Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.6% | — | Redhat Gluster StorageRedhat Enterprise Linux ServerRedhat Enterprise Linux VirtualizationRedhat Virtualization+2 | 31/10/2018 | 17/6/2026 | The Gluster file system through version 4.1.4 is vulnerable to abuse of the 'features/index' translator. A remote attacker with access to mount volumes could exploit this via the 'GF_XATTROP_ENTRY_IN_KEY' xattrop to create arbitrary, empty files on the target server. | |
| Modificada | Alta (8.8) | 2.8% | — | Redhat Gluster StorageDebian LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Virtualization | 31/10/2018 | 17/6/2026 | The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the '__server_getspec' function via the 'gf_getspec_req' RPC message. A remote authenticated attacker could exploit this to cause a denial of service or other potential unspecified impact. | |
| Modificada | Media (6.5) | 2.7% | — | Redhat Gluster StorageDebian LinuxRedhat Enterprise Virtualization HostRedhat Enterprise Linux Server+1 | 31/10/2018 | 17/6/2026 | The Gluster file system through versions 3.12 and 4.1.4 is vulnerable to a buffer overflow in the 'features/index' translator via the code handling the 'GF_XATTR_CLRLK_CMD' xattr in the 'pl_getxattr' function. A remote authenticated attacker could exploit this on a mounted volume to cause a denial of service. | |
| Modificada | Alta (7.8) | 0.76% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+7 | 15/5/2018 | 17/6/2026 | kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS or Pop SS instructions. During the stack switch operation, the… |