Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
3303 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.25% | — | Dpdk Data Plane Development KITCanonical Ubuntu LinuxOpensuse Leap | 30/9/2020 | 17/6/2026 | A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the virtual machine and the host. An attacker in a VM can change the contents of the memory after vhost_crypto has validated it. The highest… | |
| Modificada | Crítica (9.8) | 3.6% | — | Libproxy Project LibproxyFedoraproject FedoraDebian LinuxOpensuse Leap | 30/9/2020 | 17/6/2026 | url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header. | |
| Modificada | Alta (8.1) | 3.1% | — | TigervncDebian LinuxOpensuse Leap | 27/9/2020 | 17/6/2026 | In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception. | |
| Modificada | Alta (7.2) | 6.4% | — | PythonFedoraproject FedoraCanonical Ubuntu LinuxNetapp Solidfire+4 | 27/9/2020 | 17/6/2026 | http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request. | |
| Modificada | Media (4.8) | 0.92% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In TensorFlow Lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, saved models in the flatbuffer format use a double indexing scheme: a model has a set of subgraphs, each subgraph has a set of operators and each operator has a set of input/output tensors. The flatbuffer format uses indices for the tensors,… | |
| Modificada | Media (6.5) | 0.74% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, if a TFLite saved model uses the same tensor as both input and output of an operator, then, depending on the operator, we can observe a segmentation fault or just memory corruption. We have patched the issue in d58c96946b and will release patch… | |
| Modificada | Media (5.9) | 0.80% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, a crafted TFLite model can force a node to have as input a tensor backed by a `nullptr` buffer. This can be achieved by changing a buffer index in the flatbuffer serialization to convert a read-only tensor to a read-write one. The runtime… | |
| Modificada | Crítica (9.8) | 0.91% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, when determining the common dimension size of two tensors, TFLite uses a `DCHECK` which is no-op outside of debug compilation modes. Since the function always returns the dimension of the first tensor, malicious attackers can craft cases where… | |
| Modificada | Crítica (9) | 1.2% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In tensorflow-lite before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, to mimic Python's indexing with negative values, TFLite uses `ResolveAxis` to convert negative values to positive indices. However, the only check that the converted index is now valid is only present in debug builds. If the `DCHECK` does not… | |
| Modificada | Alta (7.5) | 0.96% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of required keys results in segfaults and data corruption while loading the model. This can cause a denial of service in products using `tensorflow-serving` or other… | |
| Modificada | Crítica (9.8) | 1.0% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap overflow errors and even leak contents of memory In the linked code snippet, all the binary strings after `ee ff` are… | |
| Modificada | Media (5.3) | 0.90% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In eager mode, TensorFlow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1 does not set the session state. Hence, calling `tf.raw_ops.GetSessionHandle` or `tf.raw_ops.GetSessionHandleV2` results in a null pointer dereference In linked snippet, in eager mode, `ctx->session_state()` returns `nullptr`. Since code… | |
| Modificada | Alta (7.5) | 0.97% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, by controlling the `fill` argument of tf.strings.as_string, a malicious attacker is able to trigger a format string vulnerability due to the way the internal format use in a `printf` call is constructed. This may result in segmentation fault. The… | |
| Modificada | Crítica (9) | 1.3% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking two `int64` (i.e., `long long`) arguments. However, there are several places in TensorFlow where a lambda taking `int` or `int32` arguments is being used. In these cases,… | |
| Modificada | Alta (8.8) | 0.95% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the implementation of `SparseFillEmptyRowsGrad` uses a double indexing pattern. It is possible for `reverse_index_map(i)` to be an index outside of bounds of `grad_values`, thus resulting in a heap buffer overflow. The issue is patched in commit… | |
| Modificada | Media (5.3) | 1.0% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the shapes of its arguments. Although `reverse_index_map_t` and `grad_values_t` are accessed in a similar pattern, only `reverse_index_map_t` is validated to be of proper… | |
| Modificada | Alta (7.1) | 0.83% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In Tensorflow before versions 2.2.1 and 2.3.1, the implementation of `dlpack.to_dlpack` can be made to use uninitialized memory resulting in further memory corruption. This is because the pybind11 glue code assumes that the argument is a tensor. However, there is nothing stopping users from passing in a Python object… | |
| Modificada | Media (4.3) | 0.83% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes a list of strings to `dlpack.to_dlpack` there is a memory leak following an expected validation failure. The issue occurs because the `status` argument during validation failures is not properly checked. Since each of the above methods can return an error… | |
| Modificada | Media (5.3) | 0.90% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In Tensorflow before versions 2.2.1 and 2.3.1, if a user passes an invalid argument to `dlpack.to_dlpack` the expected validations will cause variables to bind to `nullptr` while setting a `status` variable to the error condition. However, this `status` argument is not properly checked. Hence, code following these… | |
| Modificada | Media (5.3) | 0.94% | — | Google TensorflowOpensuse Leap | 25/9/2020 | 17/6/2026 | In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `tf.raw_ops.Switch` operation takes as input a tensor and a boolean and outputs two tensors. Depending on the boolean value, one of the tensors is exactly the input tensor whereas the other one should be an empty tensor. However, the eager… | |
| Modificada | Media (6.1) | 0.97% | — | Redhat PagureOpensuse Backports SLEOpensuse Leap | 25/9/2020 | 17/6/2026 | Pagure before 5.6 allows XSS via the templates/blame.html blame view. | |
| Modificada | Media (5.5) | 0.40% | — | Linux KernelDebian LinuxOpensuse LeapCanonical Ubuntu Linux | 24/9/2020 | 17/6/2026 | A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a. | |
| Modificada | Media (4.7) | 0.26% | — | XENFedoraproject FedoraDebian LinuxOpensuse Leap | 23/9/2020 | 17/6/2026 | An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. When migrating timers of x86 HVM guests between its vCPUs, the locking model used allows for a second vCPU of the same guest (also operating on the timers) to release a lock that it didn't acquire. The… | |
| Modificada | Alta (7.8) | 0.41% | — | XENFedoraproject FedoraOpensuse LeapDebian Linux | 23/9/2020 | 17/6/2026 | An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event channel. Event channels control structures can be accessed lockless as long as the port is considered to be valid. Such a sequence is missing an appropriate memory barrier (e.g., smp_*mb()) to prevent… | |
| Modificada | Media (6) | 0.32% | — | XENFedoraproject FedoraDebian LinuxOpensuse Leap | 23/9/2020 | 17/6/2026 | An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to MSR_MISC_ENABLE. When a guest accesses certain Model Specific Registers, Xen first reads the value from hardware to use as the basis for auditing the guest access. For the MISC_ENABLE MSR, which is… |