Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

368 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)4.4%—ParamikoRedhat Ansible TowerRedhat Virtualization HostRedhat Enterprise Linux Desktop+78/10/201817/6/2026
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.
ModificadaMedia (4.9)1.5%—Cisco Enterprise Network Virtualization Software5/10/201817/6/2026
A vulnerability in the user management functionality of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to perform a denial of service (DoS) attack against an affected system. The vulnerability is due to insufficient validation of user-provided input. An attacker…
ModificadaMedia (6.5)1.9%—Cisco Network Functions Virtualization Infrastructure5/10/201817/6/2026
A vulnerability in the REST API of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to read any file on an affected system. The vulnerability is due to insufficient authorization and parameter validation checks. An attacker could exploit this vulnerability by sending a…
ModificadaMedia (6.5)1.8%—Cisco Network Functions Virtualization Infrastructure5/10/201817/6/2026
A vulnerability in the web-based management interface of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to cause an affected system to reboot or shut down. The vulnerability is due to insufficient server-side authorization checks. An attacker who is logged in to the…
ModificadaMedia (6.5)2.3%—Redhat UndertowRedhat VirtualizationRedhat Virtualization Host11/9/201817/6/2026
It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.
ModificadaMedia (6.5)2.1%—GlusterfsRedhat Enterprise LinuxRedhat Enterprise Linux ServerDebian Linux+34/9/201817/6/2026
A flaw was found in RPC request using gfs3_rename_req in glusterfs server. An authenticated attacker could use this flaw to write to a destination outside the gluster volume.
ModificadaAlta (8.8)3.3%—Debian LinuxRedhat Enterprise Linux ServerGlusterfsRedhat Virtualization Host+14/9/201817/6/2026
A flaw was found in RPC request using gfs2_create_req in glusterfs server. An authenticated attacker could use this flaw to create arbitrary files and execute arbitrary code on glusterfs server nodes.
ModificadaAlta (8.8)2.7%—Debian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux ServerGlusterfs+34/9/201817/6/2026
A flaw was found in RPC request using gfs3_symlink_req in glusterfs server which allows symlink destinations to point to file paths outside of the gluster volume. An authenticated attacker could use this flaw to create arbitrary symlinks pointing anywhere on the server and execute arbitrary code on glusterfs server…
ModificadaAlta (8.1)2.8%—Debian LinuxRedhat Enterprise Linux ServerGlusterfsRedhat Virtualization Host+14/9/201817/6/2026
A flaw was found in RPC request using gfs3_lookup_req in glusterfs server. An authenticated attacker could use this flaw to leak information and execute remote denial of service by crashing gluster brick process.
ModificadaAlta (8.8)2.6%—Redhat Virtualization HostDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Server+24/9/201817/6/2026
A flaw was found in RPC request using gfs3_mknod_req supported by glusterfs server. An authenticated attacker could use this flaw to write files to an arbitrary location via path traversal and execute arbitrary code on a glusterfs server node.
ModificadaAlta (8.1)1.7%—GlusterfsRedhat Virtualization HostDebian LinuxRedhat Enterprise Linux Server+14/9/201817/6/2026
It was found that the "mknod" call derived from mknod(2) can create files pointing to devices on a glusterfs server node. An authenticated attacker could use this to create an arbitrary device and read data from any device attached to the glusterfs server node.
ModificadaMedia (6.5)2.4%—GlusterfsRedhat Virtualization HostRedhat Enterprise Linux ServerDebian Linux+14/9/201817/6/2026
It was found that an attacker could issue a xattr request via glusterfs FUSE to cause gluster brick process to crash which will result in a remote denial of service. If gluster multiplexing is enabled this will result in a crash of multiple bricks and gluster volumes.
ModificadaMedia (6.5)2.1%—GlusterfsRedhat Virtualization HostDebian LinuxRedhat Enterprise Linux Server+14/9/201817/6/2026
An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file.
ModificadaAlta (7.5)3.1%—GlusterfsRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+34/9/201817/6/2026
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
ModificadaAlta (8.8)3.4%—GlusterfsRedhat Virtualization HostRedhat Enterprise Linux ServerDebian Linux+14/9/201817/6/2026
It was found that glusterfs server is vulnerable to multiple stack based buffer overflows due to functions in server-rpc-fopc.c allocating fixed size buffers using 'alloca(3)'. An authenticated attacker could exploit this by mounting a gluster volume and sending a string longer that the fixed buffer size to cause…
ModificadaAlta (8.8)3.0%—GlusterfsRedhat Virtualization HostRedhat Enterprise Linux ServerDebian Linux+14/9/201817/6/2026
It was found that glusterfs server does not properly sanitize file paths in the "trusted.io-stats-dump" extended attribute which is used by the "debug/io-stats" translator. Attacker can use this flaw to create files and execute arbitrary code. To exploit this attacker would require sufficient access to modify the…
ModificadaCrítica (9.8)2.4%—Microfocus Data Center AutomationMicrofocus Hybrid Cloud ManagementMicrofocus Network Operations ManagementMicrofocus Operations Bridge+430/8/201817/6/2026
Remote Code Execution in the following products Hybrid Cloud Management Containerized Suite HCM2017.11, HCM2018.02, HCM2018.05, Operations Bridge Containerized Suite 2017.11, 2018.02, 2018.05, Data Center Automation Containerized Suite 2017.01 until 2018.05, Service Management Automation Suite 2017.11, 2018.02,…
ModificadaAlta (8.8)4.3%—Debian LinuxCanonical Ubuntu LinuxSambaRedhat Virtualization+422/8/201817/6/2026
A heap-buffer overflow was found in the way samba clients processed extra long filename in a directory listing. A malicious samba server could use this flaw to cause arbitrary code execution on a samba client. Samba versions before 4.6.16, 4.7.9 and 4.8.4 are vulnerable.
ModificadaMedia (5.5)0.41%—LibvirtRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+620/8/201817/6/2026
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
ModificadaAlta (8.8)3.9%—Spice Project SpiceDebian LinuxCanonical Ubuntu LinuxRedhat Virtualization+717/8/201817/6/2026
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
ModificadaAlta (7.5)5.2%—Redhat OpenstackRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+59/8/201817/6/2026
A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security…
ModificadaMedia (6.3)1.2%—Ovirt VdsmRedhat Virtualization9/8/201817/6/2026
It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image, an attacker could cause the qemu-img process to consume unbounded amounts of memory of CPU time, causing a denial of service condition that could potentially impact…
ModificadaMedia (4.3)0.81%—HP Network Function Virtualization Director6/8/201817/6/2026
HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Director (NFVD) 4.2.1 prior to gui patch 3.
ModificadaAlta (7.5)74%—Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+346/8/201817/6/2026
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
ModificadaAlta (8.1)5.6%—RPM Yum-utilsRedhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+11/8/201817/6/2026
A directory traversal issue was found in reposync, a part of yum-utils, where reposync fails to sanitize paths in remote repository configuration files. If an attacker controls a repository, they may be able to copy files outside of the destination directory on the targeted system via path traversal. If reposync is…
Orbitaley — Vulnerabilidades