Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

4278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.49%—Advanced Intrusion Detection Environment Project Advanced Intrusion Detection EnvironmentRedhat Ovirt-nodeRedhat Virtualization HostRedhat Enterprise Linux+320/1/202217/6/2026
AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
ModificadaAlta (7.5)3.1%—ClamavDebian LinuxCanonical Ubuntu Linux14/1/202217/6/2026
A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper checks that may result in an…
ModificadaAlta (7.3)2.5%—Djangoproject DjangoRedhat SatelliteDebian LinuxCanonical Ubuntu Linux+18/12/202117/6/2026
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
ModificadaAlta (7.8)0.37%—Canonical AccountsserviceCanonical Ubuntu Linux17/11/202117/6/2026
Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus function. This is fixed in versions…
ModificadaAlta (7.8)0.25%—Canonical Multipass1/10/202117/6/2026
The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner.
ModificadaMedia (5.5)0.46%—Canonical Apport1/10/202117/6/2026
—
ModificadaMedia (5.5)0.46%—Canonical Apport1/10/202117/6/2026
—
ModificadaAlta (8.8)0.25%—Canonical Multipass1/10/202117/6/2026
The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation.
ModificadaAlta (7.1)0.39%—Canonical Apport12/6/202117/6/2026
It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks.
ModificadaBaja (3.3)0.33%—Canonical Apport12/6/202117/6/2026
It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.32%—Canonical Ubuntu LinuxOracle Openjdk12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.29%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could expose private data to other local users.
ModificadaMedia (5.5)0.30%—Canonical Ubuntu Linux12/6/202117/6/2026
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could expose private data to other local users.
ModificadaAlta (7.8)0.57%—Canonical Apport11/6/202117/6/2026
It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO.
ModificadaAlta (7.8)0.43%—Canonical Apport11/6/202117/6/2026
It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel.
ModificadaAlta (7.8)0.45%—Canonical Apport11/6/202117/6/2026
It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel.
ModificadaAlta (8.8)0.64%—Linux KernelCanonical Ubuntu Linux4/6/202117/6/2026
The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc/<PID>/mem. This could be used to create a heap overflow leading to arbitrary code execution in the kernel. It was addressed via…
ModificadaAlta (7.8)27%💥 ExploitLinux KernelCanonical Ubuntu Linux4/6/202117/6/2026
The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue was fixed via commit 049c4e13714e ("bpf: Fix alu32 const subreg…
ModificadaAlta (7.8)0.55%—Linux KernelCanonical Ubuntu Linux4/6/202117/6/2026
The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue was fixed via commit 4b81ccebaeee ("bpf, ringbuf: Deny…