Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.48% | — | Nbdkit Project Nbdkit | 9/6/2025 | 30/6/2026 | A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data range, exceeding a certain limit, it causes an internal error in the nbdkit, leading to a denial of service. | |
| Modificada | Media (6.5) | 0.45% | — | Nbdkit Project NbdkitRedhat Enterprise LinuxRedhat Enterprise Linux Advanced Virtualization | 9/6/2025 | 30/6/2026 | There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, and a plugin responds with an even larger single block, the nbdkit server can encounter a critical internal error, leading to a… | |
| Modificada | Baja (3.1) | 0.58% | — | Nbdkit Project NbdkitRedhat Enterprise Linux | 2/3/2022 | 17/6/2026 | A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session.… | |
| Modificada | Media (6.5) | 0.99% | — | Nbdkit Project Nbdkit | 18/3/2021 | 17/6/2026 | A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1. | |
| Modificada | Baja (3.7) | 1.6% | — | Nbdkit Project NbdkitRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux Server | 18/3/2021 | 17/6/2026 | A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and… |