Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 319 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

26 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.3)0.26%—Openeuler GiflibAIGiflibAI14/4/202517/6/2026
Heap-based Buffer Overflow vulnerability in openEuler giflib on Linux. This vulnerability is associated with program files gif2rgb.C. This issue affects giflib: through 5.2.2.
AplazadaMedia (6)0.22%—Openeuler KernelAI15/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C. This issue affects kernel: from…
AplazadaMedia (6)0.22%—Openeuler KernelAI15/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in openEuler kernel on Linux allows Resource Leak Exposure. This vulnerability is associated with program files https://gitee.Com/openeuler/kernel/blob/openEuler-1.0-LTS/drivers/staging/gmjstcm/tcm.C. This issue affects kernel: from…
AplazadaAlta (7.2)1.7%—Openeuler Aops-zeusAI25/3/202417/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-zeus on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/aops-zeus/blob/master/zeus/conf/constant.Py. This issue affects aops-zeus:…
AplazadaAlta (8.1)1.4%—Openeuler A-tune-collectorAI25/3/202417/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Collector on Linux allows Command Injection. This vulnerability is associated with program files…
AplazadaAlta (8.1)0.92%—Openeuler Migration-toolsAI25/3/202417/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Privilege Management vulnerability in openEuler migration-tools on Linux allows Command Injection, Restful Privilege Elevation. This vulnerability is associated with program files…
AplazadaAlta (7.8)1.1%—Openeuler Gala-gopherAI25/3/202417/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler gala-gopher on Linux allows Command Injection. This vulnerability is associated with program files…
AplazadaAlta (7)0.15%—Openeuler IsuladAI25/3/202417/6/2026
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in openEuler iSulad on Linux allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions. This vulnerability is associated with program files https://gitee.Com/openeuler/iSulad/blob/master/src/cmd/isulad/main.C. This issue affects iSulad:…
AplazadaAlta (7.3)0.78%—Openeuler Aops-ceresAI23/3/202417/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-ceres on Linux allows Command Injection. This vulnerability is associated with program files ceres/function/util.Py. This issue affects aops-ceres: from 1.3.0 through 1.4.1.
ModificadaAlta (7.8)0.37%—Openatom Openeuler18/1/202417/6/2026
Integer Overflow or Wraparound vulnerability in openEuler kernel on Linux (filesystem modules) allows Forced Integer Overflow.This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3, from 5.10.0-60.18.0 before 5.10.0-183.0.0.
ModificadaMedia (5.5)0.34%—Openatom Openeuler18/1/202417/6/2026
NULL Pointer Dereference vulnerability in openEuler kernel on Linux (network modules) allows Pointer Manipulation. This vulnerability is associated with program files net/sched/sch_cbs.C. This issue affects openEuler kernel: from 4.19.90 before 4.19.90-2401.3.
ModificadaMedia (6.5)0.21%—Openeuler Isula29/10/202317/6/2026
When the isula cp command is used to copy files from a container to a host machine and the container is controlled by an attacker, the attacker can escape the container.
ModificadaMedia (6.5)0.21%—Openeuler Isula29/10/202317/6/2026
When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container.
ModificadaAlta (7.8)0.25%—Openeuler Isula29/10/202317/6/2026
When the isula load command is used to load malicious images, attackers can execute arbitrary code.
ModificadaAlta (7.8)0.55%—Openeuler Isula29/10/202317/6/2026
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
ModificadaMedia (5.5)0.21%—Openeuler ICR29/10/202317/6/2026
iSulad uses the lcr+lxc runtime (default) to run malicious images, which can cause DOS.
ModificadaAlta (7.5)0.49%—Openatom Openeuler Kernel8/3/202317/6/2026
REMAP cmd of SVM driver can be used to remap read only memory as read-write, then cause read only memory/file modified.
ModificadaMedia (5.5)0.22%—Openeuler Byacc20/1/202317/6/2026
When a file is processed, an infinite loop occurs in next_inline() of the more_curly() function.
ModificadaAlta (7.8)0.27%—Openeuler Byacc20/1/202317/6/2026
When processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memory (use after free).
ModificadaCrítica (9.8)0.67%—Openatom OpeneulerFedoraproject Fedora19/12/202217/6/2026
After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).
ModificadaAlta (7.5)1.9%—Feep LibtarOpenatom OpeneulerFedoraproject Fedora10/8/202217/6/2026
The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.
ModificadaAlta (7.5)1.9%—Feep LibtarOpenatom OpeneulerFedoraproject Fedora10/8/202217/6/2026
The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.
ModificadaAlta (8.1)1.5%—Feep LibtarOpenatom OpeneulerFedoraproject Fedora10/8/202217/6/2026
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read.
ModificadaCrítica (9.1)1.8%—Feep LibtarOpenatom OpeneulerFedoraproject Fedora10/8/202223/6/2026
An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read.
ModificadaMedia (6.8)0.61%—Openatom OpeneulerLinux KernelDebian Linux18/7/202217/6/2026
When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.