due a race condition with fixed files getting unregistered. We recommend… | |
| Modificada | Alta (7) | 0.44% | — | Linux KernelNetapp H300sNetapp H410cNetapp H410s+3 | 11/4/2023 | 1/10/2026 | A use-after-free flaw was found in btsdio_remove in drivers\bluetooth\btsdio.c in the Linux Kernel. A call to btsdio_remove with an unfinished job may cause a race problem which leads to a UAF on hdev devices. | |
| Modificada | Alta (8.2) | 1.2% | — | Cloudbase Open VswitchDebian LinuxRedhat Openshift Container PlatformRedhat Openstack Platform+2 | 10/4/2023 | 17/6/2026 | A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath flow matching all IP protocols (nw_proto is wildcarded) for this flow,… | |
| Modificada | Media (5.5) | 0.20% | — | Canonical Ubuntu LinuxDebian Linux | 7/4/2023 | 17/6/2026 | It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack. | |
| Modificada | Media (6.5) | 0.89% | — | Bzip3 Project Bzip3Debian Linux | 6/4/2023 | 17/6/2026 | An issue was discovered in libbzip3.a in bzip3 before 1.3.0. A denial of service (process hang) can occur with a crafted archive because bzip3 does not follow the required procedure for interacting with libsais. | |
| Modificada | Media (6.3) | 0.23% | — | Linux KernelDebian Linux | 5/4/2023 | 17/6/2026 | A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hwmon). This flaw could allow a local attacker to crash the system due to a race problem. This vulnerability could even lead to a kernel information leak problem. | |
| Modificada | Media (6.5) | 0.95% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (6.5) | 0.98% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Media (6.5) | 0.91% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low) | |
| Modificada | Alta (8.8) | 0.97% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.88% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.88% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Use after free in Vulkan in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.97% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.91% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Incorrect security UI in Picture In Picture in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially perform navigation spoofing via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.91% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.95% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Media (6.5) | 0.76% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.94% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Out of bounds memory access in DOM Bindings in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium) | |
| Modificada | Alta (8.8) | 0.97% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (8.8) | 1.1% | — | Google ChromeFedoraproject FedoraDebian Linux | 4/4/2023 | 17/6/2026 | Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Modificada | Alta (7.5) | 1.6% | — | FrroutingFedoraproject FedoraDebian Linux | 3/4/2023 | 17/6/2026 | Se encontró una afirmación accesible en Frrouting frr-bgpd 8.3.0 en la función peek_for_as4_capability. Los atacantes pueden construir maliciosamente paquetes abiertos BGP y enviarlos a pares BGP que ejecutan frr-bgpd, lo que resulta en DoS. | |
| Modificada | Crítica (9.8) | 6.3% | — | Artifex GhostscriptDebian Linux | 31/3/2023 | 17/6/2026 | En Artifex Ghostscript hasta la versión 10.01.0, hay un desbordamiento de búfer que puede corromper los datos internos del intérprete PostScript, en base/sbcp.c. Esto afecta a BCPEncode, BCPDecode, TBCPEncode y TBCPDecode. Si el búfer de escritura se llena hasta un byte menos de su capacidad, y se intenta escribir un… | |
| Modificada | Media (5.3) | 2.5% | — | Ruby-lang RubyRuby-lang TimeDebian LinuxFedoraproject Fedora | 31/3/2023 | 17/6/2026 | A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2. |