Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Gnome KeyringDebian Linux20/12/201916/6/2026
gnome-keyring does not discard stored secrets when using gnome_keyring_lock_all_sync function
ModificadaMedia (6.2)0.44%—Python Keyring25/11/201916/6/2026
Python keyring has insecure permissions on new databases allowing world-readable files to be created
ModificadaAlta (7.5)1.8%—Python KeyringDebian Linux28/10/201916/6/2026
Python keyring lib before 0.10 created keyring files with world-readable permissions.
ModificadaAlta (7.8)1.5%—Gnome KeyringCanonical Ubuntu LinuxOracle ZFS Storage Appliance KIT12/2/201917/6/2026
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned from the LightDM daemon. This can expose the credential in cleartext.
ModificadaAlta (7.8)0.56%—Gnome-keyring18/11/201817/6/2026
GNOME Keyring through 3.28.2 allows local users to retrieve login credentials via a Secret Service API call and the D-Bus interface if the keyring is unlocked, a similar issue to CVE-2008-7320. One perspective is that this occurs because available D-Bus protection mechanisms (involving the busconfig and policy XML…
ModificadaBaja (2.1)0.37%—Python Keyring30/11/201216/6/2026
Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack.
ModificadaMedia (4.4)0.48%—Gnome-keyring22/10/201216/6/2026
GNOME gnome-keyring 3.4.0 through 3.4.1, when gpg-cache-method is set to "idle" or "timeout," does not properly limit the amount of time a passphrase is cached, which allows attackers to have an unspecified impact via unknown attack vectors.