Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2770▲ 14 respecto a la semana anterior
Críticas / altas1475▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 447 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.62% | — | HP 3par Service Processor Firmware | 16/7/2024 | 17/6/2026 | The vulnerability could be remotely exploited to bypass authentication. | |
| Modificada | Media (5.9) | 3.6% | — | GNU GlibcFedoraproject FedoraNetapp Ontap Select Deploy Administration UtilityNetapp Service Processor+4 | 4/1/2021 | 17/6/2026 | The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read. | |
| Analizada | Alta (7.8) | 72% | ⚠ Explotación activa | Google AndroidDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+73 | 11/10/2019 | 17/6/2026 | A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interaction is required to exploit this vulnerability, however exploitation does require either the installation of a malicious local application or a separate vulnerability in a network facing… | |
| Modificada | Alta (7.5) | 3.5% | — | Linux KernelOpensuse LeapNetapp AFF A700s FirmwareNetapp H300s Firmware+13 | 30/9/2019 | 17/6/2026 | In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize() in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial of service, aka CID-6caabe7f197d. | |
| Modificada | Alta (7.8) | 0.91% | — | Linux KernelRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux Compute Node EUS+35 | 20/9/2019 | 17/6/2026 | There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.87% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR Real Time+30 | 20/9/2019 | 17/6/2026 | There is heap-based buffer overflow in Linux kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.62% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+30 | 17/9/2019 | 17/6/2026 | A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x, in the way Linux kernel's vhost functionality that translates virtqueue buffers to IOVs, logged the buffer descriptors during migration. A privileged guest user able to pass descriptors with invalid length to the host when migration is underway, could… | |
| Modificada | Media (5.6) | 0.61% | — | Linux KernelNetapp Active IQ Performance Analytics ServicesNetapp Service ProcessorDebian Linux+2 | 4/9/2019 | 17/6/2026 | A backporting error was discovered in the Linux stable/longterm kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141, 4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace: Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre… | |
| Modificada | Media (6.3) | 0.89% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote session reuse vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Modificada | Crítica (9.4) | 2.4% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote gain authorized access vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Modificada | Media (5.4) | 0.71% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote multiple multiple cross-site vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Modificada | Crítica (9.4) | 4.3% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote bypass of security restrictions vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Modificada | Crítica (9.4) | 5.1% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote authentication bypass vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Modificada | Alta (8.8) | 2.3% | — | HP 3par Service Processor Firmware | 9/8/2019 | 17/6/2026 | A remote arbitrary file upload vulnerability was discovered in HPE 3PAR Service Processor version(s): prior to 5.0.5.1. | |
| Analizada | Alta (7.8) | 52% | ⚠ Explotación activa | Linux KernelDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+18 | 17/7/2019 | 17/6/2026 | In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges… | |
| Modificada | Crítica (9.8) | 4.7% | — | HP 3par Service Processor Firmware | 9/7/2019 | 17/6/2026 | HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4. HPE 3PAR Service Processor (SP) version 4.1 through 4.4 has a remote information disclosure vulnerability which can allow for the disruption of the confidentiality, integrity and availability of the Service Processor and any… | |
| Modificada | Crítica (9.8) | 3.5% | — | Netapp Service Processor | 21/3/2019 | 17/6/2026 | Certain versions between 2.x to 5.x (refer to advisory) of the NetApp Service Processor firmware were shipped with a default account enabled that could allow unauthorized arbitrary command execution. Any platform listed in the advisory Impact section may be affected and should be upgraded to a fixed version of Service… | |
| Modificada | Media (5.9) | 17% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+78 | 27/2/2019 | 17/6/2026 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid… | |
| Modificada | Media (5.3) | 99% | — | Openbsd OpensshDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+18 | 17/8/2018 | 17/6/2026 | OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c. | |
| Modificada | Alta (7.5) | 16% | — | Openbsd OpensshDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+8 | 21/1/2018 | 17/6/2026 | sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c. | |
| Modificada | Alta (7.5) | 40% | — | OpensslDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+41 | 13/11/2017 | 17/6/2026 | A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections… | |
| Modificada | Media (4) | 1.2% | — | HP 3par Service Processor SP | 12/10/2015 | 17/6/2026 | HP 3PAR Service Processor SP 4.2.0.GA-29 (GA) SPOCC, SP 4.3.0.GA-17 (GA) SPOCC, and SP 4.3.0-GA-24 (MU1) SPOCC allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6.5) | 2.7% | — | Linux-pamOracle Sparc-opl Service Processor | 24/8/2015 | 17/6/2026 | The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password. | |
| Modificada | Alta (7.5) | 74% | — | OpensslOracle Sparc-opl Service Processor | 12/6/2015 | 17/6/2026 | The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted length field in ASN1_TIME data, as demonstrated by an attack… | |
| Modificada | Baja (3.7) | 100% | — | OpensslCanonical Ubuntu LinuxHp-uxIBM Content Manager+21 | 21/5/2015 | 17/6/2026 | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a… |