Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
623 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 4.2% | — | Debian LinuxOpensuseFedoraproject FedoraOracle Solaris+8 | 8/2/2015 | 17/6/2026 | Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row. | |
| Modificada | Media (6.8) | 3.9% | — | Canonical Ubuntu LinuxFreetypeRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+8 | 8/2/2015 | 17/6/2026 | Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT table. | |
| Modificada | Media (6.8) | 3.5% | — | Debian LinuxCanonical Ubuntu LinuxFedoraproject FedoraFreetype+7 | 8/2/2015 | 17/6/2026 | sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table. | |
| Modificada | Media (6.8) | 4.2% | — | OpensuseOracle SolarisCanonical Ubuntu LinuxDebian Linux+8 | 8/2/2015 | 17/6/2026 | The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count value, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted… | |
| Modificada | Media (6.8) | 4.3% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+8 | 8/2/2015 | 17/6/2026 | FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c. | |
| Modificada | Alta (7.5) | 5.1% | — | FreetypeDebian LinuxOpensuseFedoraproject Fedora+8 | 8/2/2015 | 17/6/2026 | The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely calculated, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted cmap SFNT table. | |
| Modificada | Alta (7.5) | 4.4% | — | Canonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+7 | 8/2/2015 | 17/6/2026 | type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted Type42 font. | |
| Modificada | Alta (7.5) | 5.1% | — | OpensuseCanonical Ubuntu LinuxDebian LinuxOracle Solaris+8 | 8/2/2015 | 17/6/2026 | The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted BDF font. | |
| Modificada | Alta (7.5) | 5.1% | — | Oracle SolarisCanonical Ubuntu LinuxFedoraproject FedoraFreetype+8 | 8/2/2015 | 17/6/2026 | The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font. | |
| Modificada | Alta (7.5) | 5.1% | — | OpensuseRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+8 | 8/2/2015 | 17/6/2026 | The tt_face_load_hdmx function in truetype/ttpload.c in FreeType before 2.5.4 does not establish a minimum record size, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font. | |
| Modificada | Baja (2.1) | 0.56% | — | Linux KernelRedhat Enterprise Linux AUSRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+15 | 9/1/2015 | 17/6/2026 | The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD. | |
| Modificada | Baja (2.1) | 0.46% | — | Linux KernelRedhat Enterprise Linux AUSRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+15 | 9/1/2015 | 17/6/2026 | The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image. | |
| Modificada | Media (6.9) | 0.34% | — | Linux KernelRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+7 | 9/1/2015 | 17/6/2026 | Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that trigger access to a key structure member during garbage collection… | |
| Modificada | Media (5) | 11% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+4 | 18/12/2014 | 17/6/2026 | The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist. | |
| Modificada | Alta (9.4) | 3.6% | — | Uninett MOD Auth MellonRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+3 | 14/11/2014 | 17/6/2026 | The mod_auth_mellon module before 0.8.1 allows remote attackers to cause a denial of service (Apache HTTP server crash) via a crafted logout request that triggers a read of uninitialized data. | |
| Modificada | Media (6.5) | 7.8% | — | Fedoraproject FedoraDebian LinuxRedhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUS+1 | 30/9/2014 | 17/6/2026 | Multiple stack-based buffer overflows in the File Transfer feature in rfbserver.c in LibVNCServer 0.9.9 and earlier allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a (1) long file or (2) directory name or the (3) FileTime attribute in a rfbFileTransferOffer… | |
| Modificada | Alta (7.5) | 8.3% | — | Redhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUSFedoraproject FedoraLibvncserver+2 | 30/9/2014 | 17/6/2026 | Integer overflow in the MallocFrameBuffer function in vncviewer.c in LibVNCServer 0.9.9 and earlier allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via an advertisement for a large screen size, which triggers a heap-based buffer overflow. | |
| Modificada | Media (4) | 7.4% | — | OpensuseApache SubversionCanonical Ubuntu LinuxApple Xcode+5 | 19/8/2014 | 17/6/2026 | Apache Subversion 1.0.0 through 1.7.x before 1.7.17 and 1.8.x before 1.8.10 uses an MD5 hash of the URL and authentication realm to store cached credentials, which makes it easier for remote servers to obtain the credentials via a crafted authentication realm. | |
| Modificada | Media (5) | 7.1% | — | MIT Kerberos 5Redhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+6 | 20/7/2014 | 17/6/2026 | MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session. | |
| Analizada | Media (5.5) | 22% | ⚠ Explotación activa💥 Exploit | Linux KernelDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUS+26 | 7/5/2014 | 17/6/2026 | The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and… | |
| Modificada | Crítica (9.8) | 4.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+11 | 30/4/2014 | 17/6/2026 | Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption)… | |
| Modificada | Alta (8.8) | 5.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+11 | 30/4/2014 | 17/6/2026 | Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors… | |
| Modificada | Media (6.1) | 1.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+11 | 30/4/2014 | 17/6/2026 | The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs… | |
| Modificada | Alta (8.8) | 3.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+11 | 30/4/2014 | 17/6/2026 | The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code in a privileged context via a crafted web page for which… | |
| Modificada | Crítica (9.8) | 7.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+11 | 30/4/2014 | 17/6/2026 | The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether objects are XBL objects, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer… |