Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
44 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.7) | 3.8% | — | Oracle OpenjdkOracle JDKOracle JREDebian Linux+15 | 21/10/2020 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.5) | 20% | — | Apache Http ServerDebian LinuxNetapp Santricity Cloud ConnectorNetapp Storage Automation Store+2 | 30/1/2019 | 17/6/2026 | In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessions since the expiry time is loaded when the session is decoded. | |
| Modificada | Media (5.3) | 20% | — | Apache Http ServerNetapp Santricity Cloud ConnectorNetapp Storage Automation StoreFedoraproject Fedora+8 | 30/1/2019 | 17/6/2026 | In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections. | |
| Modificada | Crítica (9.8) | 1.3% | — | SAP Cloud Connector | 8/1/2019 | 17/6/2026 | SAP Cloud Connector, before version 2.11.3, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. | |
| Modificada | Crítica (9.8) | 2.7% | — | SAP Cloud Connector | 8/1/2019 | 17/6/2026 | SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for functionalities that require user identity. | |
| Modificada | Crítica (9.8) | 19% | — | Eclipse JettyDebian LinuxOracle Rest Data ServicesOracle Retail Xstore Payment+15 | 26/6/2018 | 17/6/2026 | In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the second. When presented with a content-length and a chunked encoding header, the content-length was ignored (as per RFC… | |
| Modificada | Crítica (9.8) | 15% | — | Eclipse JettyDebian LinuxNetapp E-series Santricity ManagementNetapp E-series Santricity OS Controller+13 | 26/6/2018 | 17/6/2026 | In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk length parsing was vulnerable to an integer overflow. Thus a large chunk size could be interpreted as a smaller chunk… | |
| Modificada | Alta (8.8) | 2.7% | — | Eclipse JettyNetapp E-series Santricity Management Plug-insNetapp E-series Santricity OS ControllerNetapp E-series Santricity WEB Services Proxy+8 | 22/6/2018 | 17/6/2026 | In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the… | |
| Modificada | Alta (8.3) | 4.9% | — | Oracle JDKOracle JRECanonical Ubuntu LinuxNetapp Cloud Backup+13 | 19/4/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction… | |
| Modificada | Alta (8.3) | 4.1% | — | Oracle JDKOracle JRECanonical Ubuntu LinuxNetapp Cloud Backup+13 | 19/4/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Libraries). The supported version that is affected is Java SE: 10. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human interaction… | |
| Modificada | Alta (7.5) | 70% | — | Apache Http ServerDebian LinuxCanonical Ubuntu LinuxNetapp Santricity Cloud Connector+3 | 26/3/2018 | 17/6/2026 | A specially crafted HTTP request header could have crashed the Apache HTTP Server prior to version 2.4.30 due to an out of bound read while preparing data to be cached in shared memory. It could be used as a Denial of Service attack against users of mod_cache_socache. The vulnerability is considered as low risk since… | |
| Modificada | Media (5.9) | 13% | — | Apache Http ServerCanonical Ubuntu LinuxNetapp Clustered Data OntapNetapp Santricity Cloud Connector+2 | 26/3/2018 | 17/6/2026 | When an HTTP/2 stream was destroyed after being handled, the Apache HTTP Server prior to version 2.4.30 could have written a NULL pointer potentially to an already freed memory. The memory pools maintained by the server make this vulnerability hard to trigger in usual configurations, the reporter and the team could… | |
| Modificada | Media (5.9) | 15% | — | Apache Http ServerDebian LinuxCanonical Ubuntu LinuxNetapp Santricity Cloud Connector+4 | 26/3/2018 | 17/6/2026 | A specially crafted request could have crashed the Apache HTTP Server prior to version 2.4.30, due to an out of bound access after a size limit is reached by reading the HTTP header. This vulnerability is considered very hard if not impossible to trigger in non-debug mode (both log and build level), so it is… | |
| Modificada | Media (5.3) | 9.7% | — | Apache Http ServerDebian LinuxCanonical Ubuntu LinuxNetapp Santricity Cloud Connector+4 | 26/3/2018 | 17/6/2026 | In Apache httpd 2.4.0 to 2.4.29, when mod_session is configured to forward its session data to CGI applications (SessionEnv on, not the default), a remote user may influence their content by using a "Session" header. This comes from the "HTTP_SESSION" variable name used by mod_session to forward its data to CGIs,… | |
| Modificada | Alta (8.1) | 85% | — | Apache Http ServerDebian LinuxCanonical Ubuntu LinuxNetapp Santricity Cloud Connector+4 | 26/3/2018 | 17/6/2026 | In Apache httpd 2.4.0 to 2.4.29, the expression specified in <FilesMatch> could match '$' to a newline character in a malicious filename, rather than matching only the end of the filename. This could be exploited in environments where uploads of some files are are externally blocked, but only by matching the trailing… | |
| Modificada | Alta (7.5) | 17% | — | Apache Http ServerDebian LinuxCanonical Ubuntu LinuxNetapp Santricity Cloud Connector+4 | 26/3/2018 | 17/6/2026 | In Apache httpd 2.0.23 to 2.0.65, 2.2.0 to 2.2.34, and 2.4.0 to 2.4.29, mod_authnz_ldap, if configured with AuthLDAPCharsetConfig, uses the Accept-Language header value to lookup the right charset encoding when verifying the user's credentials. If the header value is not present in the charset conversion table, a… | |
| Modificada | Alta (8.3) | 3.3% | — | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+20 | 18/1/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Deployment). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human… | |
| Modificada | Alta (7.5) | 0.49% | — | Oracle JDKOracle JRERedhat SatelliteNetapp Active IQ Unified Manager+16 | 18/1/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Installer). Supported versions that are affected are Java SE: 8u152 and 9.0.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks… | |
| Modificada | Media (4.7) | 2.5% | — | Oracle JDKOracle JRERedhat SatelliteNetapp Active IQ Unified Manager+16 | 18/1/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: JavaFX). Supported versions that are affected are Java SE: 7u161, 8u152 and 9.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks require human… |