Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
455 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.6% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 14/4/2015 | 17/6/2026 | Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka… | |
| Modificada | Alta (7.2) | 2.7% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 14/4/2015 | 17/6/2026 | Microsoft Windows Server 2003 R2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly constrain impersonation levels, which allows local users to gain privileges via a crafted application, aka… | |
| Modificada | Alta (9.3) | 71% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Untrusted search path vulnerability in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a Trojan horse DLL in the current working… | |
| Modificada | Media (5.6) | 2.7% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow local users to cause a denial of service (NULL pointer dereference and blue screen), or obtain… | |
| Modificada | Baja (2.1) | 2.6% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly restrict the availability of address information during a function call, which makes… | |
| Modificada | Alta (9.3) | 21% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Alta (9.3) | 17% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Media (5) | 21% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR… | |
| Modificada | Alta (9.3) | 20% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "Adobe Font… | |
| Modificada | Media (5) | 23% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to obtain sensitive information from kernel memory, and possibly bypass the KASLR… | |
| Modificada | Alta (9.3) | 24% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted (1) web site or (2) file, aka "WTS… | |
| Modificada | Media (4.3) | 15% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for rendering of malformed PNG images, which allows remote attackers to obtain sensitive… | |
| Modificada | Baja (2.1) | 2.4% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | The kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize function buffers, which allows local users to obtain sensitive information… | |
| Modificada | Media (4.3) | 15% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly allocate memory, which allows remote attackers to cause a denial of service via a crafted… | |
| Modificada | Alta (7.2) | 1.8% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/3/2015 | 17/6/2026 | The Windows Registry Virtualization feature in the kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict changes to virtual stores, which allows local users to gain… | |
| Modificada | Media (4.3) | 13% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 6/3/2015 | 17/6/2026 | Schannel (aka Secure Channel) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict TLS state transitions, which makes it easier for remote attackers to… | |
| Modificada | Media (4.3) | 19% | — | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 do not properly initialize memory for TIFF images, which allows remote attackers to obtain sensitive information from process… | |
| Modificada | Media (4.7) | 3.8% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | The font mapper in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly scale fonts, which allows local users to cause a… | |
| Modificada | Alta (7.2) | 13% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges via a crafted application, aka "Win32k Elevation… | |
| Modificada | Baja (1.9) | 2.5% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | The CryptProtectMemory function in cng.sys (aka the Cryptography Next Generation driver) in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1, when the… | |
| Modificada | Baja (3.3) | 8.1% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows man-in-the-middle attackers to disable a signing… | |
| Modificada | Alta (8.3) | 29% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | The UNC implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not include authentication from the server to the client, which allows remote attackers to execute… | |
| Modificada | Media (6.9) | 4.5% | 💥 Exploit | Microsoft Windows 7Microsoft Windows 8Microsoft Windows 8.1Microsoft Windows RT+5 | 11/2/2015 | 17/6/2026 | win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (NULL pointer… |