Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1059 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)3.0%—Debian LinuxCanonical Ubuntu LinuxArtifex GhostscriptArtifex GPL Ghostscript+728/8/201817/6/2026
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
ModificadaAlta (7.8)3.0%—Debian LinuxCanonical Ubuntu LinuxArtifex GhostscriptArtifex GPL Ghostscript+727/8/201817/6/2026
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
ModificadaAlta (7.8)1.9%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+427/8/201817/6/2026
In Artifex Ghostscript 9.23 before 2018-08-23, attackers are able to supply malicious PostScript files to bypass .tempfile restrictions and write files.
ModificadaMedia (5.5)0.41%—LibvirtRedhat VirtualizationRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+620/8/201817/6/2026
libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
ModificadaAlta (8.8)3.9%—Spice Project SpiceDebian LinuxCanonical Ubuntu LinuxRedhat Virtualization+717/8/201817/6/2026
A vulnerability was discovered in SPICE before version 0.14.1 where the generated code used for demarshalling messages lacked sufficient bounds checks. A malicious client or server, after authentication, could send specially crafted messages to its peer which would result in a crash or, potentially, other impacts.
ModificadaAlta (7.5)74%—Redhat VirtualizationRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+346/8/201817/6/2026
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service.
ModificadaAlta (7.8)1.9%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+41/8/201817/6/2026
An out-of-bounds heap read vulnerability was found in the jpc_pi_nextpcrl() function of jasper before 2.0.6 when processing crafted input.
ModificadaAlta (7.8)1.9%—Jasper Project JasperDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+31/8/201817/6/2026
A heap-buffer overflow vulnerability was found in QMFB code in JPC codec caused by buffer being allocated with too small size. jasper versions before 2.0.0 are affected.
ModificadaMedia (5.9)2.0%—Mozilla Network Security ServicesRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+31/8/201817/6/2026
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group.
ModificadaAlta (8.1)2.5%—Uclouvain OpenjpegRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+31/8/201817/6/2026
An out-of-bounds read vulnerability was found in OpenJPEG 2.1.2, in the j2k_to_image tool. Converting a specially crafted JPEG2000 file to another format could cause the application to crash or, potentially, disclose some data from the heap.
ModificadaAlta (7.8)0.67%—Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+530/7/201817/6/2026
A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the trap flag(TF) bit in EFLAGS during emulation of the syscall instruction, which leads to a debug exception(#DB) being raised in the guest stack. A user/process inside a guest could use this flaw to potentially escalate…
ModificadaCrítica (9.9)4.4%—QemuCitrix XenserverRedhat OpenstackDebian Linux+527/7/201817/6/2026
A heap buffer overflow flaw was found in QEMU's Cirrus CLGD 54xx VGA emulator's VNC display driver support before 2.9; the issue could occur when a VNC client attempted to update its display after a VGA operation is performed by a guest. A privileged user/process inside a guest could use this flaw to crash the QEMU…
ModificadaAlta (7.5)2.5%—Spice Project SpiceDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+327/7/201817/6/2026
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An attacker able to connect to the SPICE server could send crafted messages which would cause the process to crash.
ModificadaCrítica (9.8)1.5%—LiblouisRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+227/7/201817/6/2026
A missing patch for a stack-based buffer overflow in findTable() was found in Red Hat version of liblouis before 2.5.4. An attacker could cause a denial of service condition or potentially even arbitrary code execution.
ModificadaMedia (6.7)0.54%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+127/7/201817/6/2026
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
ModificadaAlta (8.8)3.8%—Spice Project SpiceDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+327/7/201817/6/2026
A vulnerability was discovered in SPICE before 0.13.90 in the server's protocol handling. An authenticated attacker could send crafted messages to the SPICE server causing a heap overflow leading to a crash or possible code execution.
ModificadaAlta (7.5)5.2%—Linux KernelRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+127/7/201817/6/2026
It was found that the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation before 2.6.22.17 used the IPv4-only inet_sk_rebuild_header() function for both IPv4 and IPv6 DCCP connections, which could result in memory corruptions. A remote attacker could use this flaw to crash the system.
ModificadaMedia (6.5)3.0%—QemuRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+227/7/201817/6/2026
An out-of-bounds memory access issue was found in Quick Emulator (QEMU) before 1.7.2 in the VNC display driver. This flaw could occur while refreshing the VNC display surface area in the 'vnc_refresh_server_surface'. A user inside a guest could use this flaw to crash the QEMU process.
ModificadaMedia (5.5)0.46%—Freedesktop LibiceRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+227/7/201817/6/2026
It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.
ModificadaCrítica (9.9)3.6%—QemuCitrix XenserverRedhat OpenstackDebian Linux+627/7/201817/6/2026
Quick emulator (QEMU) before 2.8 built with the Cirrus CLGD 54xx VGA Emulator support is vulnerable to an out-of-bounds access issue. The issue could occur while copying VGA data in cirrus_bitblt_cputovideo. A privileged user inside guest could use this flaw to crash the QEMU process OR potentially execute arbitrary…
ModificadaMedia (5.5)0.46%—Linux KernelDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+427/7/201817/6/2026
A flaw was found in the Linux kernel's handling of clearing SELinux attributes on /proc/pid/attr files before 4.9.10. An empty (null) write to this file can crash the system by causing the system to attempt to access unmapped kernel memory.
ModificadaMedia (4.7)0.28%—Util-linux Project Util-linuxDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+327/7/201817/6/2026
A race condition was found in util-linux before 2.32.1 in the way su handled the management of child processes. A local authenticated attacker could use this flaw to kill other processes with root privileges under specific conditions.
ModificadaCrítica (9.8)6.2%—PidginDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+327/7/201817/6/2026
An out-of-bounds write flaw was found in the way Pidgin before 2.12.0 processed XML content. A malicious remote server could potentially use this flaw to crash Pidgin or execute arbitrary code in the context of the pidgin process.
ModificadaMedia (5.5)0.53%—X.org LibxdmcpRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+327/7/201817/6/2026
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
ModificadaAlta (8.1)1.3%—FreeipaRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+327/7/201817/6/2026
A vulnerability was found in ipa before 4.4. IdM's ca-del, ca-disable, and ca-enable commands did not properly check the user's permissions while modifying CAs in Dogtag. An authenticated, unauthorized attacker could use this flaw to delete, disable, or enable CAs causing various denial of service problems with…