Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2534▼ 359 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.1)0.65%—Phoenixcontact Rad-ism-900-en-bd FirmwarePhoenixcontact Rad-ism-900-en-bd/b FirmwarePhoenixcontact Rad-ism-900-en-bd-bus Firmware11/5/202217/6/2026
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.
ModificadaCrítica (9.1)1.4%—Phoenixcontact Rad-ism-900-en-bd FirmwarePhoenixcontact Rad-ism-900-en-bd/b FirmwarePhoenixcontact Rad-ism-900-en-bd-bus Firmware11/5/202217/6/2026
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware.
ModificadaBaja (1.9)0.51%—D-bus Project D-busFreedesktop DbusOpensuse25/10/201417/6/2026
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the…
ModificadaBaja (2.1)0.40%—OpensuseD-bus Project D-busFreedesktop Dbus22/9/201417/6/2026
The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection consumption and prevention of new connections) via a large number of incomplete connections.
ModificadaBaja (2.1)0.39%—D-bus Project D-busFreedesktop DbusOpensuse22/9/201417/6/2026
The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a large number of method calls.
ModificadaMedia (4.4)0.49%—D-bus Project D-busFreedesktop DbusOpensuse22/9/201417/6/2026
Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one more file descriptor than…
ModificadaMedia (4)0.44%—D-bus Project D-busFreedesktop Dbus1/7/201417/6/2026
The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct…
ModificadaMedia (4.6)0.39%—Freedesktop DbusD-bus Project D-bus22/6/201116/6/2026
The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-native byte order, which allows local users to cause a denial of service (connection loss), obtain potentially sensitive information, or…
ModificadaBaja (2.1)0.58%—D-bus Project D-bus30/12/201016/6/2026
Stack consumption vulnerability in D-Bus (aka DBus) before 1.4.1 allows local users to cause a denial of service (daemon crash) via a message containing many nested variants.
ModificadaBaja (1.7)0.38%—D-bus14/12/200616/6/2026
Unspecified vulnerability in the match_rule_equal function in bus/signals.c in D-Bus before 1.0.2 allows local applications to remove match rules for other applications and cause a denial of service (lost process messages).
ModificadaBaja (2.1)0.43%—D-bus29/6/200516/6/2026
D-BUS (dbus) before 0.22 does not properly restrict access to a socket, if the socket address is known, which allows local users to listen or send arbitrary messages on another user's per-user session bus via that socket.