Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.0% | — | Nettle Project Nettle | 25/6/2023 | 17/6/2026 | The OCB feature in libnettle in Nettle 3.9 before 3.9.1 allows memory corruption. | |
| Modificada | Alta (7.5) | 2.7% | — | Nettle Project NettleRedhat Enterprise LinuxDebian LinuxNetapp Ontap Select Deploy Administration Utility | 5/8/2021 | 17/6/2026 | A flaw was found in the way nettle's RSA decryption functions handled specially crafted ciphertext. An attacker could use this flaw to provide a manipulated ciphertext leading to application crash and denial of service. | |
| Modificada | Alta (8.1) | 1.7% | — | Nettle Project NettleFedoraproject FedoraRedhat Enterprise LinuxNetapp Active IQ Unified Manager+2 | 5/4/2021 | 17/6/2026 | A flaw was found in Nettle in versions before 3.7.2, where several Nettle signature verification functions (GOST DSA, EDDSA & ECDSA) result in the Elliptic Curve Cryptography point (ECC) multiply function being called with out-of-range scalers, possibly resulting in incorrect results. This flaw allows an attacker to… | |
| Modificada | Media (5.7) | 1.5% | — | Nettle Project Nettle | 3/12/2018 | 17/6/2026 | A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle handles endian conversion of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run a process on the same physical core as the victim process, could use this flaw extract plaintext or in some cases downgrade any TLS… | |
| Modificada | Alta (7.5) | 5.0% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+2 | 14/4/2017 | 17/6/2026 | The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys via a cache side channel attack. | |
| Modificada | Crítica (9.8) | 2.8% | — | Nettle Project NettleCanonical Ubuntu LinuxOpensuse LeapOpensuse | 23/2/2016 | 17/6/2026 | The ecc_256_modq function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8803. | |
| Modificada | Crítica (9.8) | 3.9% | — | Nettle Project NettleCanonical Ubuntu LinuxOpensuse LeapOpensuse | 23/2/2016 | 17/6/2026 | x86_64/ecc-384-modp.asm in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-384 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors. | |
| Modificada | Crítica (9.8) | 4.2% | — | Nettle Project NettleCanonical Ubuntu LinuxOpensuse LeapOpensuse | 23/2/2016 | 17/6/2026 | The ecc_256_modp function in ecc-256.c in Nettle before 3.2 does not properly handle carry propagation and produces incorrect output in its implementation of the P-256 NIST elliptic curve, which allows attackers to have unspecified impact via unknown vectors, a different vulnerability than CVE-2015-8805. |