Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2533▼ 405 respecto a la semana anterior
Críticas / altas1319▲ 38 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.1)0.39%—Openbmc Phosphor-net-ipmidAINvidia IpmiAIH3C IpmiAI15/9/202618/9/2026
OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant…
Pendiente de análisisAlta (8.8)0.27%—Openbmc Phosphor-net-ipmidAINvidia IpmiAIH3C IpmiAI15/9/202618/9/2026
OpenBMC's IPMI implementation, phosphor-net-ipmid, is vulnerable to a logic flaw where the authorization context of an existing session can be replaced with a target account while still maintaining the original integrity and encryption keys. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack,…
AplazadaCrítica (9.8)0.40%—FreeipmiAI4/9/20268/9/2026
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC returns more bytes than requested.
AplazadaCrítica (9.8)0.40%—FreeipmiAI4/9/20268/9/2026
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).
Pendiente de análisisCrítica (9.8)0.40%—FreeipmiAI4/9/202614/9/2026
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ipmi-oem-dell.c (cmc-info subcommand to dell get-system-info).
Pendiente de análisisCrítica (9.8)0.40%—FreeipmiAI4/9/20269/9/2026
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
Pendiente de análisisAlta (7.5)0.35%—FreeipmiAI4/9/20269/9/2026
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has different affected versions).
AplazadaCrítica (9.8)0.40%—FreeipmiAI4/9/20268/9/2026
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.
Pendiente de análisisAlta (7.5)0.50%—FreeipmiAI3/6/202622/7/2026
ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most…
AplazadaAlta (7.5)0.40%—FreeipmiAI24/3/202617/6/2026
ipmi-oem in FreeIPMI before 1.6.17 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform management. It is implemented by a large number of hardware manufacturers to support system management. It is most…
ModificadaAlta (8.8)0.78%—Redhat SatelliteLogicminds Rubyipmi27/2/202617/6/2026
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution…
AplazadaMedia (5.4)0.27%—Ipmi Smash CLPAI18/11/202517/6/2026
Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a stack buffer overflow via a crafted SMASH command, overwrite the return address and registers, and achieve arbitrary code execution on the BMC firmware operating system
AplazadaMedia (5)0.39%—OpenipmiAI9/10/202417/6/2026
OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) authentication bypass or code execution.
AplazadaCrítica (9.1)0.72%—Intel IpmiAI30/4/202417/6/2026
Implementations of IPMI Authenticated sessions does not provide enough randomness to protect from session hijacking, allowing an attacker to use either predictable IPMI Session ID or weak BMC Random Number to bypass security controls using spoofed IPMI packets to manage BMC device.
ModificadaAlta (8.8)3.3%—Ipmitool Project IpmitoolDebian LinuxFedoraproject FedoraOpensuse Leap5/2/202017/6/2026
It's been found that multiple functions in ipmitool before 1.8.19 neglect proper checking of the data received from a remote LAN party, which may lead to buffer overflows and potentially to remote code execution on the ipmitool side. This is especially dangerous if ipmitool is run as a privileged user. This problem is…
ModificadaMedia (5)19%—Dell Idrac6 ModularDell Idrac7Intel IpmiDell Idrac6 Monolithic19/12/201417/6/2026
The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack.
ModificadaBaja (3.6)0.43%—Ipmitool Project Ipmitool15/12/201116/6/2026
ipmievd (aka the IPMI event daemon) in OpenIPMI, as used in the ipmitool package 1.8.11 in Red Hat Enterprise Linux (RHEL) 6, Debian GNU/Linux, Fedora 16, and other products uses 0666 permissions for its ipmievd.pid PID file, which allows local users to kill arbitrary processes by writing to this file.
ModificadaAlta (7.5)1.5%—Paul L Daniels Ripmime31/12/200416/6/2026
ripMIME 1.3.2.3 and earlier allows remote attackers to bypass e-mail protection via a base64 MIME encoded attachment containing invalid characters that are not properly extracted.
ModificadaMedia (5)0.87%—Paul L Daniels Ripmime31/12/200416/6/2026
The MIMEH_read_headers function in ripMIME 1.3.1.0 does not properly handle trailing "\r" and "\n" characters in headers, which leads to a buffer underflow.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard separator characters, or use standard separators incorrectly, within MIME headers, fields, parameters, or values, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME encapsulation that uses RFC822 comment fields, which may be interpreted as other fields by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use malformed quoting in MIME headers, parameters, and values, including (1) fields that should not be quoted, (2) duplicate quotes, or (3) missing leading or trailing quote characters,…
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use non-standard but frequently supported Content-Transfer-Encoding values such as (1) uuencode, (2) mac-binhex40, and (3) yenc, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use whitespace in an unusual fashion, which may be interpreted differently by mail clients.
ModificadaAlta (7.5)2.4%—Clearswift MailsweeperF-secure Internet GatekeeperPaul L Daniels Ripmime20/10/200416/6/2026
Multiple content security gateway and antivirus products allow remote attackers to bypass content restrictions via MIME messages that use RFC2231 encoding, which may be interpreted differently by mail clients.