Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2649▼ 259 respecto a la semana anterior
Críticas / altas1356▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.4) | 4.3% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Modificada | Crítica (9.4) | 5.1% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Modificada | Alta (8.8) | 2.3% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Analizada | Alta (7.8) | 52% | ⚠ Explotación activa | Linux KernelDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+18 | 17/7/2019 | 17/6/2026 | In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges… | |
| Modificada | Alta (7.8) | 0.41% | — | Intel Processor Diagnostic Tool | 11/7/2019 | 17/6/2026 | Improper access control in the Intel(R) Processor Diagnostic Tool before version 4.1.2.24 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access. | |
| Modificada | Crítica (9.8) | 4.7% | — | HP 3par Service Processor Firmware | 9/7/2019 | 17/6/2026 | HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for the disruption of the confidentiality, integrity and availability of the Service Processor and any… | |
| Modificada | Media (6.7) | 0.40% | — | Intel Xeon D-1649n FirmwareIntel Xeon D-1633n FirmwareIntel Xeon D-1637 FirmwareIntel Xeon D-1627 Firmware+44 | 17/5/2019 | 17/6/2026 | Insufficient access control in silicon reference firmware for Intel(R) Xeon(R) Scalable Processor, Intel(R) Xeon(R) Processor D Family may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. | |
| Modificada | Media (6.7) | 0.43% | — | Intel Xeon D-1649n FirmwareIntel Xeon D-1633n FirmwareIntel Xeon D-1637 FirmwareIntel Xeon D-1627 Firmware+88 | 17/5/2019 | 17/6/2026 | Buffer overflow vulnerability in system firmware for Intel(R) Xeon(R) Processor D Family, Intel(R) Xeon(R) Scalable Processor, Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. | |
| Modificada | Media (6.1) | 87% | — | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Crítica (9.8) | 3.5% | — | Netapp Service Processor | 21/3/2019 | 17/6/2026 | Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Impact section may be affected and should be upgraded to a fixed version of Service… | |
| Modificada | Media (5.9) | 17% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+78 | 27/2/2019 | 17/6/2026 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid… | |
| Modificada | Alta (7.8) | 1.0% | — | Atlantiswordprocessor Atlantis Word Processor | 1/12/2018 | 17/6/2026 | An exploitable uninitialized pointer vulnerability exists in the rich text format parser of Atlantis Word Processor, version 3.2.7.2. A specially crafted document can cause certain RTF tokens to dereference a pointer that has been uninitialized and then write to it. An attacker must convince a victim to open a… | |
| Modificada | Alta (7.8) | 1.4% | — | Atlantiswordprocessor Atlantis Word Processor | 1/12/2018 | 17/6/2026 | An exploitable out-of-bounds write vulnerability exists in the PNG implementation of Atlantis Word Processor, version 3.2.7.2. This can allow an attacker to corrupt memory, which can result in code execution under the context of the application. An attacker must convince a victim to open a specially crafted document… | |
| Modificada | Alta (7.8) | 1.3% | — | Atlantiswordprocessor Atlantis Word Processor | 1/12/2018 | 17/6/2026 | An exploitable arbitrary write vulnerability exists in the open document format parser of the Atlantis Word Processor, version 3.2.7.2, while trying to null-terminate a string. A specially crafted document can allow an attacker to pass an untrusted value as a length to a constructor. This constructor will miscalculate… | |
| Modificada | Alta (7.8) | 1.5% | — | Atlantiswordprocessor Atlantis Word Processor | 1/10/2018 | 17/6/2026 | An exploitable uninitialized pointer vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted document can cause an uninitialized pointer representing a TTableRow to be assigned to a variable on the stack. This variable is later dereferenced and then written… | |
| Modificada | Alta (7.8) | 1.0% | — | Atlantiswordprocessor Atlantis Word Processor | 1/10/2018 | 17/6/2026 | An exploitable double-free vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted document can cause a TTableRow instance to be referenced twice, resulting in a double-free vulnerability when both the references go out of scope. An attacker must convince a… | |
| Modificada | Alta (7.8) | 0.89% | — | Atlantiswordprocessor Atlantis Word Processor | 1/10/2018 | 17/6/2026 | An exploitable stack-based buffer overflow vulnerability exists in the JPEG parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted image embedded within a document can cause a length to be miscalculated and underflow. This length is then treated as unsigned and then used in a copying operation. Due to… | |
| Modificada | Alta (7.8) | 1.0% | — | Atlantiswordprocessor Atlantis Word Processor | 1/10/2018 | 17/6/2026 | An exploitable heap-based buffer overflow vulnerability exists in the Windows enhanced metafile parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted image embedded within a document can cause an undersized allocation, resulting in an overflow when the application tries to copy data into it. An… | |
| Modificada | Alta (7.8) | 1.4% | — | Atlantiswordprocessor Atlantis Word Processor | 1/10/2018 | 17/6/2026 | An exploitable uninitialized length vulnerability exists within the Word document-parser of the Atlantis Word Processor 3.0.2.3 and 3.0.2.5. A specially crafted document can cause Atlantis to skip initializing a value representing the number of columns of a table. Later, the application will use this as a length… | |
| Modificada | Alta (7.8) | 1.3% | — | Atlantiswordprocessor Atlantis Word Processor | 1/10/2018 | 17/6/2026 | An exploitable arbitrary write vulnerability exists in the Word document parser of the Atlantis Word Processor 3.0.2.3 and 3.0.2.5. A specially crafted document can prevent Atlas from adding elements to an array that is indexed by a loop. When reading from this array, the application will use an out-of-bounds index… | |
| Modificada | Alta (7.8) | 1.0% | — | Atlantiswordprocessor Atlantis Word Processor | 1/10/2018 | 17/6/2026 | An exploitable out-of-bounds write vulnerability exists in the Word Document parser of the Atlantis Word Processor 3.0.2.3, 3.0.2.5. A specially crafted document can cause Atlantis to write a value outside the bounds of a heap allocation, resulting in a buffer overflow. An attacker must convince a victim to open a… | |
| Modificada | Alta (7.8) | 1.2% | — | Atlantiswordprocessor Atlantis Word Processor | 1/10/2018 | 17/6/2026 | An exploitable uninitialized variable vulnerability exists in the RTF-parsing functionality of Atlantis Word Processor 3.2.6 version. A specially crafted RTF file can leverage an uninitialized stack address, resulting in an out-of-bounds write, which in turn could lead to code execution. | |
| Modificada | Alta (8.8) | 1.5% | — | Logological General-purpose Preprocessor | 16/9/2018 | 17/6/2026 | GPP through 2.25 will try to use more memory space than is available on the stack, leading to a segmentation fault or possibly unspecified other impact via a crafted file. | |
| Modificada | Media (5.3) | 99% | — | Openbsd OpensshDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+18 | 17/8/2018 | 17/6/2026 | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c. | |
| Modificada | Media (6.5) | 1.7% | — | Oracle Communications Eagle Local Number Portability Application Processor | 18/7/2018 | 17/6/2026 | Vulnerability in the Oracle Communications EAGLE LNP Application Processor component of Oracle Communications Applications (subcomponent: GUI). The supported version that is affected is 10.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle… |