Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 7.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+10 | 29/8/2012 | 16/6/2026 | Heap-based buffer overflow in the nsBlockFrame::MarkLineDirty function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 5.4% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+10 | 29/8/2012 | 16/6/2026 | Use-after-free vulnerability in the MediaStreamGraphThreadRunnable::Run function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap… | |
| Modificada | Alta (10) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+10 | 29/8/2012 | 16/6/2026 | Use-after-free vulnerability in the nsHTMLSelectElement::SubmitNamesValues function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap… | |
| Modificada | Alta (10) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+11 | 29/8/2012 | 16/6/2026 | Use-after-free vulnerability in the PresShell::CompleteMove function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory… | |
| Modificada | Alta (10) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+11 | 29/8/2012 | 16/6/2026 | Use-after-free vulnerability in the gfxTextRun::CanBreakLineBefore function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory… | |
| Modificada | Alta (10) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+11 | 29/8/2012 | 16/6/2026 | Use-after-free vulnerability in the nsObjectLoadingContent::LoadObject function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap… | |
| Modificada | Alta (10) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+11 | 29/8/2012 | 16/6/2026 | Use-after-free vulnerability in the nsHTMLEditor::CollapseAdjacentTextNodes function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service… | |
| Modificada | Alta (10) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+11 | 29/8/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly… | |
| Modificada | Baja (2.1) | 0.48% | — | Oracle JREOracle JDKRedhat Icedtea6Redhat Satellite With Embedded Oracle+13 | 16/6/2012 | 16/6/2026 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown vectors related to printing on Solaris or Linux. | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | SUN JREOracle JREDebian LinuxSuse Linux Enterprise Desktop+3 | 7/6/2012 | 14/8/2026 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Update 30 and earlier, and 5.0 Update 33 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Concurrency. NOTE: the previous… | |
| Modificada | Alta (9.3) | 4.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdOpensuse+9 | 5/6/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 13.0, Thunderbird before 13.0, and SeaMonkey before 2.10 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1)… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | PHPFedoraproject FedoraDebian LinuxHp-ux+13 | 11/5/2012 | 16/6/2026 | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of… | |
| Modificada | Media (4.3) | 1.7% | — | Google ChromeXmlsoft LibxsltSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 9/2/2012 | 16/6/2026 | libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | |
| Modificada | Alta (9.3) | 5.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+4 | 1/2/2012 | 16/6/2026 | Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document. | |
| Modificada | Alta (10) | 7.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+5 | 1/2/2012 | 16/6/2026 | Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via… | |
| Modificada | Alta (9.3) | 4.5% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+4 | 1/2/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via… | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdOpensuse+3 | 1/2/2012 | 16/6/2026 | Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed… | |
| Modificada | Media (4.3) | 82% | 💥 Exploit | Apache Http ServerDebian LinuxOpensuseSuse Linux Enterprise Server+7 | 28/1/2012 | 16/6/2026 | protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with… | |
| Modificada | Media (4.6) | 2.8% | 💥 Exploit | Apache Http ServerDebian LinuxOpensuseSuse Linux Enterprise Server+8 | 18/1/2012 | 16/6/2026 | scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function. | |
| Modificada | Alta (10) | 95% | 💥 Exploit | GNU InetutilsHeimdal Project HeimdalMIT Krb5-applFreebsd+6 | 25/12/2011 | 16/6/2026 | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the… | |
| Modificada | Media (6.8) | 10% | — | Jasper Project JasperOracle Outside IN TechnologyCanonical Ubuntu LinuxDebian Linux+5 | 15/12/2011 | 16/6/2026 | The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component… | |
| Modificada | Media (6.8) | 10% | — | Jasper Project JasperOracle Outside IN TechnologyCanonical Ubuntu LinuxDebian Linux+4 | 15/12/2011 | 16/6/2026 | Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file. | |
| Modificada | Alta (9.3) | 5.3% | — | Apple Iphone OSSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT | 11/11/2011 | 16/6/2026 | FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document. | |
| Modificada | Alta (7.8) | 99% | 💥 Exploit | Apache Http ServerOpensuseSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+1 | 29/8/2011 | 16/6/2026 | The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than… | |
| Modificada | Media (6.5) | 3.9% | — | MIT Krb5-applDebian LinuxFedoraproject FedoraOpensuse+3 | 11/7/2011 | 16/6/2026 | ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related… |