Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 51% | — | OpensslDebian LinuxTenable LOG Correlation EngineTenable Nessus Network Monitor+17 | 16/2/2021 | 17/6/2026 | Calls to EVP_CipherUpdate, EVP_EncryptUpdate and EVP_DecryptUpdate may overflow the output length argument in some cases where the input length is close to the maximum permissable length for an integer on the platform. In such cases the return value from the function call will be 1 (indicating success), but the output… | |
| Modificada | Media (6.5) | 16% | — | Nodejs Node.jsDebian LinuxFedoraproject FedoraOracle Graalvm+1 | 6/1/2021 | 17/6/2026 | Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 allow two copies of a header field in an HTTP request (for example, two Transfer-Encoding header fields). In this case, Node.js identifies the first header field and ignores the second. This can lead to HTTP Request Smuggling. | |
| Modificada | Alta (8.1) | 9.1% | — | Nodejs Node.jsDebian LinuxFedoraproject FedoraOracle Graalvm+1 | 6/1/2021 | 17/6/2026 | Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an… | |
| Modificada | Media (5.9) | 7.1% | — | OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+40 | 8/12/2020 | 17/6/2026 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both… | |
| Modificada | Media (6.5) | 3.7% | — | Nodejs Node.js | 3/12/2020 | 17/6/2026 | Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x). | |
| Modificada | Alta (7.5) | 54% | — | Nodejs Node.jsFedoraproject FedoraOracle Blockchain PlatformOracle Graalvm+4 | 19/11/2020 | 17/6/2026 | A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1. | |
| Modificada | Alta (7.8) | 0.71% | — | Nodejs Node.jsOpensuse LeapFedoraproject Fedora | 18/9/2020 | 17/6/2026 | The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes. | |
| Modificada | Alta (7.5) | 8.4% | — | Nodejs Node.jsFedoraproject Fedora | 18/9/2020 | 17/6/2026 | Node.js < 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can make the server unable to accept new connections. | |
| Modificada | Alta (7.4) | 5.3% | — | Nodejs Node.jsOpensuse LeapFedoraproject Fedora | 18/9/2020 | 17/6/2026 | Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying… | |
| Modificada | Alta (8.1) | 7.6% | — | Nodejs Node.jsOracle Banking Extensibility WorkbenchOracle Blockchain PlatformOracle Mysql Cluster+5 | 24/7/2020 | 17/6/2026 | napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0. | |
| Modificada | Alta (7.4) | 6.1% | — | Nodejs Node.jsOracle Banking Extensibility WorkbenchOracle Blockchain PlatformOracle Graalvm+1 | 8/6/2020 | 17/6/2026 | TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0. | |
| Modificada | Alta (7.5) | 5.3% | — | Nghttp2Debian LinuxOpensuse LeapFedoraproject Fedora+6 | 3/6/2020 | 17/6/2026 | In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at… | |
| Modificada | Alta (8.8) | 2.7% | — | Icu-project International Components FOR UnicodeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+7 | 12/3/2020 | 17/6/2026 | An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp. | |
| Modificada | Alta (8.1) | 2.5% | — | LibuvNodejs Node.js | 11/2/2020 | 17/6/2026 | The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent threads from releasing the locks of other threads, which allows attackers to cause a denial of service (deadlock) or possibly have unspecified other impact by leveraging a race condition. | |
| Modificada | Crítica (9.8) | 20% | — | Nodejs Node.jsOracle Communications Cloud Native Core Network Function Cloud Native EnvironmentOracle GraalvmDebian Linux+3 | 7/2/2020 | 17/6/2026 | Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons | |
| Modificada | Crítica (9.8) | 57% | — | Nodejs Node.jsDebian LinuxFedoraproject FedoraOpensuse Leap+9 | 7/2/2020 | 17/6/2026 | HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed | |
| Modificada | Alta (7.5) | 20% | — | Nodejs Node.jsDebian LinuxOpensuse LeapRedhat Software Collections+6 | 7/2/2020 | 17/6/2026 | Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate | |
| Modificada | Alta (8.8) | 1.9% | — | Codecov Nodejs Uploader | 25/1/2020 | 17/6/2026 | Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument. | |
| Modificada | Alta (7.5) | 25% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+14 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These frames can be DATA, HEADERS, CONTINUATION and/or PUSH_PROMISE. The peer spends time processing each… | |
| Modificada | Alta (7.5) | 28% | — | Apple SwiftnioApache Http ServerApache Traffic ServerCanonical Ubuntu Linux+19 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they leave the TCP window closed so the peer cannot actually write (many of) the bytes on the wire. The… | |
| Modificada | Media (6.5) | 56% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+15 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman encoded into 1-byte or greater headers. Some implementations allocate memory for these headers and… | |
| Modificada | Alta (7.5) | 87% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+18 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one acknowledgement per SETTINGS frame, an empty SETTINGS frame is almost equivalent in behavior to a… | |
| Modificada | Alta (7.5) | 83% | — | Apple SwiftnioApache Traffic ServerDebian LinuxCanonical Ubuntu Linux+24 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can… | |
| Modificada | Alta (7.5) | 82% | — | Apple SwiftnioApache Traffic ServerCanonical Ubuntu LinuxDebian Linux+16 | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to resource loops, potentially leading to a denial of service. The attacker creates multiple request streams and continually shuffles the priority of the streams in a way that causes substantial churn to the priority tree. This can consume excess CPU. | |
| Modificada | Alta (7.5) | 83% | — | Apple SwiftnioApache Traffic ServerDebian LinuxNodejs Node.js | 13/8/2019 | 17/6/2026 | Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses. Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both. |