Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

4185 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)6.4%—ISC BindFedoraproject FedoraOpensuse LeapDebian Linux+321/8/202017/6/2026
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with…
ModificadaMedia (6.5)5.6%—ISC BindFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+421/8/202017/6/2026
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an…
ModificadaAlta (7.5)3.0%—ISC BindOpensuse LeapCanonical Ubuntu LinuxSynology DNS Server+121/8/202017/6/2026
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the server to crash. Servers that 'forward only' are not affected.
ModificadaAlta (7.5)3.7%—ISC BindOpensuse LeapNetapp Steelstore Cloud Integrated StorageCanonical Ubuntu Linux21/8/202017/6/2026
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit.
ModificadaAlta (7.8)0.38%—Net-snmpCanonical Ubuntu LinuxNetapp Cloud BackupNetapp HCI Management Node+220/8/202017/6/2026
Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root.
ModificadaAlta (7.8)0.46%—Net-snmpCanonical Ubuntu LinuxNetapp Cloud BackupNetapp Smi-s Provider+120/8/202017/6/2026
Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.
ModificadaAlta (7.8)1.0%💥 PoCLinux KernelRedhat Enterprise LinuxOpensuse LeapDebian Linux+619/8/202017/6/2026
A flaw null pointer dereference in the Linux kernel cgroupv2 subsystem in versions before 5.7.10 was found in the way when reboot the system. A local user could use this flaw to crash the system or escalate their privileges on the system.
ModificadaAlta (7.1)0.36%—Linux KernelCanonical Ubuntu LinuxOpensuse LeapOracle Sd-wan Edge+119/8/202017/6/2026
In the Linux kernel before 5.7.8, fs/nfsd/vfs.c (in the NFS server) can set incorrect permissions on new filesystem objects when the filesystem lacks ACL support, aka CID-22cf8419f131. This occurs because the current umask is not considered.
AnalizadaCrítica (10)99%⚠ Explotación activa💥 ExploitMicrosoft Windows Server 1903Microsoft Windows Server 1909Microsoft Windows Server 2004Microsoft Windows Server 2008+1117/8/202017/6/2026
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the…
ModificadaMedia (5.5)1.9%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A buffer overflow vulnerability in GetNumSameData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
ModificadaMedia (5.5)1.8%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A division by zero vulnerability in dot24_print_page() in devices/gdevdm24.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
ModificadaMedia (5.5)1.9%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A buffer overflow vulnerability in lxm5700m_print_page() in devices/gdevlxm.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted eps file. This is fixed in v9.51.
ModificadaMedia (5.5)1.9%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A buffer overflow vulnerability in p_print_image() in devices/gdevcdj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
ModificadaMedia (5.5)1.8%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A null pointer dereference vulnerability in devices/vector/gdevtxtw.c and psi/zbfont.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.
ModificadaMedia (5.5)1.8%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A null pointer dereference vulnerability in devices/gdevtsep.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted postscript file. This is fixed in v9.51.
ModificadaMedia (5.5)2.3%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A buffer overflow vulnerability in pcx_write_rle() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
AnalizadaMedia (5.5)1.9%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A buffer overflow vulnerability in image_render_color_thresh() in base/gxicolor.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to escalate privileges via a crafted eps file. This is fixed in v9.51.
ModificadaAlta (7.8)1.8%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A use-after-free vulnerability in xps_finish_image_path() in devices/vector/gdevxps.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.
ModificadaMedia (5.5)1.9%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A buffer overflow vulnerability in jetp3852_print_page() in devices/gdev3852.c of Artifex Software GhostScript v9.50 allows a remote attacker to escalate privileges via a crafted PDF file. This is fixed in v9.51.
ModificadaMedia (5.5)1.9%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A buffer overflow vulnerability in okiibm_print_page1() in devices/gdevokii.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
ModificadaMedia (5.5)2.0%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A buffer overflow vulnerability in tiff12_print_page() in devices/gdevtfnx.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
ModificadaMedia (5.5)1.8%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A Division by Zero vulnerability in bj10v_print_page() in contrib/japanese/gdev10v.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
ModificadaMedia (5.5)2.0%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A buffer overflow vulnerability in mj_color_correct() in contrib/japanese/gdevmjc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
AnalizadaMedia (5.5)2.3%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A buffer overflow vulnerability in FloydSteinbergDitheringC() in contrib/gdevbjca.c of Artifex Software GhostScript v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.
ModificadaMedia (5.5)2.1%—Artifex GhostscriptDebian LinuxCanonical Ubuntu Linux13/8/202017/6/2026
A buffer overflow vulnerability in GetNumWrongData() in contrib/lips4/gdevlips.c of Artifex Software GhostScript from v9.18 to v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.