Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
681 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 3.8% | — | GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+10 | 5/6/2014 | 17/6/2026 | The (1) asn1_read_value_type and (2) asn1_read_value functions in GNU Libtasn1 before 3.6 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via a NULL value in an ivalue argument. | |
| Modificada | Alta (7.5) | 3.8% | — | GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+11 | 5/6/2014 | 17/6/2026 | The asn1_get_bit_der function in GNU Libtasn1 before 3.6 does not properly report an error when a negative bit length is identified, which allows context-dependent attackers to cause out-of-bounds access via crafted ASN.1 data. | |
| Modificada | Media (5) | 6.8% | — | GnutlsGNU Libtasn1Redhat VirtualizationDebian Linux+11 | 5/6/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in the DER decoder in GNU Libtasn1 before 3.6, as used in GnuTLS, allow remote attackers to cause a denial of service (out-of-bounds read) via crafted ASN.1 data. | |
| Modificada | Baja (2.1) | 0.51% | — | Linux KernelRedhat Enterprise Linux EUSDebian LinuxOracle Linux+4 | 11/5/2014 | 17/6/2026 | The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device. | |
| Modificada | Alta (7.2) | 0.45% | — | Linux KernelOracle LinuxDebian LinuxSuse Linux Enterprise Desktop+4 | 11/5/2014 | 17/6/2026 | The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device. | |
| Analizada | Media (5.5) | 22% | ⚠ Explotación activa💥 Exploit | Linux KernelDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUS+26 | 7/5/2014 | 17/6/2026 | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and… | |
| Modificada | Media (4.3) | 44% | — | OpensslMariadbFedoraproject FedoraDebian Linux+5 | 6/5/2014 | 17/6/2026 | The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger… | |
| Modificada | Crítica (9.8) | 4.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+11 | 30/4/2014 | 17/6/2026 | Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption)… | |
| Modificada | Alta (8.8) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+11 | 30/4/2014 | 17/6/2026 | Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors… | |
| Modificada | Media (6.1) | 1.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+11 | 30/4/2014 | 17/6/2026 | The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs… | |
| Modificada | Alta (8.8) | 3.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+11 | 30/4/2014 | 17/6/2026 | The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code in a privileged context via a crafted web page for which… | |
| Modificada | Crítica (9.8) | 7.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+11 | 30/4/2014 | 17/6/2026 | The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether objects are XBL objects, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer… | |
| Modificada | Media (6.5) | 3.2% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+11 | 30/4/2014 | 17/6/2026 | Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image. | |
| Modificada | Alta (8.8) | 6.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+11 | 30/4/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown… | |
| Modificada | Baja (2.1) | 0.54% | — | Linux KernelOpensuse EvergreenRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 27/4/2014 | 17/6/2026 | The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a… | |
| Modificada | Alta (7.1) | 4.3% | — | Linux KernelOracle LinuxSuse Linux Enterprise High Availability ExtensionSuse Linux Enterprise Desktop+1 | 14/4/2014 | 17/6/2026 | Race condition in the mac80211 subsystem in the Linux kernel before 3.13.7 allows remote attackers to cause a denial of service (system crash) via network traffic that improperly interacts with the WLAN_STA_PS_STA state (aka power-save mode), related to sta_info.c and tx.c. | |
| Modificada | Media (4) | 34% | — | OpensslMariadbFedoraproject FedoraSuse Linux Enterprise Desktop+3 | 14/4/2014 | 16/6/2026 | Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment. | |
| Modificada | Baja (2.9) | 0.68% | — | Linux KernelOpensuse EvergreenSuse Linux Enterprise Server | 24/3/2014 | 17/6/2026 | Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. | |
| Modificada | Media (4.3) | 20% | — | PHPCanonical Ubuntu LinuxSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+8 | 21/3/2014 | 17/6/2026 | The gdImageCreateFromXpm function in gdxpm.c in libgd, as used in PHP 5.4.26 and earlier, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted color table in an XPM file. | |
| Modificada | Crítica (9.8) | 6.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+12 | 19/3/2014 | 17/6/2026 | vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds… | |
| Modificada | Alta (8.8) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+12 | 19/3/2014 | 17/6/2026 | TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayBuffer object, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based… | |
| Modificada | Alta (10) | 29% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+12 | 19/3/2014 | 17/6/2026 | Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary code by triggering extensive memory consumption while garbage collection is… | |
| Modificada | Crítica (9.8) | 84% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+12 | 19/3/2014 | 17/6/2026 | Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors. | |
| Modificada | Crítica (9.8) | 82% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+12 | 19/3/2014 | 17/6/2026 | The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call. | |
| Modificada | Alta (8.8) | 5.0% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdRedhat Enterprise Linux Desktop+11 | 19/3/2014 | 17/6/2026 | Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a crafted extension that renders fonts in a PDF document. |