Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
844 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.2% | — | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 4/5/2017 | 17/6/2026 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file. | |
| Modificada | Crítica (9.8) | 2.3% | — | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 4/5/2017 | 17/6/2026 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out of Bounds Write on a Heap Buffer due to improper validation of dwCompressionSize of Microsoft WIM Header WIMHEADER_V1_PACKED. This vulnerability can be exploited to gain Remote… | |
| Modificada | Crítica (9.8) | 2.0% | — | Apple Quicktime | 24/4/2017 | 16/6/2026 | Buffer overflow in QuickTime before 7.7.1 for Windows allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 5.5% | 💥 Exploit | Quickheal Total Security | 20/4/2017 | 17/6/2026 | The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service. | |
| Modificada | Media (4.6) | 0.42% | — | Redhat Quickstart Cloud Installer | 14/4/2017 | 17/6/2026 | The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display. | |
| Modificada | Alta (7.5) | 1.4% | — | Intel Quickassist Technology Engine | 7/3/2017 | 17/6/2026 | The RSA-CRT implementation in the Intel QuickAssist Technology (QAT) Engine for OpenSSL versions prior to 0.5.19 may allow remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack. | |
| Modificada | Media (6.2) | 1.0% | — | Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware | 5/2/2017 | 17/6/2026 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. An attacker could request and download the SMS logs from an unauthenticated perspective. | |
| Modificada | Alta (7.5) | 1.8% | — | Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware | 5/2/2017 | 17/6/2026 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. The application failed to check the access control of the request which could result in an attacker being able to shutdown the system. | |
| Modificada | Crítica (9.8) | 2.4% | — | Sendquick Entera SMS Gateway FirmwareSendquick Avera SMS Gateway Firmware | 5/2/2017 | 17/6/2026 | An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands. | |
| Modificada | Alta (7.8) | 7.2% | 💥 Exploit | Libquicktime | 30/1/2017 | 17/6/2026 | Integer overflow in the quicktime_read_pascal function in libquicktime 1.2.4 and earlier allows remote attackers to cause a denial of service or possibly have other unspecified impact via a crafted hdlr MP4 atom. | |
| Modificada | Crítica (9.8) | 9.7% | 💥 PoC | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 2/1/2017 | 17/6/2026 | Stack-based buffer overflow in Quick Heal Internet Security 10.1.0.316 and earlier, Total Security 10.1.0.316 and earlier, and AntiVirus Pro 10.1.0.316 and earlier on OS X allows remote attackers to execute arbitrary code via a crafted LC_UNIXTHREAD.cmdsize field in a Mach-O file that is mishandled during a Security… | |
| Modificada | Alta (8.4) | 0.39% | — | Redhat Quickstart Cloud Installer | 22/9/2016 | 17/6/2026 | The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack. | |
| Modificada | Alta (8.4) | 0.39% | — | Redhat Quickstart Cloud Installer | 22/9/2016 | 17/6/2026 | Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file. | |
| Modificada | Media (6.6) | 1.7% | — | Apple Quicktime | 9/1/2016 | 17/6/2026 | Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, and… | |
| Modificada | Media (6.6) | 1.8% | — | Apple Quicktime | 9/1/2016 | 17/6/2026 | Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash) via a crafted TXXX frame within an ID3 tag in MP3 data in a movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087,… | |
| Modificada | Media (6.6) | 1.4% | — | Apple Quicktime | 9/1/2016 | 17/6/2026 | Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7092, and… | |
| Modificada | Media (6.6) | 1.6% | — | Apple Quicktime | 9/1/2016 | 17/6/2026 | Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7091, CVE-2015-7092, and… | |
| Modificada | Media (6.6) | 1.6% | — | Apple Quicktime | 9/1/2016 | 17/6/2026 | Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and… | |
| Modificada | Media (6.6) | 1.7% | — | Apple Quicktime | 9/1/2016 | 17/6/2026 | Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7087, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and… | |
| Modificada | Media (6.6) | 1.6% | — | Apple Quicktime | 9/1/2016 | 17/6/2026 | Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7086, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and… | |
| Modificada | Media (6.6) | 1.3% | — | Apple Quicktime | 9/1/2016 | 17/6/2026 | Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7085, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and… | |
| Modificada | Media (6.6) | 1.3% | — | Apple Quicktime | 9/1/2016 | 17/6/2026 | Apple QuickTime before 7.7.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file, a different vulnerability than CVE-2015-7086, CVE-2015-7087, CVE-2015-7088, CVE-2015-7089, CVE-2015-7090, CVE-2015-7091, CVE-2015-7092, and… | |
| Modificada | Baja (3.5) | 0.77% | — | Quick Edit Project Quick Edit | 31/8/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Quick Edit module 7.x-1.x before 7.x-1.2 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via an (1) entity title, related to in-place editing, or a (2) node title. | |
| Modificada | Media (6.8) | 3.2% | — | Apple Quicktime | 25/8/2015 | 17/6/2026 | Apple QuickTime before 7.7.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-5785. | |
| Modificada | Media (6.8) | 2.8% | — | Apple Quicktime | 25/8/2015 | 17/6/2026 | Apple QuickTime before 7.7.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted file, a different vulnerability than CVE-2015-5786. |