Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3047▲ 440 respecto a la semana anterior
Críticas / altas1452▲ 212 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 151 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.40% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Alta (8.8) | 0.40% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Aplazada | Alta (8.8) | 0.40% | — | Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI | 15/2/2026 | 17/6/2026 | The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper… | |
| Modificada | Alta (7.5) | 1.1% | — | Bavarian Motor Works Bluetooth Stack | 23/5/2017 | 17/6/2026 | The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name. | |
| Modificada | Media (6.9) | 0.38% | — | Toshiba Bluetooth StackToshiba Service Station | 28/2/2015 | 17/6/2026 | Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character. | |
| Modificada | Alta (8.8) | 5.9% | — | Bluetooth StackMicrosoft Windows 7Microsoft Windows Vista | 13/7/2011 | 16/6/2026 | The Bluetooth Stack 2.1 in Microsoft Windows Vista SP1 and SP2 and Windows 7 Gold and SP1 does not prevent access to objects in memory that (1) were not properly initialized or (2) have been deleted, which allows remote attackers to execute arbitrary code via crafted Bluetooth packets, aka "Bluetooth Stack… | |
| Modificada | Alta (7.9) | 0.83% | — | Broadcom Bluetooth Stack | 31/12/2006 | 16/6/2026 | Unspecified vulnerability in the Broadcom Bluetooth stack allows remote attackers to gain administrative access (aka Remote Root) via unspecified vectors. | |
| Modificada | Alta (10) | 1.4% | — | Toshiba Bluetooth Stack | 31/10/2006 | 16/6/2026 | Unspecified vulnerability in Toshiba Bluetooth Stack before 4.20.01 has unspecified impact and attack vectors, related to the 4.20.01(T) "Security fix." NOTE: due to the lack of details in the vendor advisory, it is not clear whether this issue is related to CVE-2006-5405. | |
| Modificada | Media (5) | 2.5% | — | Toshiba Bluetooth Stack | 22/6/2006 | 16/6/2026 | The TOSRFBD.SYS driver for Toshiba Bluetooth Stack 4.00.29 and earlier on Windows allows remote attackers to cause a denial of service (reboot) via a L2CAP echo request that triggers an out-of-bounds memory access, similar to "Ping o' Death" and as demonstrated by BlueSmack. NOTE: this issue was originally reported… | |
| Modificada | Media (5) | 2.5% | — | Toshiba Bluetooth Stack | 14/1/2006 | 16/6/2026 | Directory traversal vulnerability in OBEX Push services in Toshiba Bluetooth Stack 4.00.23(T) and earlier allows remote attackers to upload arbitrary files to arbitrary remote locations specified by .. (dot dot) sequences, as demonstrated by ..\\ sequences in the RFILE argument of ussp-push. |