Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
4278 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.49% | — | Advanced Intrusion Detection Environment Project Advanced Intrusion Detection EnvironmentRedhat Ovirt-nodeRedhat Virtualization HostRedhat Enterprise Linux+3 | 20/1/2022 | 17/6/2026 | AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 3.1% | — | ClamavDebian LinuxCanonical Ubuntu Linux | 14/1/2022 | 17/6/2026 | A vulnerability in the OOXML parsing module in Clam AntiVirus (ClamAV) Software version 0.104.1 and LTS version 0.103.4 and prior versions could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to improper checks that may result in an… | |
| Modificada | Alta (7.3) | 2.5% | — | Djangoproject DjangoRedhat SatelliteDebian LinuxCanonical Ubuntu Linux+1 | 8/12/2021 | 17/6/2026 | In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths. | |
| Modificada | Alta (7.8) | 0.37% | — | Canonical AccountsserviceCanonical Ubuntu Linux | 17/11/2021 | 17/6/2026 | Ubuntu-specific modifications to accountsservice (in patch file debian/patches/0010-set-language.patch) caused the fallback_locale variable, pointing to static storage, to be freed, in the user_change_language_authorized_cb function. This is reachable via the SetLanguage dbus function. This is fixed in versions… | |
| Modificada | Alta (7.8) | 0.25% | — | Canonical Multipass | 1/10/2021 | 17/6/2026 | The MacOS version of Multipass, version 1.7.0, fixed in 1.7.2, accidentally installed the application directory with incorrect owner. | |
| Modificada | Media (5.5) | 0.46% | — | Canonical Apport | 1/10/2021 | 17/6/2026 | — | |
| Modificada | Media (5.5) | 0.46% | — | Canonical Apport | 1/10/2021 | 17/6/2026 | — | |
| Modificada | Alta (8.8) | 0.25% | — | Canonical Multipass | 1/10/2021 | 17/6/2026 | The Windows version of Multipass before 1.7.0 allowed any local process to connect to the localhost TCP control socket to perform mounts from the operating system to a guest, allowing for privilege escalation. | |
| Modificada | Alta (7.1) | 0.39% | — | Canonical Apport | 12/6/2021 | 17/6/2026 | It was discovered that the process_report() function in data/whoopsie-upload-all allowed arbitrary file writes via symlinks. | |
| Modificada | Baja (3.3) | 0.33% | — | Canonical Apport | 12/6/2021 | 17/6/2026 | It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call. | |
| Modificada | Media (5.5) | 0.29% | — | Canonical Ubuntu Linux | 12/6/2021 | 17/6/2026 | It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg-hwe-18.04 package apport hooks, it could expose private data to other local users. | |
| Modificada | Media (5.5) | 0.29% | — | Canonical Ubuntu Linux | 12/6/2021 | 17/6/2026 | It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the xorg package apport hooks, it could expose private data to other local users. | |
| Modificada | Media (5.5) | 0.32% | — | Canonical Ubuntu LinuxOracle Openjdk | 12/6/2021 | 17/6/2026 | It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-17 package apport hooks, it could expose private data to other local users. | |
| Modificada | Media (5.5) | 0.29% | — | Canonical Ubuntu Linux | 12/6/2021 | 17/6/2026 | It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users. | |
| Modificada | Media (5.5) | 0.29% | — | Canonical Ubuntu Linux | 12/6/2021 | 17/6/2026 | It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-15 package apport hooks, it could expose private data to other local users. | |
| Modificada | Media (5.5) | 0.29% | — | Canonical Ubuntu Linux | 12/6/2021 | 17/6/2026 | It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-14 package apport hooks, it could expose private data to other local users. | |
| Modificada | Media (5.5) | 0.29% | — | Canonical Ubuntu Linux | 12/6/2021 | 17/6/2026 | It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-13 package apport hooks, it could expose private data to other local users. | |
| Modificada | Media (5.5) | 0.29% | — | Canonical Ubuntu Linux | 12/6/2021 | 17/6/2026 | It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-8 package apport hooks, it could expose private data to other local users. | |
| Modificada | Media (5.5) | 0.30% | — | Canonical Ubuntu Linux | 12/6/2021 | 17/6/2026 | It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-lts package apport hooks, it could expose private data to other local users. | |
| Modificada | Alta (7.8) | 0.57% | — | Canonical Apport | 11/6/2021 | 17/6/2026 | It was discovered that apport in data/apport did not properly open a report file to prevent hanging reads on a FIFO. | |
| Modificada | Alta (7.8) | 0.43% | — | Canonical Apport | 11/6/2021 | 17/6/2026 | It was discovered that the get_starttime() function in data/apport did not properly parse the /proc/pid/stat file from the kernel. | |
| Modificada | Alta (7.8) | 0.45% | — | Canonical Apport | 11/6/2021 | 17/6/2026 | It was discovered that the get_pid_info() function in data/apport did not properly parse the /proc/pid/status file from the kernel. | |
| Modificada | Alta (8.8) | 0.64% | — | Linux KernelCanonical Ubuntu Linux | 4/6/2021 | 17/6/2026 | The io_uring subsystem in the Linux kernel allowed the MAX_RW_COUNT limit to be bypassed in the PROVIDE_BUFFERS operation, which led to negative values being usedin mem_rw when reading /proc/<PID>/mem. This could be used to create a heap overflow leading to arbitrary code execution in the kernel. It was addressed via… | |
| Modificada | Alta (7.8) | 27% | 💥 Exploit | Linux KernelCanonical Ubuntu Linux | 4/6/2021 | 17/6/2026 | The eBPF ALU32 bounds tracking for bitwise ops (AND, OR and XOR) in the Linux kernel did not properly update 32-bit bounds, which could be turned into out of bounds reads and writes in the Linux kernel and therefore, arbitrary code execution. This issue was fixed via commit 049c4e13714e ("bpf: Fix alu32 const subreg… | |
| Modificada | Alta (7.8) | 0.55% | — | Linux KernelCanonical Ubuntu Linux | 4/6/2021 | 17/6/2026 | The eBPF RINGBUF bpf_ringbuf_reserve() function in the Linux kernel did not check that the allocated size was smaller than the ringbuf size, allowing an attacker to perform out-of-bounds writes within the kernel and therefore, arbitrary code execution. This issue was fixed via commit 4b81ccebaeee ("bpf, ringbuf: Deny… |