Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

405 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)5.0%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdRedhat Enterprise Linux Desktop+1119/3/201417/6/2026
Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a crafted extension that renders fonts in a PDF document.
ModificadaCrítica (9.1)4.3%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdRedhat Enterprise Linux Desktop+1219/3/201417/6/2026
The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of service (out-of-bounds read and application crash), or possibly…
ModificadaAlta (7.5)4.0%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+1219/3/201417/6/2026
The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing…
ModificadaMedia (6.8)1.2%—OpensuseOpensuse Project OpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+419/3/201417/6/2026
The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.
ModificadaMedia (5.8)1.6%—Oracle SolarisMozilla FirefoxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+119/3/201417/6/2026
Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.
ModificadaMedia (5)3.6%—OpensuseOpensuse Project OpensuseOracle SolarisMozilla Firefox+419/3/201417/6/2026
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.
ModificadaMedia (4.3)1.9%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITMozilla Seamonkey+419/3/201417/6/2026
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.
ModificadaMedia (5)1.8%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITOracle Solaris+419/3/201417/6/2026
The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use…
ModificadaAlta (8.8)2.8%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+1219/3/201417/6/2026
The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause a denial of service (out-of-bounds read and application crash), or…
ModificadaMedia (5.5)0.38%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdSuse Linux Enterprise Software Development KIT+219/3/201417/6/2026
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.
ModificadaAlta (9.3)5.1%—Mozilla SeamonkeySuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+419/3/201417/6/2026
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
ModificadaCrítica (9.8)8.1%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+1219/3/201417/6/2026
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown…
ModificadaMedia (5)30%💥 PoCLighttpdDebian LinuxOpensuseSuse Linux Enterprise High Availability Extension+214/3/201417/6/2026
Multiple directory traversal vulnerabilities in (1) mod_evhost and (2) mod_simple_vhost in lighttpd before 1.4.35 allow remote attackers to read arbitrary files via a .. (dot dot) in the host name, related to request_check_hostname.
ModificadaCrítica (9.8)63%💥 ExploitLighttpdDebian LinuxOpensuseSuse Linux Enterprise High Availability Extension+114/3/201417/6/2026
SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.
ModificadaMedia (4.3)4.6%—Mozilla FirefoxMozilla Network Security ServicesMozilla SeamonkeyMozilla Thunderbird+96/2/201417/6/2026
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass…
ModificadaAlta (9.3)3.9%—Mozilla FirefoxMozilla Network Security ServicesMozilla SeamonkeyMozilla Thunderbird+96/2/201417/6/2026
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified…
ModificadaMedia (4.3)1.9%—Oracle SolarisSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+46/2/201417/6/2026
Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.
ModificadaAlta (10)7.2%—Mozilla FirefoxMozilla SeamonkeyCanonical Ubuntu LinuxOracle Solaris+46/2/201417/6/2026
The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation in conjunction with use of asm.js.
ModificadaAlta (7.5)2.3%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+136/2/201417/6/2026
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.
ModificadaCrítica (9.8)7.1%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+126/2/201417/6/2026
Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unspecified Content-Type values for image data.
ModificadaAlta (7.5)3.0%—Mozilla FirefoxMozilla SeamonkeyOracle SolarisCanonical Ubuntu Linux+46/2/201417/6/2026
The Content Security Policy (CSP) implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 operates on XSLT stylesheets according to style-src directives instead of script-src directives, which might allow remote attackers to execute arbitrary XSLT code by leveraging insufficient style-src restrictions.
ModificadaMedia (5)1.6%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITMozilla Firefox+36/2/201417/6/2026
Mozilla Firefox before 27.0 on Android 4.2 and earlier creates system-log entries containing profile paths, which allows attackers to obtain sensitive information via a crafted application.
ModificadaMedia (5)2.5%—Oracle SolarisCanonical Ubuntu LinuxMozilla FirefoxMozilla Seamonkey+46/2/201417/6/2026
Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions.
ModificadaAlta (8.8)6.3%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+136/2/201417/6/2026
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as…
ModificadaAlta (7.5)3.9%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+136/2/201417/6/2026
Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.