Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

520 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.3)2.6%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux+223/7/201917/6/2026
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
ModificadaMedia (5.3)2.1%—Mozilla FirefoxMozilla ThunderbirdDebian LinuxNovell Suse Package HUB FOR Suse Linux Enterprise+123/7/201917/6/2026
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
ModificadaAlta (8.8)2.4%—FfmpegDebian LinuxNovell Suse Package HUB FOR Suse Linux EnterpriseCanonical Ubuntu Linux19/4/201917/6/2026
libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.
ModificadaAlta (8.8)2.9%—Dcraw Project DcrawSuse Linux Enterprise DesktopSuse Linux Enterprise Server29/11/201817/6/2026
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
ModificadaAlta (7.5)41%—Nodejs Node.jsSuse Enterprise StorageSuse Linux Enterprise ServerSuse Openstack Cloud28/11/201817/6/2026
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.
ModificadaAlta (7.5)4.6%—Nodejs Node.jsSuse Enterprise StorageSuse Linux Enterprise ServerSuse Openstack Cloud28/11/201817/6/2026
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same…
ModificadaMedia (6.5)1.5%—Libwpd Project LibwpdRedhat Enterprise LinuxSuse Linux Enterprise Server12/11/201817/6/2026
In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.
ModificadaAlta (7.5)14%—LighttpdOpensuse Backports SLEOpensuse LeapSuse Linux Enterprise Server+17/11/201817/6/2026
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does…
ModificadaBaja (3.3)0.35%—Canonical Ubuntu LinuxLinuxcontainers LXCSuse Caas PlatformSuse Openstack Cloud+210/8/201817/6/2026
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of…
ModificadaAlta (8.2)1.1%—QuaggaOpensuseSuse LinuxRedhat Package Manager24/7/201817/6/2026
Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA, recency is determined by first comparing sequence numbers, then checksums, and finally MaxAge.…
ModificadaMedia (5.3)0.78%—Suse Linux Enterprise DesktopSuse Linux Enterprise Server8/6/201816/6/2026
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the…
ModificadaCrítica (9.8)1.0%—Suse Linux Enterprise Server8/6/201816/6/2026
A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.
ModificadaAlta (7)1.00%—PostgresqlSuse Linux Enterprise Server1/3/201817/6/2026
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
ModificadaMedia (5.6)94%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+3044/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
ModificadaAlta (7.8)0.38%—Novell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse Leap8/9/201717/6/2026
The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
ModificadaAlta (7.5)5.3%—NTPDebian LinuxOpensuse Suse Linux Enterprise ServerOpensuse Project Suse Linux Enterprise Desktop+99/8/201717/6/2026
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute…
ModificadaAlta (7.5)9.1%—Fedoraproject FedoraSuse Linux Enterprise DebuginfoOpensuse LeapOpensuse+1621/7/201717/6/2026
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to…
ModificadaMedia (5.9)2.2%—Golang GONovell Suse Package HUB FOR Suse Linux EnterpriseFedoraproject FedoraOpensuse Leap6/7/201717/6/2026
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted…
ModificadaAlta (7.8)2.7%—Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+1619/6/201717/6/2026
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these…
ModificadaCrítica (9.8)4.4%—Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+36/6/201717/6/2026
game-music-emu before 0.6.1 mishandles unspecified integer values.
ModificadaMedia (5.5)0.53%—Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+36/6/201717/6/2026
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
ModificadaBaja (3.8)0.37%—XENSuse ManagerSuse Manager ProxySuse Openstack Cloud+23/5/201717/6/2026
Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.
ModificadaAlta (7.8)2.3%—Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+512/4/201717/6/2026
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
ModificadaAlta (7.8)2.3%—Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+512/4/201717/6/2026
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
ModificadaAlta (7.8)1.9%—Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+512/4/201717/6/2026
Stack-based buffer overflow in game-music-emu before 0.6.1.