Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
593 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.33% | — | Freebsd | 13/5/2020 | 17/6/2026 | In FreeBSD 12.1-STABLE before r352509, 11.3-STABLE before r352509, and 11.3-RELEASE before p9, an unprivileged local user can trigger a use-after-free situation due to improper checking in SCTP when an application tries to update an SCTP-AUTH shared key. | |
| Modificada | Media (6) | 0.34% | — | Freebsd | 29/4/2020 | 17/6/2026 | In FreeBSD 12.1-STABLE before r359021, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r359020, and 11.3-RELEASE before 11.3-RELEASE-p7, a missing null termination check in the jail_set configuration option "osrelease" may return more bytes with a subsequent jail_get system call allowing a malicious jail… | |
| Modificada | Crítica (9.1) | 1.8% | — | Freebsd | 29/4/2020 | 17/6/2026 | In FreeBSD 12.1-STABLE before r357490, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r357489, and 11.3-RELEASE before 11.3-RELEASE-p7, incorrect use of a user-controlled pointer in the epair virtual network module allowed vnet jailed privileged users to panic the host system and potentially execute arbitrary… | |
| Modificada | Crítica (9.8) | 1.4% | — | FreebsdNetapp Clustered Data Ontap | 29/4/2020 | 17/6/2026 | In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in accessing out-of-bounds memory leading to a kernel panic or other unpredictable results. | |
| Modificada | Crítica (9.8) | 1.4% | — | FreebsdNetapp Clustered Data Ontap | 29/4/2020 | 17/6/2026 | In FreeBSD 12.1-STABLE before r356035, 12.1-RELEASE before 12.1-RELEASE-p4, 11.3-STABLE before r356036, and 11.3-RELEASE before 11.3-RELEASE-p8, incomplete packet data validation may result in memory access after it has been freed leading to a kernel panic or other unpredictable results. | |
| Modificada | Media (5.3) | 1.2% | — | Freebsd | 28/4/2020 | 17/6/2026 | In FreeBSD 12.1-STABLE before r358739, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r358740, and 11.3-RELEASE before 11.3-RELEASE-p7, a TCP SYN-ACK or challenge TCP-ACK segment over IPv6 that is transmitted or retransmitted does not properly initialize the Traffic Class field disclosing one byte of kernel… | |
| Modificada | Media (5.5) | 0.24% | — | Freebsd | 28/4/2020 | 17/6/2026 | In FreeBSD 12.1-STABLE before r356606 and 12.1-RELEASE before 12.1-RELEASE-p3, driver specific ioctl command handlers in the ixl network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to trigger updates to the device's non-volatile memory. | |
| Modificada | Media (5.5) | 0.27% | — | Freebsd | 28/4/2020 | 17/6/2026 | In FreeBSD 12.1-STABLE before r356089, 12.1-RELEASE before 12.1-RELEASE-p3, 11.3-STABLE before r356090, and 11.3-RELEASE before 11.3-RELEASE-p7, driver specific ioctl command handlers in the oce network driver failed to check whether the caller has sufficient privileges allowing unprivileged users to send passthrough… | |
| Modificada | Alta (7.5) | 53% | 💥 PoC | OpensslDebian LinuxFreebsdFedoraproject Fedora+22 | 21/4/2020 | 17/6/2026 | Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signature_algorithms_cert" TLS extension. The crash occurs if an invalid or unrecognised signature algorithm is received from… | |
| Modificada | Alta (7.8) | 0.34% | — | Freebsd | 14/3/2020 | 17/6/2026 | grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, mishandles font loading by a guest through a grub2.cfg file, leading to a buffer overflow. | |
| Modificada | Alta (7.8) | 0.41% | — | Freebsd | 14/3/2020 | 17/6/2026 | grub2-bhyve, as used in FreeBSD bhyve before revision 525916 2020-02-12, does not validate the address provided as part of a memrw command (read_* or write_*) by a guest through a grub2.cfg file. This allows an untrusted guest to perform arbitrary read or write operations in the context of the grub-bhyve process,… | |
| Modificada | Alta (7.5) | 2.6% | — | FreebsdNetbsd | 20/2/2020 | 16/6/2026 | The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Router Advertisement packets containing multiple Routing entries. | |
