Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 319 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
26 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.26% | — | Openeuler GiflibAIGiflibAI | 14/4/2025 | 17/6/2026 | Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2rgb.C. This issue affects giflib: through 5.2.2. | |
| Aplazada | Media (6) | 0.22% | — | Openeuler KernelAI | 15/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C. This issue affects kernel: from… | |
| Aplazada | Media (6) | 0.22% | — | Openeuler KernelAI | 15/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C. This issue affects kernel: from… | |
| Aplazada | Alta (7.2) | 1.7% | — | Openeuler Aops-zeusAI | 25/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-zeus on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/aops-zeus/blob/master/zeus/conf/constant.Py. This issue affects aops-zeus:… | |
| Aplazada | Alta (8.1) | 1.4% | — | Openeuler A-tune-collectorAI | 25/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Collector on Linux allows Command Injection. This vulnerability is associated with program files… | |
| Aplazada | Alta (8.1) | 0.92% | — | Openeuler Migration-toolsAI | 25/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Management vulnerability in openEuler migration-tools on Linux allows Command Injection, Restful Privilege Elevation. This vulnerability is associated with program files… | |
| Aplazada | Alta (7.8) | 1.1% | — | Openeuler Gala-gopherAI | 25/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler gala-gopher on Linux allows Command Injection. This vulnerability is associated with program files… | |
| Aplazada | Alta (7) | 0.15% | — | Openeuler IsuladAI | 25/3/2024 | 17/6/2026 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnerability is associated with program files https://gitee.Com/openeuler/iSulad/blob/master/src/cmd/isulad/main.C. This issue affects iSulad:… | |
| Aplazada | Alta (7.3) | 0.78% | — | Openeuler Aops-ceresAI | 23/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-ceres on Linux allows Command Injection. This vulnerability is associated with program files ceres/function/util.Py. This issue affects aops-ceres: from 1.3.0 through 1.4.1. | |
| Modificada | Alta (7.8) | 0.37% | — | Openatom Openeuler | 18/1/2024 | 17/6/2026 | Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0. | |
| Modificada | Media (5.5) | 0.34% | — | Openatom Openeuler | 18/1/2024 | 17/6/2026 | NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3. | |
| Modificada | Media (6.5) | 0.21% | — | Openeuler Isula | 29/10/2023 | 17/6/2026 | When the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, the attacker can escape the container. | |
| Modificada | Media (6.5) | 0.21% | — | Openeuler Isula | 29/10/2023 | 17/6/2026 | When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container. | |
| Modificada | Alta (7.8) | 0.25% | — | Openeuler Isula | 29/10/2023 | 17/6/2026 | When the isula load command is used to load malicious images, attackers can execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.55% | — | Openeuler Isula | 29/10/2023 | 17/6/2026 | When malicious images are pulled by isula pull, attackers can execute arbitrary code. | |
| Modificada | Media (5.5) | 0.21% | — | Openeuler ICR | 29/10/2023 | 17/6/2026 | iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS. | |
| Modificada | Alta (7.5) | 0.49% | — | Openatom Openeuler Kernel | 8/3/2023 | 17/6/2026 | REMAP cmd of SVM driver can be used to remap read only memory as read-write, then cause read only memory/file modified. | |
| Modificada | Media (5.5) | 0.22% | — | Openeuler Byacc | 20/1/2023 | 17/6/2026 | When a file is processed, an infinite loop occurs in next_inline() of the more_curly() function. | |
| Modificada | Alta (7.8) | 0.27% | — | Openeuler Byacc | 20/1/2023 | 17/6/2026 | When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free). | |
| Modificada | Crítica (9.8) | 0.67% | — | Openatom OpeneulerFedoraproject Fedora | 19/12/2022 | 17/6/2026 | After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free). | |
| Modificada | Alta (7.5) | 1.9% | — | Feep LibtarOpenatom OpeneulerFedoraproject Fedora | 10/8/2022 | 17/6/2026 | The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak. | |
| Modificada | Alta (7.5) | 1.9% | — | Feep LibtarOpenatom OpeneulerFedoraproject Fedora | 10/8/2022 | 17/6/2026 | The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak. | |
| Modificada | Alta (8.1) | 1.5% | — | Feep LibtarOpenatom OpeneulerFedoraproject Fedora | 10/8/2022 | 17/6/2026 | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read. | |
| Modificada | Crítica (9.1) | 1.8% | — | Feep LibtarOpenatom OpeneulerFedoraproject Fedora | 10/8/2022 | 23/6/2026 | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read. | |
| Modificada | Media (6.8) | 0.61% | — | Openatom OpeneulerLinux KernelDebian Linux | 18/7/2022 | 17/6/2026 | When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds. |