Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
382 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 1.2% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | There's a flaw in bfd_pef_scan_start_address() of bfd/pef.c in binutils which could allow an attacker who is able to submit a crafted file to be processed by objdump to cause a NULL pointer dereference. The greatest threat of this flaw is to application availability. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Media (5.5) | 1.2% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Media (6.1) | 1.1% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | There's a flaw in binutils /opcodes/tic4x-dis.c. An attacker who is able to submit a crafted input file to be processed by binutils could cause usage of uninitialized memory. The highest threat is to application availability with a lower threat to data confidentiality. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Media (5.5) | 1.1% | — | GNU BinutilsFedoraproject FedoraNetapp Cloud BackupNetapp Ontap Select Deploy Administration Utility+4 | 4/1/2021 | 17/6/2026 | A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34. | |
| Modificada | Alta (8.8) | 0.39% | — | XENLinux KernelNetapp HCI Compute Node BiosNetapp Solidfire & HCI Management Node+2 | 15/12/2020 | 17/6/2026 | An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread handler to reset ring->xenblkd to NULL when stopped. However, the handler may not have time to run if the frontend quickly toggles between the states connect and… | |
| Modificada | Alta (7.5) | 4.6% | — | Haxx LibcurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+13 | 14/12/2020 | 17/6/2026 | curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response. | |
| Modificada | Alta (7.5) | 9.8% | — | Haxx LibcurlDebian LinuxFedoraproject FedoraNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | curl 7.21.0 to and including 7.73.0 is vulnerable to uncontrolled recursion due to a stack overflow issue in FTP wildcard match parsing. | |
| Modificada | Baja (3.7) | 3.9% | — | Haxx CurlFedoraproject FedoraDebian LinuxNetapp Clustered Data Ontap+18 | 14/12/2020 | 17/6/2026 | A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions. | |
| Modificada | Media (5.7) | 0.28% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRGDebian Linux+3 | 11/12/2020 | 17/6/2026 | A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a… | |
| Modificada | Alta (7.8) | 1.7% | 💥 PoC | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise MRG+2 | 11/12/2020 | 17/6/2026 | A flaw was found in the Linux kernel’s implementation of MIDI, where an attacker with a local account and the permissions to issue ioctl commands to midi devices could trigger a use-after-free issue. A write to this specific memory while freed and before use causes the flow of execution to change and possibly allow… | |
| Modificada | Media (5.7) | 0.38% | — | Debian Advanced Package ToolNetapp Solidfire Baseboard Management Controller Firmware | 10/12/2020 | 17/6/2026 | — | |
| Modificada | Media (5.5) | 1.1% | — | GNU BinutilsNetapp Cloud BackupNetapp HCI Management NodeNetapp Ontap Select Deploy Administration Utility+1 | 9/12/2020 | 17/6/2026 | A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in _bfd_elf_get_symbol_version_string, as demonstrated in nm-new, that can cause a denial of service via a crafted file. | |
| Modificada | Media (5.5) | 1.2% | — | GNU BinutilsNetapp Cloud BackupNetapp Ontap Select Deploy Administration UtilityNetapp Solidfire & HCI Management Node | 9/12/2020 | 17/6/2026 | A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.35, in scan_unit_for_symbols, as demonstrated in addr2line, that can cause a denial of service via a crafted file. | |
| Modificada | Alta (7.8) | 1.1% | 💥 PoC | Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+8 | 9/12/2020 | 17/6/2026 | A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b. | |
