Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.48% | — | F5 Traffix Signaling Delivery Controller | 5/5/2022 | 17/6/2026 | On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Scripting (XSS) vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software… | |
| Modificada | Media (4.8) | 0.48% | — | F5 Traffix Signaling Delivery Controller | 5/5/2022 | 17/6/2026 | On F5 Traffix SDC 5.2.x versions prior to 5.2.2 and 5.1.x versions prior to 5.1.35, a stored Cross-Site Template Injection vulnerability exists in an undisclosed page of the Traffix SDC Configuration utility that allows an attacker to execute template language-specific instructions in the context of the server. Note:… | |
| Analizada | Alta (7.5) | 25% | — | Balasys DheaterSiemens Scalance W1750d FirmwareSuse Linux Enterprise ServerF5 Big-ip Access Policy Manager+26 | 11/11/2021 | 23/9/2026 | The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)at or D(HE)ater attack. The client needs very little CPU resources and network… | |
| Modificada | Media (5.9) | 0.81% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+13 | 6/2/2020 | 17/6/2026 | On BIG-IP 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.0-11.6.5.1, the tmm crashes under certain circumstances when using the connector profile if a specific sequence of connections are made. | |
| Modificada | Alta (7.5) | 6.8% | — | TcpdumpF5 Traffix Signaling Delivery ControllerApple MAC OS XDebian Linux+3 | 3/10/2019 | 17/6/2026 | The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option(). | |
| Modificada | Alta (7.5) | 3.9% | — | TcpdumpF5 Traffix Signaling Delivery ControllerApple MAC OS XDebian Linux+3 | 3/10/2019 | 17/6/2026 | The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c. | |
| Modificada | Alta (7.5) | 5.3% | — | TcpdumpApple MAC OS XDebian LinuxFedoraproject Fedora+19 | 3/10/2019 | 17/6/2026 | The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr(). | |
| Modificada | Alta (7) | 4.7% | — | F5 Traffix Signaling Delivery ControllerTcpdumpApple MAC OS XDebian Linux+3 | 3/10/2019 | 17/6/2026 | The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file(). | |
| Modificada | Alta (7.5) | 5.3% | — | TcpdumpF5 Traffix Signaling Delivery ControllerApple MAC OS XDebian Linux+3 | 3/10/2019 | 17/6/2026 | The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print(). | |
| Modificada | Alta (7.5) | 4.0% | — | TcpdumpApple MAC OS XDebian LinuxFedoraproject Fedora+19 | 3/10/2019 | 17/6/2026 | The FRF.16 parser in tcpdump before 4.9.3 has a buffer over-read in print-fr.c:mfr_print(). | |
| Modificada | Alta (7.5) | 4.1% | — | TcpdumpF5 Traffix Signaling Delivery ControllerApple MAC OS XDebian Linux+3 | 3/10/2019 | 17/6/2026 | The RSVP parser in tcpdump before 4.9.3 has a buffer over-read in print-rsvp.c:rsvp_obj_print(). | |
| Modificada | Alta (7.5) | 4.7% | — | TcpdumpF5 Traffix Signaling Delivery ControllerApple MAC OS XDebian Linux+3 | 3/10/2019 | 17/6/2026 | The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for VRRP version 2, a different vulnerability than CVE-2019-15167. | |
| Modificada | Alta (7.5) | 4.0% | — | TcpdumpF5 Traffix Signaling Delivery ControllerApple MAC OS XDebian Linux+3 | 3/10/2019 | 17/6/2026 | The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print(). | |
| Modificada | Alta (7.5) | 2.7% | — | Linux KernelCanonical Ubuntu LinuxF5 Traffix Signaling Delivery Controller | 23/9/2019 | 17/6/2026 | In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c allows attackers to obtain sensitive information from kernel stack memory because tos and flags fields are not initialized. | |
| Modificada | Alta (7.5) | 5.0% | — | OpenldapCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+5 | 26/7/2019 | 17/6/2026 | An issue was discovered in OpenLDAP 2.x before 2.4.48. When using SASL authentication and session encryption, and relying on the SASL security layers in slapd access controls, it is possible to obtain access that would otherwise be denied via a simple bind for any identity covered in those ACLs. After the first SASL… | |
| Modificada | Alta (8.1) | 12% | — | Libssh2Debian LinuxFedoraproject FedoraNetapp Cloud Backup+3 | 16/7/2019 | 17/6/2026 | In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of… | |
| Modificada | Alta (7.5) | 2.7% | — | GnupgSKS Keyserver Project SKS KeyserverFedoraproject FedoraOpensuse Leap+1 | 29/6/2019 | 17/6/2026 | Interaction between the sks-keyserver code through 1.2.0 of the SKS keyserver network, and GnuPG through 2.2.16, makes it risky to have a GnuPG keyserver configuration line referring to a host on the SKS keyserver network. Retrieving data from this network may cause a persistent denial of service, because of a… | |
| Modificada | Alta (7.5) | 92% | — | Linux KernelF5 Big-ip Advanced Firewall ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Application Acceleration Manager+17 | 19/6/2019 | 17/6/2026 | Jonathan Looney discovered that the Linux kernel default MSS is hard-coded to 48 bytes. This allows a remote peer to fragment TCP resend queues significantly more than if a larger MSS were enforced. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182,… | |
| Modificada | Alta (7.5) | 95% | — | Linux KernelF5 Big-ip Advanced Firewall ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Application Acceleration Manager+20 | 19/6/2019 | 17/6/2026 | Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182,… | |
| Modificada | Alta (7.5) | 99% | — | Linux KernelF5 Big-ip Advanced Firewall ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Application Acceleration Manager+20 | 19/6/2019 | 17/6/2026 | Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127,… | |
| Modificada | Alta (7.8) | 50% | — | Haxx LibcurlOpensuse LeapFedoraproject FedoraDebian Linux+7 | 28/5/2019 | 17/6/2026 | A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. | |
| Modificada | Alta (8.1) | 5.1% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxF5 Traffix Signaling Delivery Controller+9 | 7/5/2019 | 17/6/2026 | An issue was discovered in the Linux kernel before 4.20. There is a race condition in smp_task_timedout() and smp_task_done() in drivers/scsi/libsas/sas_expander.c, leading to a use-after-free. | |
| Modificada | Media (5.9) | 17% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNetapp Active IQ Unified Manager+78 | 27/2/2019 | 17/6/2026 | If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid… | |
| Modificada | Alta (7.8) | 2.0% | — | GNU BinutilsNetapp Element SoftwareCanonical Ubuntu LinuxF5 Traffix Signaling Delivery Controller | 24/2/2019 | 17/6/2026 | An issue was discovered in GNU Binutils 2.32. It is a heap-based buffer overflow in process_mips_specific in readelf.c via a malformed MIPS option section. | |
| Modificada | Alta (7.8) | 1.6% | — | GNU BinutilsNetapp Element Software ManagementCanonical Ubuntu LinuxF5 Traffix Signaling Delivery Controller | 24/2/2019 | 17/6/2026 | An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.32. It is a heap-based buffer over-read in d_expression_1 in cp-demangle.c after many recursive calls. |