| Modificada | Alta (7.5) | 2.6% | — | FreebsdNetbsd | 20/2/2020 | 16/6/2026 | The IPv6 implementation in FreeBSD and NetBSD (unknown versions, year 2012 and earlier) allows remote attackers to cause a denial of service via a flood of ICMPv6 Neighbor Solicitation messages, a different vulnerability than CVE-2011-2393. | |
| Modificada | Media (6.5) | 1.4% | — | Freebsd | 20/2/2020 | 17/6/2026 | The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD through 10.1 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message. | |
| Modificada | Crítica (9.8) | 2.7% | — | Freebsd | 18/2/2020 | 17/6/2026 | OpenPAM Nummularia 9.2 through 10.0 does not properly handle the error reported when an include directive refers to a policy that does not exist, which causes the loaded policy chain to no be discarded and allows context-dependent attackers to bypass authentication via a login (1) without a password or (2) with an… | |
| Modificada | Crítica (9.8) | 2.5% | — | Freebsd | 18/2/2020 | 17/6/2026 | In FreeBSD 12.1-STABLE before r357213, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-STABLE before r357214, and 11.3-RELEASE before 11.3-RELEASE-p6, URL handling in libfetch with URLs containing username and/or password components is vulnerable to a heap buffer overflow allowing… | |
| Modificada | Crítica (9.8) | 0.58% | — | Freebsd | 18/2/2020 | 17/6/2026 | In FreeBSD 12.0-RELEASE before 12.0-RELEASE-p13, a missing check in the ipsec packet processor allows reinjection of an old packet to be accepted by the ipsec endpoint. Depending on the higher-level protocol in use over ipsec, this could allow an action to be repeated. | |
| Modificada | Baja (3.3) | 0.29% | — | Freebsd | 18/2/2020 | 17/6/2026 | In FreeBSD 12.1-STABLE before r354734, 12.1-RELEASE before 12.1-RELEASE-p2, 12.0-RELEASE before 12.0-RELEASE-p13, 11.3-STABLE before r354735, and 11.3-RELEASE before 11.3-RELEASE-p6, due to incorrect initialization of a stack data structure, core dump files may contain up to 20 bytes of kernel data previously stored… | |
| Modificada | Alta (7.5) | 6.5% | 💥 Exploit | PHPApple MAC OS XFreebsdOpenbsd | 12/2/2020 | 16/6/2026 | regcomp in the BSD implementation of libc is vulnerable to denial of service due to stack exhaustion. | |
| Modificada | Alta (7.4) | 0.84% | — | FreebsdLinux KernelOpenbsdApple Ipados+4 | 11/12/2019 | 17/6/2026 | A vulnerability was discovered in Linux, FreeBSD, OpenBSD, MacOS, iOS, and Android that allows a malicious access point, or an adjacent user, to determine if a connected user is using a VPN, make positive inferences about the websites they are visiting, and determine the correct sequence and acknowledgement numbers in… | |
| Modificada | Alta (7.8) | 0.42% | — | FreebsdDebian Linux | 2/12/2019 | 16/6/2026 | FreeBSD: Input Validation Flaw allows local users to gain elevated privileges | |
| Modificada | Alta (7.5) | 1.6% | — | FreebsdNetbsd | 27/11/2019 | 16/6/2026 | Information Disclosure vulnerability in the 802.11 stack, as used in FreeBSD before 8.2 and NetBSD when using certain non-x86 architectures. A signedness error in the IEEE80211_IOC_CHANINFO ioctl allows a local unprivileged user to cause the kernel to copy large amounts of kernel memory back to the user, disclosing… | |
| Modificada | Alta (7.5) | 1.7% | — | Freebsd Name Server Daemon | 1/11/2019 | 16/6/2026 | FreeBSD NSD before 3.2.13 allows remote attackers to crash a NSD child server process (SIGSEGV) and cause a denial of service in the NSD server. | |
| Modificada | Alta (7.5) | 0.91% | — | FreebsdNetapp Clustered Data Ontap | 30/8/2019 | 17/6/2026 | In FreeBSD 12.0-STABLE before r351264, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r351265, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, the kernel driver for /dev/midistat implements a read handler that is not thread-safe. A multi-threaded program can exploit races in… | |
| Modificada | Alta (7.5) | 4.4% | — | FreebsdNetapp Clustered Data Ontap | 30/8/2019 | 17/6/2026 | In FreeBSD 12.0-STABLE before r350828, 12.0-RELEASE before 12.0-RELEASE-p10, 11.3-STABLE before r350829, 11.3-RELEASE before 11.3-RELEASE-p3, and 11.2-RELEASE before 11.2-RELEASE-p14, a missing check in the function to arrange data in a chain of mbufs could cause data returned not to be contiguous. Extra checks in the… |