Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.19% | — | CorosyncAI | 4/9/2026 | 8/9/2026 | An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems due to an integer overflow in the calculation of the expected message length, allowing a crafted network packet to trigger an out-of-bounds memory… | |
| Pendiente de análisis | Alta (7.5) | 0.35% | — | CorosyncAI | 4/9/2026 | 30/9/2026 | A heap-based buffer overflow was found in Corosync's Totem Process Group (totempg) message reassembly. When processing fragmented multicast messages, the buffer used to reassemble fragments lacks a runtime bounds check in release builds. A network-adjacent attacker able to send crafted multicast protocol messages to… | |
| Modificada | Alta (7.5) | 1.3% | — | CorosyncRedhat OpenshiftRedhat Enterprise Linux | 1/4/2026 | 21/8/2026 | A flaw was found in Corosync. An integer overflow vulnerability in Corosync's join message sanity validation allows a remote, unauthenticated attacker to send crafted User Datagram Protocol (UDP) packets. This can cause the service to crash, leading to a denial of service. This vulnerability specifically affects… | |
| Modificada | Alta (8.2) | 1.1% | — | CorosyncRedhat OpenshiftRedhat Enterprise Linux | 1/4/2026 | 21/8/2026 | A flaw was found in Corosync. A remote unauthenticated attacker can exploit a wrong return value vulnerability in the Corosync membership commit token sanity check by sending a specially crafted User Datagram Protocol (UDP) packet. This can lead to an out-of-bounds read, causing a denial of service (DoS) and… | |
| Modificada | Crítica (9.8) | 0.46% | — | Corosync | 22/3/2025 | 17/6/2026 | Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer overflow in orf_token_endian_convert in exec/totemsrp.c via a large UDP packet. | |
| Modificada | Alta (7.5) | 3.1% | — | CorosyncDebian LinuxRedhat Enterprise Linux ServerCanonical Ubuntu Linux | 12/4/2018 | 17/6/2026 | corosync before version 2.4.4 is vulnerable to an integer overflow in exec/totemcrypto.c. | |
| Modificada | Alta (8.5) | 2.5% | — | Pacemaker/corosync Configuration System Project Pacemaker/corosync Configuration System | 3/9/2015 | 17/6/2026 | The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL. | |
| Modificada | Media (4.9) | 0.98% | — | Pacemaker/corosync Configuration System Project Pacemaker/corosync Configuration System | 3/9/2015 | 17/6/2026 | Race condition in pcsd in PCS 0.9.139 and earlier uses a global variable to validate usernames, which allows remote authenticated users to gain privileges by sending a command that is checked for security after another user is authenticated. | |
| Modificada | Media (5) | 3.1% | — | Corosync | 6/6/2014 | 16/6/2026 | The init_nss_hash function in exec/totemcrypto.c in Corosync 2.0 before 2.3 does not properly initialize the HMAC key, which allows remote attackers to cause a denial of service (crash) via a crafted packet. |