Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

4185 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.48%—Linux KernelOpensuse LeapCanonical Ubuntu Linux3/6/202017/6/2026
go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c in the Linux kernel before 5.6 does not call snd_card_free for a failure path, which causes a memory leak, aka CID-9453264ef586.
ModificadaAlta (7.5)4.5%—Websocket-extensions Project Websocket-extensionsDebian LinuxCanonical Ubuntu Linux2/6/202017/6/2026
websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whose content is a repeating two-byte sequence of a backslash and some other character. This could be…
ModificadaMedia (6.7)0.42%—QemuCanonical Ubuntu LinuxDebian Linux2/6/202017/6/2026
hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation.
ModificadaBaja (2.5)0.43%—QemuDebian LinuxOpensuse LeapCanonical Ubuntu Linux2/6/202017/6/2026
address_space_map in exec.c in QEMU 4.2.0 can trigger a NULL pointer dereference related to BounceBuffer.
ModificadaAlta (7.5)1.4%—Python-rsa Project Python-rsaFedoraproject FedoraCanonical Ubuntu Linux1/6/202017/6/2026
Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory…
ModificadaMedia (5.5)0.50%—Sane-project Sane BackendsFedoraproject FedoraDebian LinuxOpensuse Leap+11/6/202017/6/2026
A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075.
ModificadaBaja (3.2)0.38%—QemuDebian LinuxOpensuse LeapCanonical Ubuntu Linux28/5/202017/6/2026
In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user.
ModificadaBaja (3.9)0.37%—QemuDebian LinuxOpensuse LeapCanonical Ubuntu Linux28/5/202017/6/2026
In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation.
ModificadaMedia (5.3)0.49%—VIMDebian LinuxOpensuse LeapCanonical Ubuntu Linux+328/5/202017/6/2026
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
ModificadaMedia (6.5)2.0%—Gnome BalsaGnome Glib-networkingCanonical Ubuntu LinuxFedoraproject Fedora+228/5/202017/6/2026
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications…
ModificadaAlta (7.8)0.50%—SympaFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux27/5/202017/6/2026
Sympa before 6.2.56 allows privilege escalation.
ModificadaMedia (5.5)0.57%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+827/5/202017/6/2026
ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query.
ModificadaMedia (5.5)0.62%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+1427/5/202017/6/2026
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
ModificadaAlta (7)1.0%—SqliteFedoraproject FedoraCanonical Ubuntu LinuxNetapp Cloud Backup+1527/5/202017/6/2026
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
ModificadaMedia (5.5)0.43%—QemuCanonical Ubuntu LinuxDebian Linux27/5/202017/6/2026
sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process.
ModificadaCrítica (9.8)5.8%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux+226/5/202017/6/2026
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.
ModificadaMedia (5.5)0.35%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux26/5/202017/6/2026
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in the disclosure of local files. This vulnerability affects…
ModificadaCrítica (9.8)2.5%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdCanonical Ubuntu Linux26/5/202017/6/2026
Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.8,…
ModificadaMedia (5.5)0.43%—NetqmailDebian LinuxCanonical Ubuntu Linux26/5/202017/6/2026
qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its…
ModificadaAlta (7.5)1.8%—NetqmailDebian LinuxCanonical Ubuntu Linux26/5/202017/6/2026
qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.
ModificadaMedia (5.5)1.0%—SqliteDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+1124/5/202017/6/2026
SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c.
ModificadaMedia (4.3)0.61%—Mozilla ThunderbirdCanonical Ubuntu Linux22/5/202017/6/2026
By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0.
ModificadaAlta (8.3)2.3%💥 PoCFreerdpCanonical Ubuntu LinuxDebian LinuxOpensuse Leap22/5/202017/6/2026
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c.
ModificadaMedia (5.5)0.54%—FreerdpCanonical Ubuntu LinuxDebian LinuxOpensuse Leap22/5/202017/6/2026
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value.
ModificadaAlta (7.1)2.3%—FreerdpCanonical Ubuntu LinuxDebian LinuxOpensuse Leap22/5/202017/6/2026
An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c.