Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
519 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+12 | 19/3/2014 | 17/6/2026 | The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing… | |
| Modificada | Alta (8.8) | 2.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+12 | 19/3/2014 | 17/6/2026 | The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause a denial of service (out-of-bounds read and application crash), or… | |
| Modificada | Media (5.5) | 0.38% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdSuse Linux Enterprise Software Development KIT+2 | 19/3/2014 | 17/6/2026 | Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update. | |
| Modificada | Crítica (9.8) | 8.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+12 | 19/3/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown… | |
| Modificada | Alta (7.5) | 2.3% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+13 | 6/2/2014 | 17/6/2026 | The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages. | |
| Modificada | Crítica (9.8) | 7.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 6/2/2014 | 17/6/2026 | Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unspecified Content-Type values for image data. | |
| Modificada | Media (5) | 2.5% | — | Oracle SolarisCanonical Ubuntu LinuxMozilla FirefoxMozilla Seamonkey+4 | 6/2/2014 | 17/6/2026 | Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same Origin Policy and obtain sensitive information by using an IFRAME element in conjunction with certain timing measurements involving the document.caretPositionFromPoint and document.elementFromPoint functions. | |
| Modificada | Alta (8.8) | 6.3% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+13 | 6/2/2014 | 17/6/2026 | RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as… | |
| Modificada | Alta (7.5) | 3.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+13 | 6/2/2014 | 17/6/2026 | Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines. | |
| Modificada | Alta (7.5) | 4.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+13 | 6/2/2014 | 17/6/2026 | The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remote attackers to bypass intended restrictions on XUL content via vectors involving XBL content… | |
| Modificada | Crítica (9.8) | 5.5% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+13 | 6/2/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown… | |
| Modificada | Media (5.9) | 2.9% | — | Fedoraproject FedoraMozilla FirefoxMozilla SeamonkeyMozilla Thunderbird+5 | 11/12/2013 | 17/6/2026 | Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it easier for man-in-the-middle attackers to spoof SSL servers in opportunistic circumstances via a valid certificate that… | |
| Modificada | Crítica (9.8) | 11% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+12 | 11/12/2013 | 17/6/2026 | The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements. | |
| Modificada | Crítica (9.8) | 10% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 11/12/2013 | 16/6/2026 | Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper… | |
| Modificada | Crítica (9.8) | 6.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 11/12/2013 | 16/6/2026 | Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors… | |
| Modificada | Crítica (9.8) | 4.2% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+5 | 11/12/2013 | 16/6/2026 | The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions on the generation of GetElementIC typed array stubs, which has unspecified impact and remote attack vectors. | |
| Modificada | Crítica (9.8) | 9.4% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 11/12/2013 | 16/6/2026 | Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving… | |
| Modificada | Crítica (9.8) | 8.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 11/12/2013 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown… | |
| Modificada | Alta (7.2) | 0.30% | — | Novell Suse Linux Enterprise FOR SAP Applications | 2/12/2013 | 16/6/2026 | Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 allows local users to have an unspecified impact via vectors related to a tmp/ directory. | |
| Modificada | Media (4.3) | 2.3% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Studio OnsiteNovell Suse Linux Enterprise DebuginfoGraphicsmagick+1 | 23/11/2013 | 16/6/2026 | The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image. | |
| Modificada | Media (6.8) | 0.75% | — | LibguestfsSuse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Server | 5/11/2013 | 16/6/2026 | The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by… | |
| Modificada | Alta (7.5) | 3.4% | — | PuppetPuppetlabs PuppetCanonical Ubuntu LinuxNovell Suse Linux Enterprise Desktop+2 | 19/8/2013 | 16/6/2026 | Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call. | |
| Modificada | Alta (7.8) | 34% | — | ISC BindSuse Linux Enterprise Software Development KITNovell Suse LinuxISC Dnsco Bind+8 | 29/7/2013 | 16/6/2026 | The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA… | |
| Modificada | Baja (3.3) | 0.49% | — | Linux KernelSuse Linux Enterprise Server | 8/6/2013 | 16/6/2026 | The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user. | |
| Modificada | Alta (10) | 6.2% | — | Adobe AIR SDKAdobe Flash PlayerAdobe AIRNovell Suse Linux Enterprise Desktop+1 | 10/4/2013 | 16/6/2026 | Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Adobe AIR before 3.7.0.1530; and Adobe AIR SDK & Compiler before 3.7.0.1530 do not… |