Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

644 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.5)3.1%—Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraOracle Solaris+1221/1/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Foreign Key.
ModificadaAlta (10)6.9%—Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+421/1/201517/6/2026
Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot.
ModificadaBaja (3.5)7.1%—Canonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+1221/1/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.
ModificadaBaja (2.1)0.56%—Linux KernelRedhat Enterprise Linux AUSRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+159/1/201517/6/2026
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.
ModificadaBaja (2.1)0.46%—Linux KernelRedhat Enterprise Linux AUSRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+159/1/201517/6/2026
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.
ModificadaMedia (5)9.7%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerMuttDebian Linux+12/12/201417/6/2026
The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function.
ModificadaMedia (5)3.7%—QemuDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+714/11/201417/6/2026
The set_pixel_format function in ui/vnc.c in QEMU allows remote attackers to cause a denial of service (crash) via a small bytes_per_pixel value.
ModificadaMedia (5.5)0.74%—Linux KernelCanonical Ubuntu LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+710/11/201417/6/2026
The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.
ModificadaMedia (5.5)0.52%—Linux KernelNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse Evergreen+610/11/201417/6/2026
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm…
ModificadaAlta (7.5)8.6%—Linux KernelRedhat Enterprise MRGCanonical Ubuntu LinuxDebian Linux+810/11/201417/6/2026
The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter.
ModificadaMedia (4)2.4%—Oracle MysqlSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+215/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:INNODB FULLTEXT SEARCH DML.
ModificadaMedia (4.3)4.6%—Juniper Junos SpaceMariadbOracle SolarisOracle Mysql+415/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect confidentiality via vectors related to C API SSL CERTIFICATE HANDLING.
ModificadaMedia (6.5)3.9%—MariadbOracle MysqlSuse Linux Enterprise DesktopSuse Linux Enterprise Server+215/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.
ModificadaBaja (2.1)0.39%—Oracle SolarisOracle MysqlMariadbSuse Linux Enterprise Desktop+315/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier and 5.6.19 and earlier allows local users to affect confidentiality via vectors related to CLIENT:MYSQLADMIN.
ModificadaMedia (6.5)2.7%—Oracle SolarisOracle MysqlMariadbSuse Linux Enterprise Desktop+315/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to CLIENT:MYSQLDUMP.
ModificadaMedia (4)2.6%—Oracle MysqlSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+215/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:DDL.
ModificadaMedia (4.3)7.3%—MariadbOracle SolarisOracle MysqlSuse Linux Enterprise Desktop+315/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.
ModificadaMedia (4)2.7%—Oracle MysqlSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+215/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to SERVER:MEMORY STORAGE ENGINE.
ModificadaMedia (4.3)4.3%—Juniper Junos SpaceOracle SolarisMariadbOracle Mysql+415/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6494.
ModificadaMedia (4.3)3.0%—Oracle MysqlOracle SolarisJuniper Junos SpaceMariadb+415/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect availability via vectors related to SERVER:SSL:yaSSL.
ModificadaMedia (4.3)4.8%—MariadbOracle SolarisJuniper Junos SpaceOracle Mysql+415/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote attackers to affect availability via vectors related to CLIENT:SSL:yaSSL, a different vulnerability than CVE-2014-6496.
ModificadaMedia (4)2.7%—Oracle MysqlSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+215/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to SERVER:DML.
ModificadaMedia (4.3)2.6%—Juniper Junos SpaceOracle MysqlOracle SolarisMariadb+415/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote attackers to affect integrity via vectors related to SERVER:SSL:yaSSL.
ModificadaBaja (3.5)1.4%—Oracle MysqlMariadbSuse Linux Enterprise DesktopSuse Linux Enterprise Server+215/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.6.19 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:MEMCACHED.
ModificadaMedia (6.8)4.4%—MariadbOracle MysqlOracle SolarisSuse Linux Enterprise Desktop+315/10/201417/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier and 5.6.20 and earlier allows remote authenticated users to affect availability via vectors related to SERVER:OPTIMIZER.