Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

681 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)2.3%—Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.4%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)2.9%—Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+223/3/202017/6/2026
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)3.5%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+223/3/202017/6/2026
Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.4%—Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+223/3/202017/6/2026
Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaBaja (2.5)0.32%—Suse Linux Enterprise ServerOpensuse Leap2/3/202017/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in chkstat of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 11 set permissions intended for specific binaries on other binaries because it erroneously followed symlinks. The symlinks can't be controlled by attackers…
ModificadaCrítica (9.8)2.4%—Opensuse LeapSuse Linux Enterprise Server2/3/202017/6/2026
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-2.18.1. SUSE Linux Enterprise…
ModificadaCrítica (9.8)2.4%—Opensuse LeapSuse Linux Enterprise Server2/3/202017/6/2026
A Use After Free vulnerability in wicked of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Leap 15.1, Factory allows remote attackers to cause DoS or potentially code execution. This issue affects: SUSE Linux Enterprise Server 12 wicked versions prior to 0.6.60-3.5.1. SUSE Linux Enterprise…
ModificadaMedia (5.5)0.38%—Opensuse LeapSuse Linux Enterprise Server2/3/202017/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the mysql-systemd-helper of the mariadb packaging of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15 allows local attackers to change the permissions of arbitrary files to 0640. This issue affects: SUSE Linux Enterprise Server 12 mariadb…
ModificadaAlta (7.8)0.39%—Suse Linux Enterprise ServerOpensuse Leap2/3/202017/6/2026
A UNIX Symbolic Link (Symlink) Following vulnerability in the packaging of salt of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15; openSUSE Factory allows local attackers to escalate privileges from user salt to root. This issue affects: SUSE Linux Enterprise Server 12 salt-master version…
ModificadaAlta (7.8)7.0%—ImagemagickSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT17/2/202017/6/2026
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than…
ModificadaMedia (5)1.3%—Nextcloud ServerOpensuse Backports SLENovell Suse Linux Enterprise Server4/2/202017/6/2026
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
ModificadaMedia (4.9)1.5%—Nextcloud ServerOpensuse BackportsSuse Linux Enterprise Server4/2/202017/6/2026
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
ModificadaBaja (3.5)0.98%—QemuFedoraproject FedoraNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+731/1/202017/6/2026
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.
ModificadaMedia (6.8)0.88%—Gnome NetworkmanagerOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server27/1/202016/6/2026
NetworkManager 0.9.x does not pin a certificate's subject to an ESSID when 802.11X authentication is used.
ModificadaMedia (5.5)0.43%—Yast2-rmt Project Yast2-rmtOpensuse LeapSuse Linux Enterprise Server27/1/202017/6/2026
A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt…
ModificadaBaja (3.3)0.27%—Suse Linux Enterprise Server24/1/202017/6/2026
The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to…
ModificadaMedia (6.5)3.6%—QemuFedoraproject FedoraCanonical Ubuntu LinuxSuse Linux Enterprise Debuginfo+423/1/202017/6/2026
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
ModificadaAlta (8.8)39%—PhpmyadminSuse Linux Enterprise ServerDebian Linux9/1/202017/6/2026
In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server.
ModificadaAlta (8.8)1.1%—Obs-serverSuse Linux Enterprise Server2/1/202016/6/2026
obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation.
ModificadaAlta (7.5)3.2%—EglibcNovell Suse Linux Enterprise ServerDebian LinuxCanonical Ubuntu Linux+131/12/201916/6/2026
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
ModificadaAlta (8.8)2.0%—Canonical Cloud-initDebian LinuxSuse Linux Enterprise Server25/11/201916/6/2026
An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data.
ModificadaAlta (7.5)2.3%—Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+2315/11/201917/6/2026
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.
ModificadaAlta (7.1)0.34%—Suse Linux Enterprise Server7/10/201917/6/2026
The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by…
ModificadaMedia (5.3)4.3%—LibgdPHPCanonical Ubuntu LinuxDebian Linux+919/6/201917/6/2026
When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead…