Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.7% | — | OpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+4 | 6/2/2014 | 17/6/2026 | The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site. | |
| Modificada | Alta (7.5) | 4.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+13 | 6/2/2014 | 17/6/2026 | The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remote attackers to bypass intended restrictions on XUL content via vectors involving XBL content… | |
| Modificada | Crítica (9.8) | 5.5% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+13 | 6/2/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown… | |
| Modificada | Media (5.9) | 2.9% | — | Fedoraproject FedoraMozilla FirefoxMozilla SeamonkeyMozilla Thunderbird+5 | 11/12/2013 | 17/6/2026 | Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it easier for man-in-the-middle attackers to spoof SSL servers in opportunistic circumstances via a valid certificate that… | |
| Modificada | Media (4.3) | 3.3% | — | OpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+5 | 11/12/2013 | 17/6/2026 | Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard data by leveraging certain middle-click paste operations. | |
| Modificada | Crítica (9.8) | 11% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+12 | 11/12/2013 | 17/6/2026 | The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements. | |
| Modificada | Alta (7.5) | 3.7% | — | OpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+5 | 11/12/2013 | 16/6/2026 | Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code. | |
| Modificada | Crítica (9.8) | 10% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 11/12/2013 | 16/6/2026 | Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper… | |
| Modificada | Crítica (9.8) | 6.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 11/12/2013 | 16/6/2026 | Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors… | |
| Modificada | Crítica (9.8) | 4.2% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+5 | 11/12/2013 | 16/6/2026 | The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions on the generation of GetElementIC typed array stubs, which has unspecified impact and remote attack vectors. | |
| Modificada | Media (4.3) | 2.4% | — | Mozilla FirefoxMozilla SeamonkeyFedoraproject FedoraOracle Solaris+12 | 11/12/2013 | 16/6/2026 | Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site. | |
| Modificada | Crítica (9.8) | 9.4% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 11/12/2013 | 16/6/2026 | Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving… | |
| Modificada | Media (4.3) | 3.4% | — | Mozilla FirefoxMozilla SeamonkeyFedoraproject FedoraOracle Solaris+12 | 11/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header. | |
| Modificada | Media (5.8) | 2.1% | — | Oracle SolarisFedoraproject FedoraCanonical Ubuntu LinuxSuse Linux Enterprise Desktop+5 | 11/12/2013 | 16/6/2026 | Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation. | |
| Modificada | Alta (10) | 6.5% | — | Mozilla FirefoxMozilla SeamonkeyOracle SolarisFedoraproject Fedora+5 | 11/12/2013 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | |
| Modificada | Crítica (9.8) | 8.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 11/12/2013 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown… | |
| Modificada | Media (4.3) | 2.3% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Studio OnsiteNovell Suse Linux Enterprise DebuginfoGraphicsmagick+1 | 23/11/2013 | 16/6/2026 | The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image. | |
| Modificada | Media (6.8) | 0.75% | — | LibguestfsSuse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Server | 5/11/2013 | 16/6/2026 | The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by… | |
| Modificada | Alta (7.5) | 13% | — | Apache MOD FcgidDebian LinuxSuse CloudOpensuse+1 | 17/10/2013 | 16/6/2026 | Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors. | |
| Modificada | Alta (7.8) | 34% | — | ISC BindSuse Linux Enterprise Software Development KITNovell Suse LinuxISC Dnsco Bind+8 | 29/7/2013 | 16/6/2026 | The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA… | |
| Modificada | Baja (3.5) | 2.8% | — | Oracle SolarisOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+5 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication. | |
| Modificada | Media (4) | 2.6% | — | Oracle MysqlOracle SolarisOpensuseSuse Linux Enterprise Desktop+4 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Audit Log. | |
| Modificada | Media (4) | 2.8% | — | Oracle MysqlMariadbOpensuseSuse Linux Enterprise Desktop+2 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options. | |
| Modificada | Media (4) | 2.4% | — | Oracle MysqlOracle SolarisSuse Linux Enterprise DesktopSuse Linux Enterprise Server+3 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Prepared Statements. | |
| Modificada | Media (4) | 3.0% | — | Oracle MysqlDebian LinuxCanonical Ubuntu LinuxMariadb+4 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer. |