Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
920 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 17% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Media (5) | 21% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Media (5) | 23% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR… | |
| Modificada | Alta (9.3) | 24% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS… | |
| Modificada | Media (4.3) | 15% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for rendering of malformed PNG images, which allows remote attackers to obtain sensitive… | |
| Modificada | Baja (2.1) | 2.4% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize function buffers, which allows local users to obtain sensitive information… | |
| Modificada | Media (4.3) | 15% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+4 | 11/3/2015 | 17/6/2026 | The photo-decoder implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly initialize memory for rendering of JXR images, which allows remote attackers to obtain sensitive… | |
| Modificada | Alta (7.2) | 1.6% | — | Microsoft Windows 2003 ServerMicrosoft Windows 7Microsoft Windows Server 2008Microsoft Windows Vista | 11/3/2015 | 17/6/2026 | The kernel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 does not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka "Impersonation Level Check Elevation of Privilege Vulnerability." | |
| Modificada | Media (4.3) | 15% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly allocate memory, which allows remote attackers to cause a denial of service via a crafted… | |
| Modificada | Alta (7.2) | 1.8% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict changes to virtual stores, which allows local users to gain… | |
| Modificada | Media (4.3) | 13% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 6/3/2015 | 17/6/2026 | Schannel (aka Secure Channel) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to… | |
| Modificada | Media (4.3) | 19% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for TIFF images, which allows remote attackers to obtain sensitive information from process… | |
| Modificada | Media (4.7) | 3.8% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly scale fonts, which allows local users to cause a… | |
| Modificada | Alta (7.2) | 13% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation… | |
| Modificada | Baja (1.9) | 2.5% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1, when the… | |
| Modificada | Baja (3.3) | 8.1% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows man-in-the-middle attackers to disable a signing… | |
| Modificada | Alta (8.3) | 29% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authentication from the server to the client, which allows remote attackers to execute… | |
| Modificada | Media (6.9) | 4.5% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (NULL pointer… | |
| Analizada | Alta (7.8) | 76% | ⚠ Explotación activa💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+4 | 13/1/2015 | 17/6/2026 | Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an… | |
| Modificada | Alta (10) | 97% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows Server 2003+3 | 13/1/2015 | 17/6/2026 | Buffer overflow in the Telnet service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows Telnet Service Buffer… | |
| Modificada | Media (6.1) | 12% | 💥 PoC | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT 8.1+4 | 13/1/2015 | 17/6/2026 | The Network Location Awareness (NLA) service in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 does not perform mutual authentication to determine a domain connection, which allows remote attackers to… | |
| Modificada | Alta (7.2) | 3.6% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 13/1/2015 | 17/6/2026 | The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges by conducting a junction attack to load another… |