Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3072▲ 552 respecto a la semana anterior
Críticas / altas1458▲ 273 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.19%—Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux13/6/202621/9/2026
A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to files in the dump directory without sanitizing embedded control characters. A local user can inject…
ModificadaAlta (7.8)0.23%—Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux13/6/202621/9/2026
A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the…
ModificadaAlta (7.5)1.6%—Redhat Automatic BUG Reporting ToolFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+131/1/202026/8/2026
ABRT might allow attackers to obtain sensitive information from crash reports.
ModificadaAlta (7.8)0.39%—Redhat Automatic BUG Reporting Tool14/1/202017/6/2026
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) does not properly handle the process environment before invoking abrt-action-install-debuginfo, which allows local users to gain privileges.
ModificadaAlta (7.8)0.56%—Redhat Automatic BUG Reporting Tool14/1/202017/6/2026
Directory traversal vulnerability in abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to read, write to, or change ownership of arbitrary files via unspecified vectors to the (1) NewProblem, (2) GetInfo, (3) SetElement, or (4) DeleteElement method.
ModificadaAlta (7.1)0.40%—Redhat Automatic BUG Reporting Tool14/1/202017/6/2026
abrt-dbus in Automatic Bug Reporting Tool (ABRT) allows local users to delete or change the ownership of arbitrary files via the problem directory argument to the (1) ChownProblemDir, (2) DeleteElement, or (3) DeleteProblem method.
ModificadaMedia (6.5)1.1%—Redhat Automatic BUG Reporting ToolRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+314/1/202017/6/2026
daemon/abrt-handle-upload.in in Automatic Bug Reporting Tool (ABRT), when moving problem reports from /var/spool/abrt-upload, allows local users to write to arbitrary files or possibly have other unspecified impact via a symlink attack on (1) /var/spool/abrt or (2) /var/tmp/abrt.
ModificadaAlta (7.8)0.41%—Redhat Automatic BUG Reporting Tool14/1/202017/6/2026
The default event handling scripts in Automatic Bug Reporting Tool (ABRT) allow local users to gain privileges as demonstrated by a symlink attack on a var_log_messages file.
ModificadaBaja (3.3)0.31%—Redhat Automatic BUG Reporting Tool1/5/201816/6/2026
Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary files via vectors related to sha1sums.
ModificadaAlta (7)3.0%—Redhat Automatic BUG Reporting Tool9/2/201826/8/2026
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot into a user-specified directory in a namedspaced environment.
ModificadaAlta (7.8)4.8%—Redhat Automatic BUG Reporting Tool26/6/201717/6/2026
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impact on arbitrary files via a symlink attack on (1) /var/tmp/abrt/*/maps, (2) /tmp/jvm-*/hs_error.log, (3) /proc/*/exe, (4) /etc/os-release in a chroot, or (5) an unspecified root directory related to…
ModificadaMedia (4.7)0.34%—Redhat Automatic BUG Reporting Tool26/6/201717/6/2026
The kernel-invoked coredump processor in Automatic Bug Reporting Tool (ABRT) does not properly check the ownership of files before writing core dumps to them, which allows local users to obtain sensitive information by leveraging write permissions to the working directory of a crashed application.
ModificadaMedia (5.5)0.42%—Redhat Automatic BUG Reporting Tool26/6/201717/6/2026
The event scripts in Automatic Bug Reporting Tool (ABRT) uses world-readable permission on a copy of sosreport file in problem directories, which allows local users to obtain sensitive information from /var/log/messages via unspecified vectors.
AnalizadaAlta (7.8)5.0%⚠ Explotación activaRedhat Automatic BUG Reporting ToolOracle LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+37/12/201527/8/2026
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name, as demonstrated by /var/tmp/abrt/abrt-hax-coredump or /var/spool/abrt/abrt-hax-coredump.
ModificadaBaja (3.6)0.90%—Redhat Automatic BUG Reporting ToolRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+17/12/201517/6/2026
The abrt-action-install-debuginfo-to-abrt-cache help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users to write to arbitrary files via a symlink attack on unpacked.cpio in a pre-created directory with a predictable name in /var/tmp.
ModificadaMedia (6.9)0.31%—Redhat Automatic BUG Reporting Tool12/3/201316/6/2026
abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."
ModificadaBaja (3.7)0.45%—Redhat Automatic BUG Reporting Tool12/3/201316/6/2026
Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module.
ModificadaBaja (1.9)0.44%—Redhat Automatic BUG Reporting Tool3/7/201216/6/2026
The C handler plug-in in Automatic Bug Reporting Tool (ABRT), possibly 2.0.8 and earlier, does not properly set the group (GID) permissions on core dump files for setuid programs when the sysctl fs.suid_dumpable option is set to 2, which allows local users to obtain sensitive information.