Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

519 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)3.8%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+1021/11/201216/6/2026
Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 on Mac OS X allows remote attackers to execute arbitrary code via an HTML document.
ModificadaMedia (6.4)8.8%—Linux KernelNovell Suse Linux Enterprise Server21/6/201216/6/2026
The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a…
ModificadaAlta (7.8)4.2%—Novell Suse Linux Enterprise ServerLinux Kernel21/6/201216/6/2026
The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to…
ModificadaBaja (1.2)0.56%—Linux KernelNovell Suse Linux Enterprise ServerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+413/6/201216/6/2026
The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call.
ModificadaMedia (6.8)73%💥 PoCGoogle ChromeApple Iphone OSApple MAC OS XApple MAC OS X Server+316/2/201216/6/2026
Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation.
ModificadaBaja (2.1)0.38%—Rubyforge Rubygem-sqlite3Novell Suse Linux Enterprise13/5/201116/6/2026
The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
ModificadaMedia (4.4)0.34%—Pureftpd Pure-ftpdNovell Suse Linux18/4/201116/6/2026
pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors.
ModificadaAlta (10)2.1%—Novell Suse Linux13/1/201116/6/2026
The supportconfig script in supportutils in SUSE Linux Enterprise 11 SP1 and 10 SP3 does not "disguise passwords" in configuration files, which has unknown impact and attack vectors.
ModificadaBaja (2.1)0.46%—Linux KernelRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationSuse Linux Enterprise Desktop+223/12/201016/6/2026
arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device.
ModificadaAlta (7.5)5.9%—Google ChromeXmlsoft Libxml2Apple ItunesApple Safari+137/12/201016/6/2026
Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
ModificadaMedia (4.3)2.7%—Google ChromeApple ItunesApple SafariApple Iphone OS+1117/11/201016/6/2026
libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML…
ModificadaAlta (7.2)0.38%—Novell Suse LinuxOpensuse12/10/201016/6/2026
Multiple buffer overflows in the Novell Client novfs module for the Linux kernel in SUSE Linux Enterprise 11 SP1 and openSUSE 11.3 allow local users to gain privileges via unspecified vectors.
ModificadaAlta (7.1)0.39%—Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise High Availability ExtensionSuse Linux Enterprise Desktop+130/9/201016/6/2026
The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor.
ModificadaAlta (7.8)3.5%💥 ExploitLinux KernelVmware ESXSuse Linux Enterprise DesktopSuse Linux Enterprise Server24/9/201016/6/2026
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privileges by leveraging the ability of the compat_mc_getsockopt…
ModificadaMedia (5.5)0.41%—Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+221/9/201016/6/2026
The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl call.
ModificadaMedia (5.5)0.42%—Linux KernelCanonical Ubuntu LinuxOpensuseSuse Linux Enterprise Desktop+921/9/201016/6/2026
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the…
ModificadaAlta (7.8)0.51%—Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server8/9/201016/6/2026
The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a…
ModificadaAlta (7.8)0.41%—Linux KernelVmware ESXCanonical Ubuntu LinuxDebian Linux+118/9/201016/6/2026
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by…
ModificadaAlta (7.8)0.42%—Linux KernelVmware ESXCanonical Ubuntu LinuxSuse Linux Enterprise Desktop+18/9/201016/6/2026
The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof the results of DNS queries and perform arbitrary CIFS…
ModificadaAlta (10)2.9%—Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+18/9/201016/6/2026
The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via…
ModificadaMedia (5.5)0.38%—Linux KernelVmware ESXCanonical Ubuntu LinuxSuse Linux Enterprise High Availability Extension+28/9/201016/6/2026
The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor.
ModificadaMedia (5)2.1%—Novell Suse Linux3/9/201016/6/2026
WebYaST in yast2-webclient in SUSE Linux Enterprise (SLE) 11 on the WebYaST appliance uses a fixed secret key that is embedded in the appliance's image, which allows remote attackers to spoof session cookies by leveraging knowledge of this key.
ModificadaAlta (10)3.0%—Google ChromeOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server15/6/201016/6/2026
Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remote fonts in conjunction with shadow DOM trees, aka rdar problem 8007953. NOTE: this might overlap…
ModificadaMedia (4.3)1.3%—Google ChromeOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server15/6/201016/6/2026
Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA element. NOTE: this might overlap CVE-2010-1762.
ModificadaAlta (9.3)2.8%—Google ChromeOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server15/6/201016/6/2026
rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that has a large colspan attribute within a table.
Orbitaley — Vulnerabilidades