Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.6% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+5 | 20/3/2017 | 17/6/2026 | The png coder in ImageMagick allows remote attackers to cause a denial of service (crash). | |
| Modificada | Alta (7.5) | 3.7% | — | Opensuse LeapOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Desktop+6 | 20/3/2017 | 17/6/2026 | Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption). | |
| Modificada | Crítica (9.8) | 4.6% | — | Opensuse Project Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+6 | 20/3/2017 | 17/6/2026 | The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact. | |
| Modificada | Crítica (9.8) | 4.9% | — | Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+7 | 20/3/2017 | 17/6/2026 | Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact. | |
| Modificada | Media (5.5) | 1.9% | — | Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+7 | 20/3/2017 | 17/6/2026 | The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file. | |
| Modificada | Media (5.5) | 2.1% | — | Suse Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+6 | 20/3/2017 | 17/6/2026 | The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file. | |
| Modificada | Crítica (9.8) | 3.9% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+4 | 20/3/2017 | 17/6/2026 | The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors. | |
| Modificada | Alta (7.5) | 3.6% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+5 | 20/3/2017 | 17/6/2026 | Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors. | |
| Modificada | Crítica (9.8) | 3.9% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+4 | 20/3/2017 | 17/6/2026 | The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions." | |
| Modificada | Alta (7.5) | 3.7% | — | ImagemagickOpensuse LeapOpensuseSuse Linux Enterprise Server+3 | 17/3/2017 | 17/6/2026 | coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image." | |
| Modificada | Media (5.5) | 1.8% | — | ImagemagickSuse Linux Enterprise DebuginfoNovell LeapOpensuse Leap+7 | 17/3/2017 | 17/6/2026 | Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file. | |
| Modificada | Crítica (9.8) | 2.9% | — | ImagemagickOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+3 | 17/3/2017 | 17/6/2026 | distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors. | |
| Modificada | Media (5.5) | 0.40% | — | QemuSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Server FOR SAP+1 | 15/3/2017 | 17/6/2026 | Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit. | |
| Modificada | Media (5.5) | 1.9% | — | GraphicsmagickDebian LinuxSuse Linux Enterprise DebuginfoSuse Studio Onsite+3 | 3/2/2017 | 17/6/2026 | GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath function in magick/render.c. | |
| Modificada | Media (5.5) | 2.0% | — | GraphicsmagickDebian LinuxSuse Linux Enterprise DebuginfoSuse Studio Onsite+3 | 3/2/2017 | 17/6/2026 | Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c. | |
| Modificada | Media (5.5) | 0.85% | — | Systemd Project SystemdNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+5 | 13/10/2016 | 17/6/2026 | The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled. | |
| Modificada | Media (5.5) | 2.3% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITCanonical Ubuntu Linux+1 | 20/9/2016 | 17/6/2026 | The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file. | |
| Modificada | Media (5.5) | 2.0% | — | LibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+1 | 20/9/2016 | 17/6/2026 | Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file. | |
| Modificada | Media (5.5) | 2.2% | — | Canonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 20/9/2016 | 17/6/2026 | The compress_bidder_init function in archive_read_support_filter_compress.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file, which triggers an invalid left shift. | |
| Modificada | Alta (7.8) | 2.1% | — | LibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+2 | 20/9/2016 | 17/6/2026 | Multiple integer overflows in the (1) get_time_t_max and (2) get_time_t_min functions in archive_read_support_format_mtree.c in libarchive before 3.2.0 allow remote attackers to have unspecified impact via a crafted mtree file, which triggers undefined behavior. | |
| Modificada | Alta (7.5) | 4.3% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITLibarchive+1 | 20/9/2016 | 17/6/2026 | bsdtar in libarchive before 3.2.0 allows remote attackers to cause a denial of service (infinite loop) via an ISO with a directory that is a member of itself. | |
| Modificada | Media (5.5) | 1.5% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITLibarchive | 20/9/2016 | 17/6/2026 | Memory leak in the __archive_read_get_extract function in archive_read_extract2.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service via a tar file. | |
| Modificada | Media (5.5) | 2.1% | — | Canonical Ubuntu LinuxLibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 20/9/2016 | 17/6/2026 | The process_add_entry function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. | |
| Modificada | Media (5.5) | 2.0% | — | Canonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+1 | 20/9/2016 | 17/6/2026 | The archive_read_format_rar_read_data function in archive_read_support_format_rar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted rar archive. | |
| Modificada | Media (5.5) | 2.1% | — | Canonical Ubuntu LinuxLibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 20/9/2016 | 17/6/2026 | The readline function in archive_read_support_format_mtree.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (invalid read) via a crafted mtree file, related to newline parsing. |