Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
937 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 59% | — | ISC BindSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+10 | 9/3/2016 | 17/6/2026 | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to… | |
| Modificada | Crítica (9.8) | 2.6% | — | Google ChromeNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse+1 | 21/2/2016 | 17/6/2026 | Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors. | |
| Modificada | Alta (8.1) | 91% | 💥 Exploit | Debian LinuxCanonical Ubuntu LinuxHP Helion OpenstackHP Server Migration Pack+26 | 18/2/2016 | 17/6/2026 | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the… | |
| Analizada | Alta (7.5) | 96% | ⚠ Explotación activa💥 Exploit | Rubyonrails RailsOpensuse LeapOpensuseSuse Linux Enterprise Module FOR Containers+2 | 16/2/2016 | 17/6/2026 | Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application's unrestricted use of the render method and providing a .. (dot dot) in a… | |
| Modificada | Media (6.2) | 0.57% | — | Linux KernelSuse Linux Enterprise Real Time Extension | 8/2/2016 | 17/6/2026 | The fuse_fill_write_pages function in fs/fuse/file.c in the Linux kernel before 4.4 allows local users to cause a denial of service (infinite loop) via a writev system call that triggers a zero length for the first segment of an iov. | |
| Modificada | Alta (7.8) | 0.42% | — | Canonical Ubuntu LinuxSuse Linux Enterprise Real Time ExtensionLinux Kernel | 8/2/2016 | 17/6/2026 | The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c. | |
| Modificada | Media (4.6) | 1.8% | 💥 Exploit | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Real Time ExtensionNovell Suse Linux Enterprise Server+1 | 8/2/2016 | 17/6/2026 | The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a bulk-out endpoint. | |
| Analizada | Alta (8.8) | 68% | ⚠ Explotación activa | Adobe AIR SDKAdobe AIR SDK & CompilerAdobe Flash PlayerAdobe AIR+13 | 28/12/2015 | 17/6/2026 | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified… | |
| Modificada | Baja (2.1) | 0.48% | — | IBM Java 2 SDKIBM Java SDKRedhat SatelliteRedhat Enterprise Linux Desktop+5 | 7/12/2015 | 17/6/2026 | IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR2, 7 R1 before SR3 FP20, 7 before SR9 FP20, 6 R1 before SR8 FP15, and 6 before SR16 FP15 allow physically proximate attackers to obtain sensitive information by reading the Kerberos Credential Cache. | |
| Modificada | Media (5.3) | 39% | 💥 PoC | Apple MAC OS XOracle API GatewayOracle Communications Webrtc Session ControllerOracle Exalogic Infrastructure+21 | 6/12/2015 | 17/6/2026 | The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1q, and 1.0.2 before 1.0.2e mishandles errors caused by malformed X509_ATTRIBUTE data, which allows remote attackers to obtain sensitive information from process memory by triggering a… | |
| Modificada | Media (5) | 5.1% | — | Gnome NetworkmanagerSuse Linux Enterprise DebuginfoSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+5 | 17/11/2015 | 17/6/2026 | GNOME NetworkManager allows remote attackers to cause a denial of service (IPv6 traffic disruption) via a crafted MTU value in an IPv6 Router Advertisement (RA) message, a different vulnerability than CVE-2015-8215. | |
| Modificada | Alta (7.5) | 10% | — | LibpngFedoraproject FedoraOpensuse LeapOpensuse+16 | 13/11/2015 | 17/6/2026 | Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other… | |
| Modificada | Media (4) | 4.1% | — | MIT Kerberos 5Oracle SolarisCanonical Ubuntu LinuxDebian Linux+5 | 9/11/2015 | 17/6/2026 | The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request. | |
| Modificada | Alta (7.1) | 4.5% | — | MIT Kerberos 5Opensuse LeapOpensuseSuse Linux Enterprise Desktop+4 | 9/11/2015 | 17/6/2026 | lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mishandled during a gss_inquire_context call. | |
| Modificada | Media (5) | 6.2% | — | MIT Kerberos 5Oracle SolarisCanonical Ubuntu LinuxDebian Linux+5 | 9/11/2015 | 17/6/2026 | lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call. | |
| Modificada | Alta (7.5) | 3.5% | — | QemuDebian LinuxFedoraproject FedoraSuse Linux Enterprise Desktop+3 | 6/11/2015 | 17/6/2026 | hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error… | |
| Analizada | Media (5.3) | 14% | ⚠ Explotación activa | Oracle JDKOracle JRERedhat SatelliteRedhat Enterprise Linux Desktop+17 | 22/10/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60 allows remote attackers to affect integrity via unknown vectors related to Deployment. | |
| Modificada | Media (4) | 3.0% | — | Oracle SolarisOracle MysqlMariadbCanonical Ubuntu Linux+13 | 21/10/2015 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges. | |
| Modificada | Media (4.9) | 0.68% | — | Novell Suse Linux Enterprise Real Time ExtensionRedhat Enterprise Linux | 19/10/2015 | 17/6/2026 | The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor. | |
| Modificada | Media (4.6) | 0.49% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Desktop+1 | 19/10/2015 | 17/6/2026 | Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request. | |
| Analizada | Alta (7.8) | 65% | ⚠ Explotación activa💥 Exploit | Adobe Flash PlayerOpensuse EvergreenOpensuseSuse Linux Enterprise Desktop+6 | 15/10/2015 | 17/6/2026 | Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015. | |
| Modificada | Media (6.8) | 5.0% | — | Suse Linux Enterprise DebuginfoSuse Linux Enterprise DesktopSuse Linux Enterprise ServerGNU Glibc+2 | 28/9/2015 | 17/6/2026 | Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer. | |
| Modificada | Alta (9.3) | 13% | — | XENFedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise Server+20 | 12/8/2015 | 17/6/2026 | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.63% | — | XENSuse Linux Enterprise DebuginfoSuse Linux Enterprise DesktopSuse Linux Enterprise Server+4 | 12/8/2015 | 17/6/2026 | Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands. | |
| Analizada | Alta (8.8) | 69% | ⚠ Explotación activa💥 Exploit | Mozilla FirefoxMozilla Firefox OSOracle SolarisCanonical Ubuntu Linux+11 | 8/8/2015 | 17/6/2026 | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015. |