Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▲ 460 respecto a la semana anterior
Críticas / altas1445▲ 228 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 156 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.26% | — | SmartosAIJoyent Triton Data CenterAIDebianAI | 19/3/2025 | 17/6/2026 | SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the 60f76fd2-143f-4f57-819b-1ae32684e81b image (a Debian 12 LX zone image from 2024-07-26). | |
| Modificada | Crítica (9.8) | 72% | — | Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+4 | 15/1/2025 | 29/6/2026 | A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled checksum lengths (s2length) in the code. When MAX_DIGEST_LEN exceeds the fixed SUM_LENGTH (16 bytes), an attacker can write out of bounds in the sum2 buffer. | |
| Modificada | Alta (7.5) | 4.7% | — | Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+16 | 14/1/2025 | 30/6/2026 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory. | |
| Modificada | Alta (7.5) | 2.3% | — | Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+14 | 14/1/2025 | 30/6/2026 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification… | |
| Modificada | Media (6.8) | 1.8% | — | Samba RsyncRedhat Openshift Container PlatformRedhat Enterprise LinuxAlmalinux+5 | 14/1/2025 | 21/8/2026 | A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums of local data to the client to compare with in order to… | |
| Modificada | Alta (7.5) | 8.8% | — | Samba RsyncRedhat OpenshiftRedhat Openshift Container PlatformRedhat Enterprise Linux+18 | 14/1/2025 | 21/9/2026 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time. | |
| Modificada | Alta (8.8) | 0.61% | — | Adtran SDG Smartos | 24/7/2024 | 17/6/2026 | AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have SSH enabled by default, accessible both over the LAN and the Internet. During a window of time when the device is being set up, it uses a default username and password combination of admin/admin with root-level… | |
| Modificada | Alta (7.2) | 0.53% | — | Adtran SDG Smartos | 24/7/2024 | 17/6/2026 | AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented, hard-coded support account whose password is based on the devices MAC address. All of the devices internet interfaces share a similar MAC address that only varies in their final octet. This allows… | |
| Modificada | Alta (8.8) | 1.7% | — | Adtran SDG SmartosAdtran 834-5 Firmware | 24/7/2024 | 17/6/2026 | Adtran 834-5 11.1.0.101-202106231430, and fixed as of SmartOS Version 12.6.3.1, devices allow OS Command Injection via shell metacharacters to the Ping or Traceroute utility. | |
| Modificada | Media (5.5) | 0.32% | — | IllumosOmniosce OmniosOpenindianaJoyent Smartos+1 | 26/12/2022 | 17/6/2026 | An issue was discovered in illumos before f859e7171bb5db34321e45585839c6c3200ebb90, OmniOS Community Edition r151038, OpenIndiana Hipster 2021.04, and SmartOS 20210923. A local unprivileged user can cause a deadlock and kernel panic via crafted rename and rmdir calls on tmpfs filesystems. Oracle Solaris 10 and 11 is… | |
| Modificada | Crítica (9.8) | 1.4% | — | IllumosJoyent SmartosOmniosce Omnios | 26/10/2020 | 17/6/2026 | An issue was discovered in illumos before 2020-10-22, as used in OmniOS before r151030by, r151032ay, and r151034y and SmartOS before 20201022. There is a buffer overflow in parse_user_name in lib/libpam/pam_framework.c. | |
| Modificada | Media (5.5) | 0.47% | — | Joyent Smartos | 7/9/2018 | 17/6/2026 | An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFSADDENTRIES when used with a 32 bit model. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploit… | |
| Modificada | Alta (7) | 0.44% | — | Joyent SmartosOracle Solaris | 19/3/2018 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Alta (7.8) | 0.38% | — | Joyent Smartos | 21/2/2018 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Alta (7) | 0.50% | — | Joyent SmartosOracle SolarisOracle ZFS Storage Appliance | 21/2/2018 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Media (5.5) | 0.52% | — | Joyent Smartos | 31/1/2017 | 17/6/2026 | An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never freed. When repeatedly exploited this will result in memory… | |
| Modificada | Alta (7) | 0.54% | — | Joyent Smartos | 14/12/2016 | 17/6/2026 | An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a buffer overflow in the path variable… | |
| Modificada | Alta (7) | 0.53% | — | Joyent Smartos | 14/12/2016 | 17/6/2026 | An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with 32-bit file systems. An attacker can craft an input that can cause a buffer overflow in the nm variable… | |
| Modificada | Alta (7) | 0.53% | — | Joyent Smartos | 14/12/2016 | 17/6/2026 | An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a buffer overflow in the path variable… | |
| Modificada | Alta (7) | 0.53% | — | Joyent Smartos | 14/12/2016 | 17/6/2026 | An exploitable buffer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a buffer overflow in the nm variable… | |
| Modificada | Alta (7.8) | 0.49% | — | Joyent Smartos | 14/12/2016 | 17/6/2026 | An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with 32-bit file systems. An attacker can craft an input that can cause a kernel panic and potentially be… | |
| Modificada | Alta (8.8) | 0.55% | — | Joyent Smartos | 14/12/2016 | 17/6/2026 | An exploitable integer overflow exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES when dealing with native file systems. An attacker can craft an input that can cause a kernel panic and potentially be… | |
| Modificada | Alta (7.2) | 40% | — | FreebsdIllumosJoyent SmartosXEN+7 | 12/6/2012 | 16/6/2026 | The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008… |