| Modificada | Media (4.4) | 0.47% | — | Linux KernelFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+7 | 9/12/2020 | 17/6/2026 | A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24. | |
| Modificada | Media (5.9) | 7.1% | 💥 PoC | OpensslDebian LinuxFedoraproject FedoraOracle API Gateway+40 | 8/12/2020 | 17/6/2026 | The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both… | |
| Modificada | Alta (7.5) | 2.2% | — | OpenldapRedhat Enterprise LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller Firmware | 8/12/2020 | 17/6/2026 | A NULL pointer dereference was found in OpenLDAP server and was fixed in openldap 2.4.55, during a request for renaming RDNs. An unauthenticated attacker could remotely crash the slapd process by sending a specially crafted request, causing a Denial of Service. | |
| Modificada | Alta (7.5) | 2.7% | — | GNU GlibcRedhat Enterprise LinuxNetapp Cloud BackupNetapp Solidfire Baseboard Management Controller | 6/12/2020 | 17/6/2026 | sysdeps/i386/ldbl2mpn.c in the GNU C Library (aka glibc or libc6) before 2.23 on x86 targets has a stack-based buffer overflow if the input to any of the printf family of functions is an 80-bit long double with a non-canonical bit pattern, as seen when passing a \x00\x04\x00\x00\x00\x00\x00\x00\x00\x04 value to… | |
| Modificada | Alta (8.1) | 5.2% | — | Linux KernelNetapp Cloud BackupNetapp A250 FirmwareNetapp FAS 500f Firmware+2 | 2/12/2020 | 17/6/2026 | An out-of-bounds memory write flaw was found in how the Linux kernel’s Voice Over IP H.323 connection tracking functionality handled connections on ipv6 port 1720. This flaw allows an unauthenticated remote user to crash the system, causing a denial of service. The highest threat from this vulnerability is to… | |
| Modificada | Baja (3.6) | 0.41% | — | Linux KernelDebian LinuxNetapp 500f FirmwareNetapp A250 Firmware+4 | 28/11/2020 | 17/6/2026 | An issue was discovered in the Linux kernel before 5.7.3, related to mm/gup.c and mm/huge_memory.c. The get_user_pages (aka gup) implementation, when used for a copy-on-write page, does not properly consider the semantics of read operations and therefore can grant unintended write access, aka CID-17839856fd58. | |
| Modificada | Alta (7) | 0.61% | 💥 PoC | Linux KernelNetapp Cloud BackupNetapp Solidfire, Enterprise SDS & HCI Storage NodeNetapp Solidfire & HCI Management Node+3 | 28/11/2020 | 17/6/2026 | An issue was discovered in kmem_cache_alloc_bulk in mm/slub.c in the Linux kernel before 5.5.11. The slowpath lacks the required TID increment, aka CID-fd4d9c7d0c71. | |
| Modificada | Alta (7) | 0.46% | — | Linux KernelNetapp HCI Management NodeNetapp SolidfireNetapp HCI Compute Node+1 | 28/11/2020 | 17/6/2026 | An issue was discovered in mm/mmap.c in the Linux kernel before 5.7.11. There is a race condition between certain expand functions (expand_downwards and expand_upwards) and page-table free operations from an munmap call, aka CID-246c320a8cfe. | |
| Modificada | Alta (7) | 0.36% | — | Linux KernelNetapp Cloud BackupNetapp Element SoftwareNetapp HCI Management Node+3 | 28/11/2020 | 17/6/2026 | An issue was discovered in __split_huge_pmd in mm/huge_memory.c in the Linux kernel before 5.7.5. The copy-on-write implementation can grant unintended write access because of a race condition in a THP mapcount check, aka CID-c444eb564fb1. | |
| Modificada | Media (6.7) | 0.93% | 💥 PoC | Linux KernelBroadcom Brocade Fabric Operating System FirmwareNetapp Cloud BackupNetapp Solidfire & HCI Management Node+15 | 23/11/2020 | 17/6/2026 | Use-after-free vulnerability in fs/block_dev.c in the Linux kernel before 5.8 allows local users to gain privileges or cause a denial of service by leveraging improper access to a certain error field. | |
| Modificada | Media (6.7) | 0.42% | — | Intel BiosNetapp AFF BiosNetapp FAS BiosNetapp HCI Compute Node Bios+2 | 12/11/2020 | 17/6/2026 | Improper access control in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. |