Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2756▼ 505 respecto a la semana anterior
Críticas / altas1305▼ 214 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 3.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+9 | 13/11/2008 | 16/6/2026 | nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized,… | |
| Modificada | Media (6.9) | 0.31% | — | Linux KernelCanonical Ubuntu LinuxOpensuseSuse Linux Enterprise Desktop+4 | 2/5/2008 | 16/6/2026 | Race condition in the directory notification subsystem (dnotify) in Linux kernel 2.6.x before 2.6.24.6, and 2.6.25 before 2.6.25.1, allows local users to cause a denial of service (OOPS) and possibly gain privileges via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.5% | — | MIT Kerberos 5Apple MAC OS XApple MAC OS X ServerOpensuse+7 | 19/3/2008 | 16/6/2026 | The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values." | |
| Modificada | Alta (9.3) | 4.3% | — | X.org X ServerCanonical Ubuntu LinuxDebian LinuxApple MAC OS X+7 | 18/1/2008 | 16/6/2026 | The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990. | |
| Modificada | Baja (2.1) | 0.43% | — | Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+8 | 4/12/2007 | 16/6/2026 | The do_coredump function in fs/exec.c in Linux kernel 2.4.x and 2.6.x up to 2.6.24-rc3, and possibly other versions, does not change the UID of a core dump file if it exists before a root process creates a core dump in the same location, which might allow local users to obtain sensitive information. |