Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
–

296 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.41%—HPE Hp-uxAINfsv4AI9/9/202417/6/2026
HPE has identified a denial of service vulnerability in HPE HP-UX System's Network File System (NFSv4) services.
ModificadaMedia (5.5)0.18%—Hp-ux16/6/202317/6/2026
HP-UX could be exploited locally to create a Denial of Service (DoS) when any physical interface is configured with IPv6/inet6.
ModificadaBaja (3.3)0.26%—Hp-ux Directory ServerRedhat Directory ServerFedoraproject 389 Directory ServerRedhat Directory Server9/1/202016/6/2026
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by…
ModificadaAlta (7.5)60%—ISC BindRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+716/1/201917/6/2026
"deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an…
ModificadaAlta (7.5)89%—Oracle LinuxOracle VM ServerISC BindHp-ux+128/9/201617/6/2026
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly construct responses, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted query.
ModificadaMedia (5.9)63%—Hp-uxISC BindFedoraproject FedoraRedhat Enterprise Linux Desktop+519/7/201617/6/2026
ISC BIND 9.x before 9.9.9-P2, 9.10.x before 9.10.4-P2, and 9.11.x before 9.11.0b2, when lwresd or the named lwres option is enabled, allows remote attackers to cause a denial of service (daemon crash) via a long request that uses the lightweight resolver protocol.
ModificadaMedia (5.9)1.9%—Hp-ux Ipfilter18/2/201617/6/2026
HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.
ModificadaAlta (7.2)0.56%—Hp-ux6/7/201517/6/2026
Unspecified vulnerability in pppoec in HP HP-UX 11iv2 and 11iv3 allows local users to gain privileges by leveraging setuid permissions.
ModificadaBaja (3.7)100%—OpensslCanonical Ubuntu LinuxHp-uxIBM Content Manager+2121/5/201517/6/2026
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a…
ModificadaAlta (8.5)4.7%—Hp-ux10/12/201417/6/2026
HP HP-UX B.11.11, B.11.23, and B.11.31, when the PAM configuration includes libpam_updbe, allows remote authenticated users to bypass authentication, and consequently execute arbitrary code, via unspecified vectors.
ModificadaMedia (4.9)0.61%—Hp-ux30/10/201417/6/2026
Unspecified vulnerability in the kernel in HP HP-UX B.11.31 allows local users to cause a denial of service via unknown vectors.
ModificadaMedia (6.8)1.6%—HP System Management HomepageHp-ux19/10/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaAlta (9.3)6.1%—Hp-uxDebian LinuxOracle JDKOracle JRE17/7/201417/6/2026
Unspecified vulnerability in the Java SE component in Oracle Java SE 7u60 and SE 8u5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
ModificadaBaja (3.8)0.26%—Hp-ux Whitelisting19/4/201417/6/2026
Unspecified vulnerability in HP HP-UX Whitelisting (aka WLI) before A.01.02.02 on HP-UX B.11.31 allows local users to bypass intended access restrictions via unknown vectors.
ModificadaMedia (4.3)2.7%—Hp-ux14/3/201417/6/2026
Unspecified vulnerability in rpc.lockd in the NFS subsystem in HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service via unknown vectors.
ModificadaMedia (6.2)0.36%—Hp-ux11/3/201417/6/2026
Unspecified vulnerability in m4 in HP HP-UX B.11.23 and B.11.31 allows local users to obtain sensitive information or modify data via unknown vectors.
ModificadaAlta (7.8)34%—ISC BindSuse Linux Enterprise Software Development KITNovell Suse LinuxISC Dnsco Bind+829/7/201316/6/2026
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA…
AnalizadaCrítica (9.8)100%⚠ Explotación activaPHPFedoraproject FedoraDebian LinuxHp-ux+1311/5/201216/6/2026
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of…
ModificadaAlta (10)7.4%—HP Distributed Computing EnvironmentHp-ux5/4/201216/6/2026
Distributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
ModificadaMedia (5.8)1.8%—Hp-ux28/3/201216/6/2026
Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.11 and 11.23 allows remote attackers to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0125.
ModificadaBaja (3.3)0.44%—Hp-ux28/3/201216/6/2026
Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.31 allows local users to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0126.
ModificadaMedia (6.8)0.33%—Hp-ux Containers4/11/201116/6/2026
Unspecified vulnerability in HP-UX Containers (formerly HP-UX Secure Resource Partitions (SRP)) A.03.00, A.03.00.002, and A.03.01, when running with patch PHKL_42310, allows local users to gain privileges via unknown vectors.
ModificadaMedia (6.8)0.31%—Hp-ux11/7/201116/6/2026
Unspecified vulnerability in the dynamic loader in HP HP-UX B.11.11, B.11.23, and B.11.31 allows local users to gain privileges or cause a denial of service via unknown vectors.
ModificadaMedia (6.8)2.9%—HP Nfs/oncplusHp-ux15/4/201116/6/2026
Unspecified vulnerability in HP NFS/ONCplus B.11.31.10 and earlier on HP-UX B.11.31 allows remote authenticated users to cause a denial of service via unknown vectors.
ModificadaMedia (4.4)0.28%—Hp-ux4/4/201116/6/2026
Unspecified vulnerability in the OS-Core.CORE2-KRN fileset in HP HP-UX B.11.23 and B.11.31 allows local users to cause a denial of service via unknown vectors.