Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 88% | 💥 PoC | OpensslRedhat StorageFedoraproject FedoraRedhat Enterprise Linux+7 | 5/6/2014 | 17/6/2026 | The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake. | |
| Modificada | Media (5) | 3.8% | — | GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+10 | 5/6/2014 | 17/6/2026 | The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument. | |
| Modificada | Alta (7.5) | 3.8% | — | GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+11 | 5/6/2014 | 17/6/2026 | The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data. | |
| Modificada | Media (5) | 6.8% | — | GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+11 | 5/6/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data. | |
| Modificada | Baja (3.3) | 0.36% | — | Suse Linux Enterprise DesktopRedhat Enterprise LinuxRedhat Enterprise MRGLinux Kernel | 5/6/2014 | 17/6/2026 | kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number. | |
| Modificada | Media (4.3) | 2.9% | — | Opalvoip Portable Tool LibraryEkigaSuse Linux Enterprise Software Development KITSuse Linux Enterprise Desktop | 23/5/2014 | 16/6/2026 | The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka… | |
| Modificada | Baja (2.1) | 0.51% | — | Linux KernelRedhat Enterprise Linux EUSDebian LinuxOracle Linux+4 | 11/5/2014 | 17/6/2026 | The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device. | |
| Modificada | Alta (7.2) | 0.45% | — | Linux KernelOracle LinuxDebian LinuxSuse Linux Enterprise Desktop+4 | 11/5/2014 | 17/6/2026 | The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device. | |
| Analizada | Media (5.5) | 22% | ⚠ Explotación activa💥 Exploit | Linux KernelDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUS+26 | 7/5/2014 | 17/6/2026 | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and… | |
| Modificada | Media (4.3) | 44% | — | OpensslMariadbFedoraproject FedoraDebian Linux+5 | 6/5/2014 | 17/6/2026 | The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger… | |
| Modificada | Alta (7.1) | 4.3% | — | Linux KernelOracle LinuxSuse Linux Enterprise High Availability ExtensionSuse Linux Enterprise Desktop+1 | 14/4/2014 | 17/6/2026 | Race condition in the mac80211 subsystem in the Linux kernel before 3.13.7 allows remote attackers to cause a denial of service (system crash) via network traffic that improperly interacts with the WLAN_STA_PS_STA state (aka power-save mode), related to sta_info.c and tx.c. | |
| Modificada | Media (4) | 34% | — | OpensslMariadbFedoraproject FedoraSuse Linux Enterprise Desktop+3 | 14/4/2014 | 16/6/2026 | Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment. | |
| Modificada | Crítica (9.8) | 6.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+12 | 19/3/2014 | 17/6/2026 | vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds… | |
| Modificada | Alta (8.8) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+12 | 19/3/2014 | 17/6/2026 | TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayBuffer object, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based… | |
| Modificada | Alta (10) | 29% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+12 | 19/3/2014 | 17/6/2026 | Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary code by triggering extensive memory consumption while garbage collection is… | |
| Modificada | Crítica (9.8) | 84% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+12 | 19/3/2014 | 17/6/2026 | Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors. | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+12 | 19/3/2014 | 17/6/2026 | The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call. | |
| Modificada | Alta (8.8) | 5.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdRedhat Enterprise Linux Desktop+11 | 19/3/2014 | 17/6/2026 | Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a crafted extension that renders fonts in a PDF document. | |
| Modificada | Crítica (9.1) | 4.3% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdRedhat Enterprise Linux Desktop+12 | 19/3/2014 | 17/6/2026 | The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of service (out-of-bounds read and application crash), or possibly… | |
| Modificada | Alta (7.5) | 4.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+12 | 19/3/2014 | 17/6/2026 | The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing… | |
| Modificada | Baja (2.6) | 2.1% | — | Mozilla FirefoxMozilla SeamonkeyOpensuseOracle Solaris+3 | 19/3/2014 | 17/6/2026 | The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document that is accessed after a browser restart. | |
| Modificada | Media (6.8) | 1.2% | — | OpensuseOpensuse Project OpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+4 | 19/3/2014 | 17/6/2026 | The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors. | |
| Modificada | Media (5.8) | 1.6% | — | Oracle SolarisMozilla FirefoxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 19/3/2014 | 17/6/2026 | Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection. | |
| Modificada | Media (5) | 3.6% | — | OpensuseOpensuse Project OpensuseOracle SolarisMozilla Firefox+4 | 19/3/2014 | 17/6/2026 | Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution. | |
| Modificada | Media (4.3) | 1.9% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITMozilla Seamonkey+4 | 19/3/2014 | 17/6/2026 | Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt. |