Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
681 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4) | 2.4% | — | Oracle MysqlOracle SolarisSuse Linux Enterprise DesktopSuse Linux Enterprise Server+3 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Prepared Statements. | |
| Modificada | Media (4) | 3.0% | — | Oracle MysqlDebian LinuxCanonical Ubuntu LinuxMariadb+4 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer. | |
| Modificada | Media (4) | 3.2% | — | Oracle MysqlMariadbDebian LinuxCanonical Ubuntu Linux+4 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Full Text Search. | |
| Modificada | Media (5) | 3.8% | — | Oracle MysqlOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options. | |
| Modificada | Media (4) | 2.7% | — | Oracle MysqlOracle SolarisOpensuseSuse Linux Enterprise Desktop+3 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.30 and earlier and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Partition. | |
| Modificada | Media (4) | 3.1% | — | Oracle SolarisOracle MysqlDebian LinuxOpensuse+5 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Data Manipulation Language. | |
| Modificada | Media (4) | 3.1% | — | Oracle MysqlMariadbDebian LinuxCanonical Ubuntu Linux+4 | 17/7/2013 | 16/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Parser. | |
| Analizada | Alta (8.8) | 69% | ⚠ Explotación activa💥 Exploit | Mozilla FirefoxMozilla ThunderbirdMozilla Thunderbird ESRCanonical Ubuntu Linux+11 | 26/6/2013 | 16/6/2026 | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa💥 Exploit | Oracle JRESUN JRESuse Linux Enterprise DesktopSuse Linux Enterprise Java+2 | 18/6/2013 | 16/6/2026 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the… | |
| Modificada | Baja (3.3) | 0.49% | — | Linux KernelSuse Linux Enterprise Server | 8/6/2013 | 16/6/2026 | The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user. | |
| Modificada | Baja (2.1) | 0.40% | — | Linux KernelSuse Linux Enterprise Server | 7/6/2013 | 16/6/2026 | The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via (1) a crafted IDAGETPCIINFO command for a /dev/ida device, related… | |
| Modificada | Media (4.3) | 3.5% | — | Canonical Ubuntu LinuxSuse Linux Enterprise ServerClamav | 13/5/2013 | 16/6/2026 | pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file. | |
| Modificada | Media (5) | 3.5% | — | Canonical Ubuntu LinuxSuse Linux Enterprise ServerClamav | 13/5/2013 | 16/6/2026 | Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-bounds read. | |
| Modificada | Alta (7.2) | 0.98% | 💥 Exploit | Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRGSuse Linux Enterprise Desktop+2 | 29/4/2013 | 16/6/2026 | The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then… | |
| Modificada | Media (6.8) | 3.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+6 | 3/4/2013 | 16/6/2026 | Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to… | |
| Modificada | Media (5) | 19% | 💥 Exploit | MariadbOracle MysqlRedhat Enterprise LinuxDebian Linux+5 | 28/3/2013 | 16/6/2026 | MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is… | |
| Modificada | Alta (9.3) | 4.9% | — | QemuFedoraproject FedoraOpensuseSuse Linux Enterprise Server+8 | 13/2/2013 | 16/6/2026 | Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet. | |
| Modificada | Media (6.8) | 5.8% | — | Redhat LibvirtOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+7 | 8/2/2013 | 16/6/2026 | Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain… | |
| Modificada | Alta (9.3) | 5.3% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+5 | 13/1/2013 | 16/6/2026 | Heap-based buffer overflow in the gfxTextRun::ShrinkToLigatureBoundaries function in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via a crafted document. | |
| Modificada | Alta (9.3) | 5.9% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+5 | 13/1/2013 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Thunderbird before 17.0.2, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | |
| Modificada | Alta (9.3) | 5.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+10 | 13/1/2013 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allow remote attackers to cause a denial of service (memory… | |
| Modificada | Alta (9.3) | 7.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+9 | 13/1/2013 | 16/6/2026 | Stack-based buffer overflow in the Canvas implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via an HTML document that specifies invalid width and… | |
| Modificada | Alta (10) | 5.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+10 | 13/1/2013 | 16/6/2026 | The nsSVGPathElement::GetPathLengthScale function in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code or cause a denial… | |
| Modificada | Alta (9.3) | 4.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+10 | 13/1/2013 | 16/6/2026 | Use-after-free vulnerability in the ~nsHTMLEditRules implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.1, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.1, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code… | |
| Modificada | Alta (9.3) | 3.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+5 | 13/1/2013 | 16/6/2026 | The nsSOCKSSocketInfo::ConnectToProxy function in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not ensure thread safety for SSL sessions, which allows remote attackers to execute arbitrary code via crafted… |