Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
52 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.7) | 0.13% | — | Frrouting FRRAI | 13/9/2026 | 22/9/2026 | In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to change the ownership of arbitrary files. This is a TOCTOU Race Condition caused by a combination… | |
| Pendiente de análisis | Alta (7.5) | 0.61% | — | Frrouting FRRAI | 3/6/2026 | 22/7/2026 | Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. | |
| Aplazada | Alta (7.5) | 0.68% | — | Frrouting FRRAI | 4/5/2026 | 15/7/2026 | An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. | |
| Analizada | Media (6.5) | 0.44% | — | Frrouting | 4/5/2026 | 17/6/2026 | Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticated attackers to cause a Denial of Service (DoS) via supplying a crafted UPDATE message. | |
| Modificada | Alta (7.5) | 0.72% | — | Frrouting | 1/5/2026 | 15/7/2026 | An off-by-one out-of-bounds write vulnerability in the bgp_flowspec_op_decode() function (bgpd/bgp_flowspec_util.c) of FRRouting (FRR) stable/10.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted FlowSpec component. | |
| Analizada | Media (6) | 0.37% | — | Frrouting | 30/4/2026 | 17/6/2026 | FRRouting before 10.5.3 contains an integer overflow vulnerability in seven OSPF Traffic Engineering and Segment Routing TLV parser functions where a uint16_t accumulator variable truncates uint32_t values returned by the TLV_SIZE() macro, causing the loop termination condition to fail while pointer advancement… | |
| Analizada | Baja (2.3) | 0.37% | — | Frrouting | 30/3/2026 | 17/6/2026 | A vulnerability has been found in FRRouting FRR up to 10.5.1. This affects the function process_type2_route of the file bgpd/bgp_evpn.c of the component EVPN Type-2 Route Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The attack is considered to have high complexity.… | |
| Analizada | Alta (7.5) | 0.64% | — | Frrouting | 28/10/2025 | 17/6/2026 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LSA Update packet. | |
| Analizada | Alta (7.5) | 0.64% | — | Frrouting | 28/10/2025 | 17/6/2026 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_pref_pref_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. | |
| Analizada | Alta (7.5) | 0.64% | — | Frrouting | 28/10/2025 | 17/6/2026 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_unknown_tlv function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. | |
| Analizada | Alta (7.5) | 0.64% | — | Frrouting | 28/10/2025 | 17/6/2026 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_lan_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. | |
| Analizada | Alta (7.5) | 0.50% | — | Frrouting | 27/10/2025 | 17/6/2026 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_link_info function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. | |
| Analizada | Alta (7.5) | 0.50% | — | Frrouting | 27/10/2025 | 17/6/2026 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_adj_sid function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. | |
| Analizada | Alta (7.5) | 0.50% | — | Frrouting | 27/10/2025 | 17/6/2026 | FRRouting/frr from v4.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the show_vty_ext_link_rmt_itf_addr function at ospf_ext.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted OSPF packet. | |
| Analizada | Alta (7.5) | 0.50% | — | Frrouting | 27/10/2025 | 17/6/2026 | FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the ospf_opaque_lsa_dump function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) under specific malformed LSA conditions. | |
| Analizada | Alta (7.5) | 0.50% | — | Frrouting | 27/10/2025 | 17/6/2026 | FRRouting/frr from v2.0 through v10.4.1 was discovered to contain a NULL pointer dereference via the opaque_info_detail function at ospf_opaque.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted LS Update packet. | |
| Aplazada | Alta (7.5) | 0.85% | — | Frrouting FRRAI | 6/1/2025 | 17/6/2026 | In FRRouting (FRR) before 10.3 from 6.0 onward, all routes are re-validated if the total size of an update received via RTR exceeds the internal socket's buffer size, default 4K on most OSes. An attacker can use this to trigger re-parsing of the RIB for FRR routers using RTR by causing more than this number of updates… | |
| Modificada | Alta (7.5) | 0.64% | — | FrroutingRedhat Enterprise Linux | 19/8/2024 | 17/6/2026 | An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value. | |
| Analizada | Alta (7.5) | 0.69% | — | Frrouting | 30/4/2024 | 17/6/2026 | In FRRouting (FRR) through 9.1, it is possible for the get_edge() function in ospf_te.c in the OSPF daemon to return a NULL pointer. In cases where calling functions do not handle the returned NULL value, the OSPF daemon crashes, leading to denial of service. | |
| Analizada | Media (6.5) | 0.55% | — | Frrouting | 7/4/2024 | 17/6/2026 | In the Opaque LSA Extended Link parser in FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ext_link for OSPF LSA packets during an attempt to read Segment Routing Adjacency SID subTLVs (lengths are not validated). | |
| Analizada | Media (6.5) | 0.51% | — | Frrouting | 7/4/2024 | 17/6/2026 | In FRRouting (FRR) through 9.1, there can be a buffer overflow and daemon crash in ospf_te_parse_ri for OSPF LSA packets during an attempt to read Segment Routing subTLVs (their size is not validated). | |
| Modificada | Media (6.5) | 0.70% | — | Frrouting | 7/4/2024 | 17/6/2026 | In FRRouting (FRR) through 9.1, an infinite loop can occur when receiving a MP/GR capability as a dynamic capability because malformed data results in a pointer not advancing. | |
| Modificada | Media (6.5) | 0.83% | — | Frrouting | 7/4/2024 | 17/6/2026 | In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash. | |
| Modificada | Media (6.5) | 0.32% | — | Frrouting | 28/2/2024 | 17/6/2026 | ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field. | |
| Modificada | Alta (7.5) | 0.93% | — | Frrouting | 6/11/2023 | 17/6/2026 | bgpd/bgp_label.c in FRRouting (FRR) before 8.5 attempts to read beyond the end of the stream during labeled unicast parsing. |