Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
81 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.4% | — | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+4 | 16/5/2016 | 17/6/2026 | PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 does not ensure that pathnames lack %00 sequences, which might allow remote attackers to read or write to arbitrary files via crafted input to an application that calls (1) a DOMDocument load method, (2) the xmlwriter_open_uri function, (3) the finfo_file… | |
| Analizada | Media (5.5) | 77% | ⚠ Explotación activa | Redhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux FOR IBM Z Systems EUS+26 | 5/5/2016 | 17/6/2026 | The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. | |
| Modificada | Media (5.5) | 20% | — | Canonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+6 | 5/5/2016 | 17/6/2026 | The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files via a crafted image. | |
| Modificada | Baja (3.3) | 11% | — | Canonical Ubuntu LinuxImagemagickRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+6 | 5/5/2016 | 17/6/2026 | The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via a crafted image. | |
| Analizada | Media (5.5) | 75% | ⚠ Explotación activa | Redhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux FOR IBM Z Systems EUS+26 | 5/5/2016 | 17/6/2026 | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. | |
| Modificada | Alta (7.5) | 29% | — | OpensslRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+4 | 5/5/2016 | 17/6/2026 | The asn1_d2i_read_bio function in crypto/asn1/a_d2i_fp.c in the ASN.1 BIO implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (memory consumption) via a short invalid encoding. | |
| Modificada | Crítica (9.8) | 78% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+5 | 5/5/2016 | 17/6/2026 | The ASN.1 implementation in OpenSSL before 1.0.1o and 1.0.2 before 1.0.2c allows remote attackers to execute arbitrary code or cause a denial of service (buffer underflow and memory corruption) via an ANY field in crafted serialized data, aka the "negative zero" issue. | |
| Modificada | Media (5.9) | 89% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+11 | 5/5/2016 | 17/6/2026 | The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obtain sensitive cleartext information via a padding-oracle attack against an AES CBC session. NOTE: this vulnerability exists because of an… | |
| Modificada | Alta (7.5) | 27% | — | OpensslRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+4 | 5/5/2016 | 17/6/2026 | Integer overflow in the EVP_EncryptUpdate function in crypto/evp/evp_enc.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of data. | |
| Modificada | Alta (7.5) | 40% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+11 | 5/5/2016 | 17/6/2026 | Integer overflow in the EVP_EncodeUpdate function in crypto/evp/encode.c in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h allows remote attackers to cause a denial of service (heap memory corruption) via a large amount of binary data. | |
| Modificada | Media (5.9) | 3.4% | — | Oracle JDKOracle JREOracle JrockitRedhat Icedtea7+8 | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality via vectors related to Security. | |
| Modificada | Alta (8.8) | 5.0% | — | MercurialDebian LinuxSuse Linux Enterprise DebuginfoOpensuse+10 | 13/4/2016 | 17/6/2026 | Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository. | |
| Modificada | Alta (8.8) | 5.4% | — | Debian LinuxMercurialFedoraproject FedoraRedhat Enterprise Linux Desktop+10 | 13/4/2016 | 17/6/2026 | Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository. | |
| Modificada | Alta (7.5) | 2.2% | — | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+4 | 8/4/2016 | 17/6/2026 | The calloc function in the glibc package in Red Hat Enterprise Linux (RHEL) 6.7 and 7.2 does not properly initialize memory areas, which might allow context-dependent attackers to cause a denial of service (hang or crash) via unspecified vectors. | |
| Modificada | Alta (8.1) | 91% | — | Debian LinuxCanonical Ubuntu LinuxHP Helion OpenstackHP Server Migration Pack+26 | 18/2/2016 | 17/6/2026 | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the… | |
| Modificada | Media (4) | 4.2% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+10 | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer. | |
| Modificada | Baja (1.7) | 4.4% | — | Oracle LinuxRedhat Enterprise LinuxDebian LinuxOracle Solaris+12 | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to privileges. | |
| Modificada | Baja (3.5) | 3.9% | — | Oracle LinuxRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+12 | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to UDF. | |
| Modificada | Baja (3.5) | 4.2% | — | Debian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+12 | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect integrity via unknown vectors related to encryption. | |
| Modificada | Baja (3.5) | 3.9% | — | Redhat Enterprise LinuxDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+12 | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to InnoDB. | |
| Modificada | Baja (3.5) | 3.9% | — | Opensuse LeapOpensuseOracle LinuxRedhat Enterprise Linux+12 | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML. | |
| Modificada | Media (4) | 4.3% | — | Redhat Enterprise LinuxOracle SolarisOracle LinuxOpensuse Leap+12 | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer. | |
| Modificada | Media (4) | 4.3% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+12 | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and 5.6.27 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via vectors related to DML. | |
| Modificada | Alta (7.2) | 0.59% | — | Canonical Ubuntu LinuxMariadbRedhat Enterprise LinuxOracle Mysql+12 | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Client. NOTE: the previous information is from… | |
| Modificada | Media (6.8) | 7.5% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+12 | 21/1/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier, 5.6.27 and earlier, and 5.7.9 and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Options. |