Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

937 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.48%—QemuDebian LinuxFedoraproject FedoraSuse Linux Enterprise Desktop+43/6/201517/6/2026
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
ModificadaBaja (3.7)100%💥 PoCOpensslCanonical Ubuntu LinuxHp-uxIBM Content Manager+2121/5/201517/6/2026
The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a…
ModificadaAlta (7.5)7.2%—Mozilla FirefoxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+414/5/201517/6/2026
Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.
ModificadaMedia (6.8)4.0%—Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse+314/5/201517/6/2026
Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a document containing crafted text in conjunction with a Cascading…
ModificadaMedia (6.8)4.8%—Mozilla ThunderbirdMozilla FirefoxMozilla Firefox ESRNovell Suse Linux Enterprise Software Development KIT+314/5/201517/6/2026
Heap-based buffer overflow in the SVGTextFrame class in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code via crafted SVG graphics data in conjunction with a crafted Cascading Style Sheets (CSS) token sequence.
ModificadaAlta (7.5)4.2%—Mozilla FirefoxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+114/5/201517/6/2026
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
ModificadaAlta (7.5)4.9%—Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse+314/5/201517/6/2026
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
ModificadaMedia (6.8)5.4%—GstreamerMozilla FirefoxMozilla SeamonkeyMozilla Thunderbird+1014/5/201517/6/2026
GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.
ModificadaBaja (2.9)0.79%—XENSuse Linux Enterprise Software Development KITSuse Linux Enterprise DesktopSuse Linux Enterprise Server+528/4/201517/6/2026
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.
ModificadaMedia (4.6)0.47%—Suse Linux Enterprise ServerLinux KernelDebian Linux21/4/201517/6/2026
net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry.
ModificadaMedia (4.3)2.2%—Google ChromeDebian LinuxCanonical Ubuntu LinuxOpensuse+719/4/201517/6/2026
Google Chrome before 42.0.2311.90 does not properly consider the interaction of page navigation with the handling of touch events and gesture events, which allows remote attackers to trigger unintended UI actions via a crafted web site that conducts a "tapjacking" attack.
ModificadaBaja (2.1)0.44%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITOracle Mysql16/4/201517/6/2026
Unspecified vulnerability in the MySQL Utilities component in Oracle MySQL 1.5.1 and earlier, when running on Windows, allows local users to affect integrity via unknown vectors related to Installation.
ModificadaMedia (4.9)3.6%—Debian LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+116/4/201517/6/2026
Unspecified vulnerability in the MySQL Connectors component in Oracle MySQL 5.1.34 and earlier allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Connector/J.
ModificadaMedia (4)5.1%—Oracle SolarisOracle MysqlMariadbCanonical Ubuntu Linux+1016/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
ModificadaMedia (4)5.2%—Oracle MysqlOracle SolarisDebian LinuxMariadb+1016/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
ModificadaMedia (5)7.1%—Oracle SolarisOracle Communications Policy ManagementOracle MysqlDebian Linux+1116/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileges.
ModificadaBaja (3.5)5.0%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITOracle Mysql+1016/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
ModificadaMedia (5.7)9.9%—Juniper Junos SpaceOracle MysqlDebian LinuxCanonical Ubuntu Linux+1016/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.
ModificadaMedia (4)2.4%—Oracle Communications Policy ManagementSuse Linux Enterprise Software Development KITSuse Linux Enterprise DesktopSuse Linux Enterprise Server+116/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors.
ModificadaBaja (3.5)4.7%—Oracle MysqlOracle SolarisDebian LinuxCanonical Ubuntu Linux+1016/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Federated.
ModificadaAlta (9.3)4.3%—OpensuseSuse Linux Enterprise ServerOracle JavafxOracle JDK+116/4/201517/6/2026
Unspecified vulnerability in Oracle Java SE 7u76 and 8u40, and JavaFX 2.2.76, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-0484.
ModificadaAlta (10)5.6%—Oracle JDKOracle JREOracle JavafxSuse Linux Enterprise Desktop+116/4/201517/6/2026
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and Java FX 2.2.76, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2015-0459.
ModificadaMedia (6.8)3.0%—Oracle JDKOracle JREOracle JavafxOpensuse+116/4/201517/6/2026
Unspecified vulnerability in Oracle Java SE 7u76 and 8u40, and Java FX 2.2.76, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2015-0492.
ModificadaAlta (10)5.7%—Oracle JDKOracle JREOracle JavafxNovell Suse Linux Enterprise Desktop+116/4/201517/6/2026
Unspecified vulnerability in Oracle Java SE 5.0u81, 6u91, 7u76, and 8u40, and JavaFX 2.2.76, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D, a different vulnerability than CVE-2015-0491.
ModificadaAlta (7.6)5.0%—Oracle JDKOracle JRENovell Suse Linux Enterprise DesktopOpensuse16/4/201517/6/2026
Unspecified vulnerability in in Oracle Java SE 6u91, 7u76, and 8u40 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.