Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.5)0.57%—HPE Icewall Federation AgentAIHPE Icewall ProxyAI11/9/202611/9/2026
A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).
ModificadaAlta (7.5)4.0%—Canonical Ubuntu LinuxXmlsoft Libxml2Debian LinuxHP Icewall Federation Agent+230/7/201817/6/2026
It was found that Red Hat JBoss Core Services erratum RHSA-2016:2957 for CVE-2016-3705 did not actually include the fix for the issue found in libxml2, making it vulnerable to a Denial of Service attack due to a Stack Overflow. This is a regression CVE for the same issue as CVE-2016-3705.
ModificadaMedia (6.1)1.7%—HP Icewall Federation Agent15/2/201817/6/2026
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Federation Agent version 3.0 was found.
ModificadaMedia (5.9)42%—OpensslHP Icewall Federation AgentHP Icewall McrpHP Icewall SSO+526/9/201617/6/2026
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
ModificadaCrítica (9.8)46%—HP Icewall Federation AgentHP Icewall McrpHP Icewall SSOHP Icewall SSO Agent Option+216/9/201617/6/2026
The BN_bn2dec function in crypto/bn/bn_print.c in OpenSSL before 1.1.0 does not properly validate division results, which allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors.
ModificadaCrítica (9.8)7.0%—HP Icewall Federation AgentApple WatchosApple MAC OS XXmlsoft Libxml2+159/6/201617/6/2026
Format string vulnerability in libxml2 before 2.9.4 allows attackers to have unspecified impact via format string specifiers in unknown vectors.
ModificadaAlta (7.5)14%—HP Icewall Federation AgentCanonical Ubuntu LinuxDebian LinuxOracle VM Server+79/6/201617/6/2026
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application crash) via a crafted file, involving xmlParseName.
ModificadaAlta (7.5)5.1%—Canonical Ubuntu LinuxXmlsoft Libxml2Debian LinuxHP Icewall Federation Agent+217/5/201617/6/2026
The (1) xmlParserEntityCheck and (2) xmlParseAttValueComplex functions in parser.c in libxml2 2.9.3 do not properly keep track of the recursion depth, which allows context-dependent attackers to cause a denial of service (stack consumption and application crash) via a crafted XML document containing a large number of…
ModificadaAlta (7.5)7.0%—Opensuse LeapDebian LinuxHP Icewall Federation AgentHP Icewall File Manager+1017/5/201617/6/2026
The xmlStringGetNodeList function in tree.c in libxml2 2.9.3 and earlier, when used in recovery mode, allows context-dependent attackers to cause a denial of service (infinite recursion, stack consumption, and application crash) via a crafted XML document.
ModificadaMedia (5)5.9%—Debian LinuxCanonical Ubuntu LinuxXmlsoft Libxml2Redhat Enterprise Linux Desktop+515/12/201517/6/2026
The xmlParseXMLDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive information via an (1) unterminated encoding value or (2) incomplete XML declaration in XML data, which triggers an out-of-bounds heap read.
ModificadaMedia (5.8)4.3%—Xmlsoft Libxml2HP Icewall Federation AgentHP Icewall File ManagerApple Iphone OS+815/12/201517/6/2026
The xmlSAX2TextNode function in SAX2.c in the push interface in the HTML parser in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (stack-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
ModificadaMedia (6.4)5.4%—Debian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+515/12/201517/6/2026
The xmlNextChar function in libxml2 2.9.2 does not properly check the state, which allows context-dependent attackers to cause a denial of service (heap-based buffer over-read and application crash) or obtain sensitive information via crafted XML data.
ModificadaMedia (5)5.9%—HP Icewall Federation AgentHP Icewall File ManagerXmlsoft Libxml2Debian Linux+915/12/201517/6/2026
The xmlParseMisc function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service (out-of-bounds heap read) via unspecified vectors related to incorrect entities boundaries and start tags.
ModificadaMedia (5)6.4%—Apple Iphone OSApple MAC OS XApple TvosApple Watchos+1115/12/201517/6/2026
Heap-based buffer overflow in the xmlGROW function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to obtain sensitive process memory information via unspecified vectors.
ModificadaMedia (5)7.2%—HP Icewall Federation AgentHP Icewall File ManagerCanonical Ubuntu LinuxDebian Linux+515/12/201517/6/2026
Heap-based buffer overflow in the xmlParseXmlDecl function in parser.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors related to extracting errors after an encoding conversion failure.
ModificadaMedia (5)7.2%—Debian LinuxCanonical Ubuntu LinuxXmlsoft Libxml2Redhat Enterprise Linux Desktop+515/12/201517/6/2026
Heap-based buffer overflow in the xmlDictComputeFastQKey function in dict.c in libxml2 before 2.9.3 allows context-dependent attackers to cause a denial of service via unspecified vectors.
ModificadaAlta (7.1)4.5%—Canonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+915/12/201517/6/2026
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
ModificadaMedia (6.8)4.7%—HP Icewall Federation AgentHP Icewall File ManagerDebian LinuxApple Iphone OS+518/11/201517/6/2026
The xmlParseConditionalSections function in parser.c in libxml2 does not properly skip intermediary entities when it stops parsing invalid input, which allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via crafted XML data, a different vulnerability than CVE-2015-7941.
ModificadaBaja (2.1)1.5%—HP Icewall Smart Device OptionHP Icewall SSO AgentHP Icewall SSO Saml2 OptionHP Icewall File Manager+323/9/201316/6/2026
Unspecified vulnerability in HP IceWall SSO 8.0 through 10.0, IceWall SSO Agent Option 8.0 through 10.0, IceWall SSO Smart Device Option 10.0, IceWall SSO SAML2 Agent Option 8.0, IceWall SSO JAVA Agent Library 8.0 through 10.0, IceWall Federation Agent 3.0, and IceWall File Manager 3.0 through SP4 allows remote…