Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
937 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.3% | — | Google ChromeCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+5 | 5/6/2016 | 17/6/2026 | Use-after-free vulnerability in ports/SkFontHost_FreeType.cpp in Skia, as used in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Alta (8.8) | 1.3% | — | Google ChromeCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+5 | 5/6/2016 | 17/6/2026 | The ToV8Value function in content/child/v8_value_converter_impl.cc in the V8 bindings in Google Chrome before 51.0.2704.63 does not properly restrict use of getters and setters, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via crafted JavaScript… | |
| Modificada | Alta (8.8) | 1.6% | — | Google V8Google ChromeCanonical Ubuntu LinuxDebian Linux+6 | 5/6/2016 | 17/6/2026 | objects.cc in Google V8 before 5.0.71.32, as used in Google Chrome before 51.0.2704.63, does not properly restrict lazy deoptimization, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted JavaScript code. | |
| Modificada | Media (6.5) | 3.1% | — | Google ChromeCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+6 | 5/6/2016 | 17/6/2026 | uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion." | |
| Modificada | Alta (8.8) | 1.5% | — | Debian LinuxOpensuse LeapOpensuseRedhat Enterprise Linux Desktop+4 | 5/6/2016 | 17/6/2026 | extensions/renderer/resources/binding.js in the extension bindings in Google Chrome before 51.0.2704.63 does not properly use prototypes, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.5% | — | Canonical Ubuntu LinuxDebian LinuxOpensuse LeapOpensuse+5 | 5/6/2016 | 17/6/2026 | Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy by leveraging the mishandling of Document reattachment during destruction, related to FrameLoader.cpp and LocalFrame.cpp. | |
| Modificada | Alta (8.8) | 1.6% | — | Debian LinuxOpensuse LeapOpensuseRedhat Enterprise Linux Desktop+4 | 5/6/2016 | 17/6/2026 | The extensions subsystem in Google Chrome before 51.0.2704.63 allows remote attackers to bypass the Same Origin Policy via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.6% | — | Google ChromeCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+5 | 5/6/2016 | 17/6/2026 | Blink, as used in Google Chrome before 51.0.2704.63, allows remote attackers to bypass the Same Origin Policy via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.5% | — | Google ChromeDebian LinuxOpensuse LeapOpensuse+4 | 5/6/2016 | 17/6/2026 | The ModuleSystem::RequireForJsInner function in extensions/renderer/module_system.cc in the extension bindings in Google Chrome before 51.0.2704.63 mishandles properties, which allows remote attackers to conduct bindings-interception attacks and bypass the Same Origin Policy via unspecified vectors. | |
| Modificada | Alta (8.1) | 5.7% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Module FOR Legacy SoftwareNovell Suse Linux Enterprise ServerNovell Suse Manager+9 | 3/6/2016 | 17/6/2026 | The com.ibm.rmi.io.SunSerializableFactory class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) does not properly deserialize classes in an AccessController doPrivileged block,… | |
| Modificada | Alta (8.1) | 4.0% | — | Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node SupplementaryRedhat Enterprise Linux Server+9 | 3/6/2016 | 17/6/2026 | The com.ibm.CORBA.iiop.ClientDelegate class in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) uses the invoke method of the java.lang.reflect.Method class in an AccessController… | |
| Modificada | Crítica (9.8) | 13% | — | Mozilla FirefoxApple MAC OS XSuse Linux Enterprise DebuginfoSuse Studio Onsite+10 | 26/5/2016 | 17/6/2026 | Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow. | |
| Modificada | Media (5.6) | 3.9% | — | Suse Linux Enterprise ServerSuse Linux Enterprise Software Development KITIBM Java SDKRedhat Satellite+9 | 24/5/2016 | 17/6/2026 | Buffer overflow in the Java Virtual Machine (JVM) in IBM SDK, Java Technology Edition 6 before SR16 FP25 (6.0.16.25), 6 R1 before SR8 FP25 (6.1.8.25), 7 before SR9 FP40 (7.0.9.40), 7 R1 before SR3 FP40 (7.1.3.40), and 8 before SR3 (8.0.3.0) allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.51% | — | Canonical Ubuntu LinuxLinux KernelOracle LinuxNovell Suse Linux Enterprise Software Development KIT+2 | 23/5/2016 | 17/6/2026 | The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem. | |
| Modificada | Alta (7.8) | 0.48% | — | Novell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Workstation ExtensionNovell Suse Linux Enterprise Module FOR Public CloudNovell Suse Linux Enterprise Server+8 | 23/5/2016 | 17/6/2026 | Use-after-free vulnerability in drivers/net/ppp/ppp_generic.c in the Linux kernel before 4.5.2 allows local users to cause a denial of service (memory corruption and system crash, or spinlock) or possibly have unspecified other impact by removing a network namespace, related to the ppp_register_net_channel and… | |
| Modificada | Media (5.5) | 0.83% | — | Linux KernelCanonical Ubuntu LinuxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+6 | 23/5/2016 | 17/6/2026 | The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface. | |
| Modificada | Baja (3.3) | 1.7% | 💥 Exploit | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+6 | 23/5/2016 | 17/6/2026 | The rtnl_fill_link_ifmap function in net/core/rtnetlink.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory by reading a Netlink message. | |
| Modificada | Alta (7.5) | 4.7% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise ServerCanonical Ubuntu Linux+1 | 23/5/2016 | 17/6/2026 | The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message. | |
| Modificada | Media (6.2) | 0.55% | — | Canonical Ubuntu LinuxLinux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+7 | 23/5/2016 | 17/6/2026 | The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call. | |
| Modificada | Crítica (9.6) | 4.2% | — | PHPCanonical Ubuntu LinuxOpensuse LeapOpensuse+2 | 22/5/2016 | 17/6/2026 | ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related… | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa💥 Exploit | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server From Rhui+5 | 11/5/2016 | 10/9/2026 | Adobe Flash Player 21.0.0.226 and earlier allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in May 2016. | |
| Analizada | Media (5.5) | 77% | ⚠ Explotación activa💥 Exploit | Redhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux FOR IBM Z Systems EUS+26 | 5/5/2016 | 17/6/2026 | The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. | |
| Analizada | Media (5.5) | 75% | ⚠ Explotación activa💥 Exploit | Redhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux FOR IBM Z Systems EUS+26 | 5/5/2016 | 17/6/2026 | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. | |
| Analizada | Alta (8.4) | 97% | ⚠ Explotación activa💥 Exploit | ImagemagickCanonical Ubuntu LinuxDebian LinuxOpensuse Leap+2 | 5/5/2016 | 17/6/2026 | The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to execute arbitrary code via shell metacharacters in a crafted image, aka "ImageTragick." | |
| Modificada | Media (4.6) | 0.59% | — | Canonical Ubuntu LinuxNovell Suse Linux Enterprise Software Development KITSuse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Desktop+6 | 2/5/2016 | 17/6/2026 | Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor. |