Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 6.2% | — | Oracle SolarisMozilla FirefoxMozilla Firefox ESRNovell Suse Linux Enterprise Software Development KIT+2 | 6/7/2015 | 17/6/2026 | Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a shared worker. | |
| Modificada | Media (4.3) | 3.3% | — | Novell Suse Linux Enterprise Software Development KITCanonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise Desktop+4 | 6/7/2015 | 17/6/2026 | Mozilla Network Security Services (NSS) before 3.19, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, Thunderbird before 38.1, and other products, does not properly determine state transitions for the TLS state machine, which allows man-in-the-middle attackers to defeat… | |
| Modificada | Media (5) | 8.9% | — | Ruby-lang RubyRubygemsOracle SolarisRedhat Enterprise Linux | 24/6/2015 | 17/6/2026 | RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack." | |
| Modificada | Media (5) | 50% | — | Redhat Enterprise LinuxApple MAC OS XPHPHP System Management Homepage+8 | 9/6/2015 | 17/6/2026 | Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome. | |
| Modificada | Media (6.8) | 14% | — | Oracle LinuxOracle SolarisApple MAC OS XRedhat Enterprise Linux+7 | 9/6/2015 | 17/6/2026 | The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that… | |
| Modificada | Alta (7.5) | 38% | — | Apple MAC OS XRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+7 | 9/6/2015 | 17/6/2026 | Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) phar, or (3) ZIP archive. | |
| Modificada | Alta (7.5) | 9.9% | — | LighttpdHP Virtual Customer Access SystemOracle Solaris | 9/6/2015 | 17/6/2026 | mod_auth in lighttpd before 1.4.36 allows remote attackers to inject arbitrary log entries via a basic HTTP authentication string without a colon character, as demonstrated by a string containing a NULL and new line character. | |
| Modificada | Baja (3.3) | 3.0% | — | Linux KernelFedoraproject FedoraOracle LinuxOracle Solaris+2 | 27/5/2015 | 17/6/2026 | The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message. | |
| Modificada | Media (5) | 3.0% | — | Oracle SolarisWireshark | 26/5/2015 | 17/6/2026 | The (1) dissect_tfs_request and (2) dissect_tfs_response functions in epan/dissectors/packet-ieee80211.c in the IEEE 802.11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 interpret a zero value as a length rather than an error condition, which allows remote attackers to cause a denial of service… | |
| Modificada | Alta (7.8) | 3.7% | — | Oracle LinuxOracle SolarisWireshark | 26/5/2015 | 17/6/2026 | Multiple memory leaks in the x11_init_protocol function in epan/dissectors/packet-x11.c in the X11 dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 allow remote attackers to cause a denial of service (memory consumption) via a crafted packet. | |
| Modificada | Media (5) | 2.9% | — | Oracle SolarisOracle LinuxWireshark | 26/5/2015 | 17/6/2026 | epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.14 and 1.12.x before 1.12.5 improperly refers to previously processed bytes, which allows remote attackers to cause a denial of service (application crash) via a crafted packet, a different vulnerability than CVE-2015-2188. | |
| Modificada | Baja (3.5) | 1.8% | — | Openstack HorizonOracle Solaris | 19/5/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate. | |
| Modificada | Baja (2.6) | 11% | — | Oracle LinuxOracle SolarisSquid-cache SquidFedoraproject Fedora | 18/5/2015 | 17/6/2026 | Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate. | |
| Modificada | Alta (7.5) | 7.2% | — | Mozilla FirefoxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+4 | 14/5/2015 | 17/6/2026 | Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283. | |
| Modificada | Media (4) | 2.9% | — | Openstack KeystoneOracle Solaris | 12/5/2015 | 17/6/2026 | OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and other sensitive backend information by reading the Keystone logs. | |
| Modificada | Media (6.4) | 4.4% | — | Thekelleys DnsmasqOracle Solaris | 8/5/2015 | 17/6/2026 | The tcp_request function in Dnsmasq before 2.73rc4 does not properly handle the return value of the setup_reply function, which allows remote attackers to read process memory and cause a denial of service (out-of-bounds read and crash) via a malformed DNS request. | |
| Modificada | Alta (7.5) | 37% | — | Fedoraproject FedoraCanonical Ubuntu LinuxDebian LinuxHaxx Curl+5 | 24/4/2015 | 17/6/2026 | The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character. | |
| Modificada | Alta (7.1) | 3.0% | — | Oracle Solaris | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Sun Solaris 11.2 allows remote attackers to affect availability via vectors related to Kernel IDMap. | |
| Modificada | Alta (7.2) | 0.44% | — | Oracle Solaris | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Accounting commands. | |
| Modificada | Baja (2.1) | 0.43% | — | Oracle Solaris | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality via unknown vectors related to Text Utilities. | |
| Modificada | Media (4) | 5.1% | — | Oracle SolarisOracle MysqlMariadbCanonical Ubuntu Linux+10 | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to DDL. | |
| Modificada | Media (4) | 5.2% | — | Oracle MysqlOracle SolarisDebian LinuxMariadb+10 | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer. | |
| Modificada | Media (5) | 7.1% | — | Oracle SolarisOracle Communications Policy ManagementOracle MysqlDebian Linux+11 | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileges. | |
| Modificada | Baja (3.5) | 5.0% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITOracle Mysql+10 | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via vectors related to DDL. | |
| Modificada | Baja (3.5) | 4.7% | — | Oracle MysqlOracle SolarisDebian LinuxCanonical Ubuntu Linux+10 | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Federated. |