Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1112 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.14%—Openbsd10/8/202317/6/2026
OpenBSD 7.3 before errata 014 is missing an argument-count bounds check in console terminal emulation. This could cause incorrect memory access and a kernel crash after receiving crafted DCS or CSI terminal escape sequences.
ModificadaAlta (8.8)0.23%—Freebsd1/8/202317/6/2026
The fwctl driver implements a state machine which is executed when a bhyve guest accesses certain x86 I/O ports. The interface lets the guest copy a string into a buffer resident in the bhyve process' memory. A bug in the state machine implementation can result in a buffer overflowing when copying this string.…
ModificadaAlta (7.5)0.65%—FreebsdNetapp Clustered Data Ontap1/8/202317/6/2026
A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.
ModificadaCrítica (9.8)80%💥 PoCOpenbsd OpensshFedoraproject Fedora20/7/202317/6/2026
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix…
ModificadaCrítica (9.8)1.1%—Freebsd22/6/202317/6/2026
pam_krb5 authenticates a user by essentially running kinit with the password, getting a ticket-granting ticket (tgt) from the Kerberos KDC (Key Distribution Center) over the network, as a way to verify the password. However, if a keytab is not provisioned on the system, pam_krb5 has no way to validate the response…
ModificadaCrítica (9.8)0.94%—Openbsd LibresslOpenbsd16/6/202317/6/2026
A double free or use after free could occur after SSL_clear in OpenBSD 7.2 before errata 026 and 7.3 before errata 004, and in LibreSSL before 3.6.3 and 3.7.x before 3.7.3. NOTE: OpenSSL is not affected.
ModificadaCrítica (9.8)0.57%—Openbsd LibresslOpenbsd15/4/202317/6/2026
x509/x509_verify.c in LibreSSL before 3.4.2, and OpenBSD before 7.0 errata 006, allows authentication bypass because an error for an unverified certificate chain is sometimes discarded.
ModificadaMedia (5.3)0.36%—Openbsd LibresslOpenbsd12/4/202317/6/2026
An issue was discovered in x509/x509_verify.c in LibreSSL before 3.6.1, and in OpenBSD before 7.2 errata 001. x509_verify_ctx_add_chain does not store errors that occur during leaf certificate verification, and therefore an incorrect error is returned. This behavior occurs when there is an installed verification…
ModificadaAlta (7.8)0.28%—OpensmtpdOpenbsd4/4/202317/6/2026
ascii_load_sockaddr in smtpd in OpenBSD before 7.1 errata 024 and 7.2 before errata 020, and OpenSMTPD Portable before 7.0.0-portable commit f748277, can abort upon a connection from a local, scoped IPv6 address.
ModificadaCrítica (9.8)2.3%—Openbsd OpensshNetapp Brocade Fabric Operating SystemNetapp HCI Bootstrap OSNetapp Solidfire Element OS17/3/202314/7/2026
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
ModificadaAlta (7.5)0.76%—Openbsd3/3/202317/6/2026
In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.
ModificadaMedia (6.5)0.64%—Freebsd8/2/202317/6/2026
When GELI reads a key file from standard input, it does not reuse the key file to initialize multiple providers at once resulting in the second and subsequent devices silently using a NULL key as the user key file. If a user only uses a key file without a user passphrase, the master key is encrypted with an empty key…
ModificadaMedia (6.5)90%💥 PoCOpenbsd OpensshFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp A250 Firmware+23/2/202317/6/2026
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states…
ModificadaAlta (7.5)1.3%—Libsdl Simple Directmedia LayerRedhat Enterprise Linux12/1/202317/6/2026
A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x are not affected.
ModificadaAlta (7.5)0.81%—Freebsd6/9/202217/6/2026
sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a denial-of-service (DoS) vulnerability due to improper handling of TSopt on TCP connections. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaAlta (7.5)1.1%—Libsdl Simple Directmedia Layer28/7/202217/6/2026
SDL v1.2 was discovered to contain a use-after-free via the XFree function at /src/video/x11/SDL_x11yuv.c.
ModificadaAlta (7.8)0.99%—Libsdl SDL TTFFedoraproject Fedora4/5/202217/6/2026
SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file.
ModificadaAlta (8.8)2.1%—Libsdl Simple Directmedia Layer1/4/202217/6/2026
There is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, an attacker can cause the application using this library to crash, denial of service or Code execution.
ModificadaAlta (7.5)1.9%—Openbsd25/3/202217/6/2026
slaacd in OpenBSD 6.9 and 7.0 before 2022-03-22 has an integer signedness error and resultant heap-based buffer overflow triggerable by a crafted IPv6 router advertisement. NOTE: privilege separation and pledge can prevent exploitation.
ModificadaAlta (7.5)1.9%—Openbsd25/3/202217/6/2026
engine.c in slaacd in OpenBSD 6.9 and 7.0 before 2022-02-21 has a buffer overflow triggerable by an IPv6 router advertisement with more than seven nameservers. NOTE: privilege separation and pledge can prevent exploitation.
ModificadaBaja (3.7)1.7%—Openbsd OpensshDebian Linux13/3/202217/6/2026
An issue was discovered in OpenSSH before 8.9. If a client is using public-key authentication with agent forwarding but without -oLogLevel=verbose, and an attacker has silently modified the server to support the None authentication option, then the user cannot determine whether FIDO authentication is going to confirm…
ModificadaAlta (7.5)0.85%—Freebsd18/1/202217/6/2026
In FreeBSD 13.0-STABLE before n247428-9352de39c3dc, 12.2-STABLE before r370674, 13.0-RELEASE before p6, and 12.2-RELEASE before p12, certain conditions involving use of the highlight buffer while text is scrolling on the console, console data may overwrite data structures associated with the system console or other…
ModificadaAlta (7.5)0.96%—Netbsd25/12/202117/6/2026
In NetBSD through 9.2, the IPv6 Flow Label generation algorithm employs a weak cryptographic PRNG.
ModificadaAlta (7.5)0.96%—Netbsd25/12/202117/6/2026
In NetBSD through 9.2, there is an information leak in the TCP ISN (ISS) generation algorithm.
ModificadaAlta (7.5)0.96%—Netbsd25/12/202117/6/2026
In NetBSD through 9.2, the IPv4 ID generation algorithm does not use appropriate cryptographic measures.
Orbitaley — Vulnerabilidades