Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.29% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions. | |
| Modificada | Alta (7.5) | 0.28% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions. | |
| Modificada | Alta (7.5) | 0.26% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell BIOSConnect feature contains a buffer overflow vulnerability. An authenticated malicious admin user with local access to the system may potentially exploit this vulnerability to run arbitrary code and bypass UEFI restrictions. | |
| Modificada | Media (6.5) | 0.54% | — | Dell Alienware M15 R6 FirmwareDell Chengming 3990 FirmwareDell Chengming 3991 FirmwareDell G15 5510 Firmware+124 | 24/6/2021 | 17/6/2026 | Dell UEFI BIOS https stack leveraged by the Dell BIOSConnect feature and Dell HTTPS Boot feature contains an improper certificate validation vulnerability. A remote unauthenticated attacker may exploit this vulnerability using a person-in-the-middle attack which may lead to a denial of service and payload tampering. |