Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
–

46 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaAlta (8.8)——Windriver VxworksAI1/10/20262/10/2026
An improper privilege management vulnerability (CWE-269) exists in the command shell of Wind River VxWorks 7 when configured to enforce per-user command privileges. Under certain shell operations, a command may be evaluated without the privilege check that is normally applied, allowing an authenticated user with…
Pendiente de análisisMedia (5.5)0.10%—Windriver VxworksAI28/9/202630/9/2026
In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem failing to properly release allocated kernel memory before terminating the calling application. Fixed in Version 26.09
Pendiente de análisisMedia (5.5)0.10%—Windriver VxworksAI28/9/202629/9/2026
Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when processing specific service routines, causing the system to terminate operations before releasing allocated memory pools. Fixed in VxWorks 7 26.09
Pendiente de análisisAlta (7.8)0.11%—Windriver VxworksAI28/9/202629/9/2026
Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory management subsystem. Fixed in Version 26.09
Pendiente de análisisMedia (5.5)0.10%—Windriver VxworksAI28/9/202628/9/2026
Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09.
AplazadaCrítica (9.3)0.77%—Vxworks Mr-gm5l-s1AIVxworks Mr-gm5a-l1AI11/3/202617/6/2026
Authentication bypass issue exists in MR-GM5L-S1 and MR-GM5A-L1, which may allow an attacker to bypass authentication and change the device configuration.
AplazadaMedia (4.6)0.21%—Wind River Systems Vxworks 7AI21/3/202517/6/2026
: Uncontrolled Resource Consumption vulnerability in Wind River Systems VxWorks 7 on VxWorks allows Excessive Allocation. Specifically crafted USB packets may lead to the system becoming unavailable This issue affects VxWorks 7: from 22.06 through 24.03.
AplazadaMedia (4.3)0.25%—Windriver VxworksAI14/5/202417/6/2026
A crafted network packet may cause a buffer overrun in Wind River VxWorks 7 through 23.09.
AnalizadaAlta (7.5)0.49%—Windriver Vxworks15/2/202417/6/2026
An issue was discovered in Wind River VxWorks 7 22.09 and 23.03. If a VxWorks task or POSIX thread that uses OpenSSL exits, limited per-task memory is not freed, resulting in a memory leak.
ModificadaAlta (8.8)1.5%—Windriver Vxworks22/9/202317/6/2026
An issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processes files within an archive that have relative or absolute file paths. A developer using the "tarExtract" function may expect that the function will strip leading slashes from…
ModificadaAlta (7.5)1.1%—Windriver Vxworks25/11/202217/6/2026
An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during the IP Radius access procedure.
ModificadaAlta (7.5)1.0%—Windriver Vxworks29/3/202217/6/2026
In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario.
ModificadaMedia (6.5)0.88%—Windriver Vxworks24/11/202117/6/2026
An issue was discovered in VxWorks 6.9 through 7. In the IKE component, a specifically crafted packet may lead to reading beyond the end of a buffer, or a double free.
ModificadaCrítica (9.8)2.5%—Windriver VxworksOracle Communications Eagle12/5/202117/6/2026
An issue was discovered in Wind River VxWorks 7. The memory allocator has a possible integer overflow in calculating a memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.
ModificadaCrítica (9.8)1.8%—Windriver Vxworks13/4/202117/6/2026
An issue was discovered in Wind River VxWorks through 6.8. There is a possible stack overflow in dhcp server.
ModificadaCrítica (9.8)2.4%—Windriver VxworksSiemens Ruggedcom WIN Subscriber Station FirmwareSiemens Scalance X200-4 P IRT FirmwareSiemens Scalance X201-3p IRT Firmware+3213/4/202117/6/2026
An issue was discovered in Wind River VxWorks before 6.5. There is a possible heap overflow in dhcp client.
ModificadaMedia (5.3)1.0%—Windriver Vxworks13/4/202117/6/2026
An issue was discovered in Wind River VxWorks 7 before 21.03. A specially crafted packet may lead to buffer over-read on IKE.
ModificadaCrítica (9.8)1.9%—Windriver VxworksSiemens Sgt-100 FirmwareSiemens Sgt-200 FirmwareSiemens Sgt-300 Firmware+411/3/202117/6/2026
A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
ModificadaAlta (7.3)1.6%—Windriver VxworksOracle Communications Eagle3/2/202117/6/2026
In Wind River VxWorks, memory allocator has a possible overflow in calculating the memory block's size to be allocated by calloc(). As a result, the actual memory allocated is smaller than the buffer size specified by the arguments, leading to memory corruption.
ModificadaAlta (7.5)1.1%—Windriver Vxworks23/7/202017/6/2026
httpRpmFs in WebCLI in Wind River VxWorks 5.5 through 7 SR0640 has no check for an escape from the web root.
ModificadaAlta (7.5)1.4%—Windriver Vxworks27/4/202017/6/2026
The IGMP component in VxWorks 6.8.3 IPNET CVE patches created in 2019 has a NULL Pointer Dereference.
ModificadaCrítica (9.8)4.1%—Windriver VxworksBelden Hirschmann HiosBelden Garrettcom Magnum Dx940e FirmwareSiemens Ruggedcom Win7000 Firmware+314/8/201917/6/2026
Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw).
ModificadaCrítica (9.8)9.0%—Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+99/8/201917/6/2026
Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.
ModificadaCrítica (9.8)23%—Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+99/8/201917/6/2026
Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.
ModificadaAlta (7.5)23%—Windriver VxworksSonicwall SonicosSiemens Siprotec 5 FirmwareNetapp E-series Santricity OS Controller+89/8/201917/6/2026
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.