Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2507▼ 423 respecto a la semana anterior
Críticas / altas1283▲ 4 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 4.1% | — | Nodejs Node.jsSuse Linux Enterprise | 10/10/2016 | 17/6/2026 | CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument. | |
| Modificada | Crítica (9.8) | 8.6% | — | C-aresC-ares Project C-aresDebian LinuxNodejs Node.js+1 | 3/10/2016 | 17/6/2026 | Heap-based buffer overflow in the ares_create_query function in c-ares 1.x before 1.12.0 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly execute arbitrary code via a hostname with an escaped trailing dot. | |
| Modificada | Alta (7.5) | 29% | — | Novell Suse Linux Enterprise Module FOR WEB ScriptingOpensslNodejs Node.js | 26/9/2016 | 17/6/2026 | crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation. | |
| Modificada | Media (5.9) | 42% | — | OpensslHP Icewall Federation AgentHP Icewall McrpHP Icewall SSO+5 | 26/9/2016 | 17/6/2026 | The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c. | |
| Modificada | Alta (7.5) | 63% | — | OpensslNodejs Node.jsNovell Suse Linux Enterprise Module FOR WEB Scripting | 26/9/2016 | 17/6/2026 | Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions. | |
| Modificada | Media (6.5) | 1.9% | — | Google ChromeNodejs Node.jsDebian Linux | 25/9/2016 | 17/6/2026 | The parser in Google V8, as used in Google Chrome before 53.0.2785.113, mishandles scopes, which allows remote attackers to obtain sensitive information from arbitrary memory locations via crafted JavaScript code. | |
| Modificada | Crítica (9.8) | 32% | — | Nodejs Node.jsOpenssl | 16/9/2016 | 17/6/2026 | Integer overflow in the MDC2_Update function in crypto/mdc2/mdc2dgst.c in OpenSSL before 1.1.0 allows remote attackers to cause a denial of service (out-of-bounds write and application crash) or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Alta (7.5) | 95% | — | Redhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB ServerRedhat Jboss WEB ServerRedhat Enterprise Linux+5 | 1/9/2016 | 17/6/2026 | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated… | |
| Modificada | Alta (7.5) | 6.7% | — | IBM SDKNodejs Node.jsNpmjs NPM | 2/7/2016 | 17/6/2026 | The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, includes bearer tokens with arbitrary requests, which allows remote HTTP servers to obtain sensitive information by reading Authorization headers. | |
| Modificada | Media (5.5) | 1.2% | — | OpensslOracle LinuxOracle SolarisSuse Linux Enterprise+3 | 20/6/2016 | 17/6/2026 | The dsa_sign_setup function in crypto/dsa/dsa_ossl.c in OpenSSL through 1.0.2h does not properly ensure the use of constant-time operations, which makes it easier for local users to discover a DSA private key via a timing side-channel attack. | |
| Modificada | Alta (8.8) | 4.2% | — | Debian LinuxGoogle ChromeOpensuseGoogle V8+2 | 14/5/2016 | 17/6/2026 | The Zone::New function in zone.cc in Google V8 before 5.0.71.47, as used in Google Chrome before 50.0.2661.102, does not properly determine when to expand certain memory allocations, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via crafted… | |
| Modificada | Media (5.9) | 89% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+11 | 5/5/2016 | 17/6/2026 | The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an… | |
| Modificada | Alta (7.5) | 40% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+11 | 5/5/2016 | 17/6/2026 | Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data. | |
| Modificada | Alta (7.5) | 7.3% | — | Nodejs Node.jsFedoraproject Fedora | 7/4/2016 | 17/6/2026 | The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a. | |
| Modificada | Alta (7.5) | 6.3% | — | Nodejs Node.jsFedoraproject Fedora | 7/4/2016 | 17/6/2026 | Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header. | |
| Modificada | Alta (7.5) | 27% | — | OpensslNodejs Node.jsCanonical Ubuntu LinuxDebian Linux | 3/3/2016 | 17/6/2026 | Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified other impact via a long digit string that is mishandled by the (1) BN_dec2bn or (2) BN_hex2bn function,… | |
| Modificada | Media (5.1) | 1.9% | — | OpensslNodejs Node.jsDebian LinuxCanonical Ubuntu Linux | 3/3/2016 | 17/6/2026 | The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy… | |
| Modificada | Alta (7.5) | 5.4% | — | Nodejs Node.js | 2/1/2016 | 17/6/2026 | Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request. | |
| Modificada | Alta (7.5) | 44% | — | OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js | 6/12/2015 | 17/6/2026 | crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter. | |
| Modificada | Alta (7.5) | 25% | — | OpensslNodejs Node.jsCanonical Ubuntu Linux | 6/12/2015 | 17/6/2026 | The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for remote attackers to obtain sensitive private-key information via an… | |
| Modificada | Crítica (9.8) | 5.7% | — | Google ChromeNodejs Node.jsDebian Linux | 6/12/2015 | 17/6/2026 | The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other… | |
| Modificada | Alta (7.5) | 3.0% | — | Google V8Iojs Io.jsNodejs Node.js | 9/7/2015 | 17/6/2026 | The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory… | |
| Modificada | Alta (10) | 3.2% | — | Fedoraproject FedoraLibuv Project LibuvNodejs Node.js | 18/5/2015 | 17/6/2026 | libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors. | |
| Modificada | Media (5) | 8.3% | — | Nodejs Node.js | 19/10/2014 | 17/6/2026 | The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array. | |
| Modificada | Media (5) | 3.3% | — | Nodejs | 5/9/2014 | 17/6/2026 | Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that triggers V8 garbage collection in conjunction with a V8 interrupt, which allows remote attackers to cause a denial of service (memory corruption and application crash) via deep JSON objects whose parsing… |