Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
242 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 2.6% | — | Oracle JDKOracle JRENetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+6 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 11.0.4 and 13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can… | |
| Modificada | Media (4.8) | 3.3% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+14 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.7) | 3.7% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+16 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JAXP). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Baja (3.7) | 3.5% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Baja (3.7) | 3.5% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise… | |
| Modificada | Media (5.9) | 2.6% | — | Oracle JDKOracle JRENetapp E-series Santricity OS ControllerNetapp E-series Santricity Storage Manager+6 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (6.8) | 3.6% | — | Oracle JDKOracle JREDebian LinuxNetapp E-series Santricity OS Controller+11 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Kerberos). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Kerberos to compromise Java… | |
| Modificada | Baja (3.1) | 3.3% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux+15 | 16/10/2019 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u231, 8u221, 11.0.4 and 13; Java SE Embedded: 8u221. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Media (6.5) | 4.3% | — | SqliteNetapp Active IQ Unified ManagerNetapp E-series Santricity OS ControllerNetapp Oncommand Insight+16 | 9/9/2019 | 17/6/2026 | In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner." | |
| Modificada | Crítica (9.8) | 9.0% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+9 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host. | |
| Modificada | Crítica (9.8) | 23% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+9 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option. | |
| Modificada | Alta (7.5) | 23% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+8 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options. | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Windriver VxworksNetapp E-series Santricity OS ControllerSonicwall SonicosSiemens Siprotec 5 Firmware+8 | 9/8/2019 | 17/6/2026 | Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow. | |
| Modificada | Media (5.3) | 60% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+8 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report. | |
| Modificada | Alta (8.1) | 3.2% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+8 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition. | |
| Modificada | Alta (8.8) | 84% | — | Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+6 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc. | |
| Modificada | Crítica (9.8) | 27% | — | Windriver VxworksNetapp E-series Santricity OS ControllerSonicwall SonicosSiemens Siprotec 5 Firmware+8 | 9/8/2019 | 17/6/2026 | Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options. | |
| Analizada | Alta (7.8) | 52% | ⚠ Explotación activa💥 Exploit | Linux KernelDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+18 | 17/7/2019 | 17/6/2026 | In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges… | |
| Modificada | Alta (8.1) | 12% | 💥 PoC | Libssh2Debian LinuxFedoraproject FedoraNetapp Cloud Backup+3 | 16/7/2019 | 17/6/2026 | In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of… | |
| Modificada | Media (5.3) | 5.2% | — | Xmlsoft LibxsltOpensuse LeapNetapp Active IQ Unified ManagerNetapp Cloud Backup+21 | 1/7/2019 | 17/6/2026 | In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of uninitialized stack data. | |
| Modificada | Crítica (9.8) | 5.2% | — | Xmlsoft LibxsltCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+18 | 10/4/2019 | 17/6/2026 | libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded. | |
| Modificada | Crítica (9.8) | 6.1% | — | PerlCanonical Ubuntu LinuxDebian LinuxNetapp E-series Santricity OS Controller+4 | 7/12/2018 | 17/6/2026 | Perl before 5.26.3 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | |
| Modificada | Crítica (9.1) | 9.5% | — | PerlCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+5 | 7/12/2018 | 17/6/2026 | Perl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process memory. | |
| Modificada | Crítica (9.8) | 12% | — | PerlCanonical Ubuntu LinuxDebian LinuxNetapp E-series Santricity OS Controller+14 | 7/12/2018 | 17/6/2026 | Perl before 5.26.3 and 5.28.x before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. | |
| Modificada | Crítica (9.8) | 13% | — | PerlCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+4 | 5/12/2018 | 17/6/2026 | Perl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations. |