Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.19% | — | Vserver V-serverAIVserver V-server LiteAI | 28/11/2024 | 17/6/2026 | There is an Out-of-bounds read vulnerability in V-Server (v4.0.19.0 and earlier) and V-Server Lite (v4.0.19.0 and earlier). If a user opens a specially crafted file, information may be disclosed and/or arbitrary code may be executed. | |
| Modificada | Crítica (9.8) | 1.8% | — | Linux-vserver | 6/11/2019 | 16/6/2026 | linux vserver 2.6 before 2.6.17 suffers from privilege escalation in remount code. | |
| Modificada | Baja (2.1) | 0.47% | — | Virtual Private Server Vserver | 1/5/2006 | 16/6/2026 | Virtual Private Server (Vserver) 2.0.x before 2.0.2-rc18 and 2.1.x before 2.1.1-rc18 provides certain context capabilities (ccaps) that allow local guest users to perform operations that were only intended to be allowed by the guest-root. | |
| Modificada | Alta (7.2) | 0.36% | — | Util-vserver | 6/4/2006 | 16/6/2026 | vserver in util-vserver 0.30.209 executes a command as root when the suexec userid parameter is invalid and non-numeric, which might cause local users to inadvertently execute dangerous commands as root. | |
| Modificada | Alta (7.5) | 1.8% | — | Util-vserver | 31/12/2005 | 16/6/2026 | util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to conduct unauthorized activities. | |
| Modificada | Media (5) | 2.1% | — | Debian Kernel-patch-vserverDebian Linux | 31/12/2005 | 16/6/2026 | The Linux 2.4 kernel patch in kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux does not correctly set the "chroot barrier" with util-vserver, which allows attackers to access files on the host system that are outside of the vserver. | |
| Modificada | Media (6.2) | 0.36% | — | Linux NetkitLinux-vserverLinux Kernel | 7/3/2005 | 16/6/2026 | Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores. | |
| Modificada | Baja (3.6) | 0.37% | — | Linux-vserver | 31/12/2004 | 16/6/2026 | Linux VServer 1.27 and earlier, 1.3.9 and earlier, and 1.9.1 and earlier shares /proc permissions across all virtual and host servers, which allows local users with the ability to set permissions in /proc to obtain system information or cause a denial of service on other virtual servers or the host server. | |
| Modificada | Alta (10) | 2.5% | — | Linux-vserver | 31/12/2004 | 16/6/2026 | Unspecified vulnerability in procfs in the Linux-VServer stable branch for the 2.4 kernel before 1.23 and Linux-VServer development branch for the 2.4 kernel before 1.3.5 has unspecified impact and attack vectors, related to "write access to specific proc entries from a vserver context", a different vulnerability than… | |
| Modificada | Alta (7.2) | 3.1% | 💥 Exploit | Linux-vserverAI | 6/2/2004 | 16/6/2026 | Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside the virtual server via a modified chroot-again exploit using the chmod command. | |
| Modificada | Media (5) | 1.9% | — | Linux-vserver | 31/12/2003 | 16/6/2026 | Multiple race conditions in Linux-VServer 1.22 with Linux kernel 2.4.23 and SMP allow local users to cause a denial of service (kernel oops) via unknown attack vectors related to the (1) s_info and (2) ip_info data structures and the (a) forget_original_parent, (b) goodness, (c) schedule, (d) update_process_times, and… |