Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

231 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.0%—Suse Linux Enterprise Server8/6/201816/6/2026
A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.
ModificadaAlta (7)1.00%—PostgresqlSuse Linux Enterprise Server1/3/201817/6/2026
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
ModificadaMedia (5.6)94%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+3044/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
ModificadaAlta (7.8)0.38%—Novell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse Leap8/9/201717/6/2026
The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
ModificadaAlta (7.5)5.3%—NTPDebian LinuxOpensuse Suse Linux Enterprise ServerOpensuse Project Suse Linux Enterprise Desktop+99/8/201717/6/2026
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute…
ModificadaAlta (7.5)9.1%—Fedoraproject FedoraSuse Linux Enterprise DebuginfoOpensuse LeapOpensuse+1621/7/201717/6/2026
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to…
ModificadaAlta (7.8)2.7%—Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+1619/6/201717/6/2026
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these…
ModificadaCrítica (9.8)4.4%—Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+36/6/201717/6/2026
game-music-emu before 0.6.1 mishandles unspecified integer values.
ModificadaMedia (5.5)0.53%—Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+36/6/201717/6/2026
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
ModificadaBaja (3.8)0.37%—XENSuse ManagerSuse Manager ProxySuse Openstack Cloud+23/5/201717/6/2026
Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.
ModificadaAlta (7.8)2.3%—Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+512/4/201717/6/2026
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
ModificadaAlta (7.8)2.3%—Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+512/4/201717/6/2026
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
ModificadaAlta (7.8)1.9%—Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+512/4/201717/6/2026
Stack-based buffer overflow in game-music-emu before 0.6.1.
ModificadaAlta (7.8)0.53%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Server23/3/201717/6/2026
A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root).
ModificadaAlta (7.5)3.7%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+520/3/201717/6/2026
ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
ModificadaAlta (7.5)3.6%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+420/3/201717/6/2026
Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).
ModificadaAlta (7.5)3.6%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+520/3/201717/6/2026
The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
ModificadaAlta (7.5)3.7%—Opensuse LeapOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Desktop+620/3/201717/6/2026
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
ModificadaCrítica (9.8)4.6%—Opensuse Project Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+620/3/201717/6/2026
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
ModificadaCrítica (9.8)4.9%—Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+720/3/201717/6/2026
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
ModificadaMedia (5.5)1.9%—Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+720/3/201717/6/2026
The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
ModificadaMedia (5.5)2.1%—Suse Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+620/3/201717/6/2026
The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
ModificadaCrítica (9.8)3.9%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+420/3/201717/6/2026
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
ModificadaAlta (7.5)3.6%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+520/3/201717/6/2026
Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
ModificadaCrítica (9.8)3.9%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+420/3/201717/6/2026
The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."