Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
551 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.6% | — | Libreswan | 1/7/2015 | 17/6/2026 | libreswan 3.9 through 3.12 allows remote attackers to cause a denial of service (daemon restart) via an IKEv1 packet with (1) unassigned bits set in the IPSEC DOI value or (2) the next payload value set to ISAKMP_NEXT_SAK. | |
| Modificada | Media (6.8) | 7.6% | — | Canonical Ubuntu LinuxDebian LinuxApache OpenofficeFedoraproject Fedora+4 | 28/4/2015 | 17/6/2026 | The HWP filter in LibreOffice before 4.3.7 and 4.4.x before 4.4.2 and Apache OpenOffice before 4.1.2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted HWP document, which triggers an out-of-bounds write. | |
| Modificada | Alta (7.5) | 1.8% | — | Openbsd Libressl | 29/12/2014 | 17/6/2026 | Double free vulnerability in the ssl_parse_clienthello_use_srtp_ext function in d1_srtp.c in LibreSSL before 2.1.2 allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a certain length-verification error during processing of a DTLS handshake. | |
| Modificada | Alta (7.5) | 4.1% | — | LibreofficeFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux | 26/11/2014 | 17/6/2026 | LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file. | |
| Modificada | Alta (7.5) | 5.1% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationCanonical Ubuntu Linux+2 | 7/11/2014 | 17/6/2026 | Use-after-free vulnerability in the socket manager of Impress Remote in LibreOffice 4.x before 4.2.7 and 4.3.x before 4.3.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to TCP port 1599. | |
| Modificada | Media (5.4) | 0.30% | — | Mercadolibre | 9/9/2014 | 17/6/2026 | The MercadoLibre (aka com.mercadolibre) application 3.8.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 11% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationApache Openoffice+1 | 27/8/2014 | 17/6/2026 | The OLE preview generation in Apache OpenOffice before 4.1.1 and OpenOffice.org (OOo) might allow remote attackers to embed arbitrary data into documents via crafted OLE objects. | |
| Modificada | Alta (9.3) | 15% | — | Apache OpenofficeLibreoffice | 26/8/2014 | 17/6/2026 | Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet. | |
| Modificada | Alta (10) | 3.9% | — | Fedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+3 | 3/7/2014 | 17/6/2026 | LibreOffice 4.2.4 executes unspecified VBA macros automatically, which has unspecified impact and attack vectors, possibly related to doc/docmacromode.cxx. | |
| Modificada | Media (5) | 2.5% | — | Libreswan | 26/1/2014 | 17/6/2026 | Libreswan 3.7 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon restart) via IKEv2 packets that lack expected payloads. | |
| Modificada | Media (5) | 2.5% | — | Libreswan | 16/1/2014 | 17/6/2026 | The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload. | |
| Modificada | Alta (9.3) | 1.6% | — | Libreswan | 9/1/2014 | 17/6/2026 | Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact and attack vectors, involving the /var/tmp/libreswan-nss-pwd temporary file. | |
| Modificada | Media (5) | 2.7% | — | Libreswan | 7/1/2014 | 16/6/2026 | Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid major number in an IKE packet. | |
| Modificada | Alta (9.3) | 4.6% | — | Djvulibre Project Djvulibre | 2/12/2013 | 16/6/2026 | DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DjVu (aka .djv) file. | |
| Modificada | Media (5.1) | 1.8% | — | Libreswan | 9/7/2013 | 16/6/2026 | Buffer overflow in the atodn function in libreswan 3.0 and 3.1, when Opportunistic Encryption is enabled and an RSA key is being used, allows remote attackers to cause a denial of service (pluto IKE daemon crash) and possibly execute arbitrary code via crafted DNS TXT records. NOTE: this might be the same… | |
| Modificada | Media (4.3) | 3.5% | — | LibreofficeSUN Openoffice.org | 19/11/2012 | 16/6/2026 | LibreOffice 3.5.x before 3.5.7.2 and 3.6.x before 3.6.1, and OpenOffice.org (OOo), allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted (1) odt file to vcllo.dll, (2) ODG (Drawing document) file to svxcorelo.dll, (3) PolyPolygon record in a .wmf (Window Meta File) file embedded… | |
| Modificada | Alta (7.5) | 7.0% | — | Apache OpenofficeLibreofficeCanonical Ubuntu LinuxDebian Linux+7 | 6/8/2012 | 16/6/2026 | Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect… | |
| Modificada | Alta (7.5) | 14% | — | LibreofficeDebian LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+6 | 21/6/2012 | 16/6/2026 | Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC… | |
| Modificada | Media (6.8) | 13% | — | Apache Openoffice.orgLibreoffice | 19/6/2012 | 16/6/2026 | Integer overflow in filter/source/msfilter/msdffimp.cxx in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the length of an Escher graphics record in a PowerPoint (.ppt)… | |
| Modificada | Media (6.5) | 14% | — | Librdf RaptorLibreofficeApache OpenofficeFedoraproject Fedora+9 | 17/6/2012 | 16/6/2026 | Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document. | |
| Modificada | Media (4.3) | 2.9% | — | LibreofficeSUN Openoffice.org | 21/10/2011 | 16/6/2026 | oowriter in OpenOffice.org 3.3.0 and LibreOffice before 3.4.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted DOC file that triggers an out-of-bounds read in the DOC sprm parser. | |
| Modificada | Alta (9.3) | 7.0% | — | Libreoffice | 21/7/2011 | 16/6/2026 | Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice before 3.3.3 allows remote attackers to execute arbitrary code via a crafted .lwp file. | |
| Modificada | Alta (7.8) | 2.8% | 💥 Exploit | Phplibre Registrotl | 17/10/2006 | 16/6/2026 | registroTL stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for /usuarios.dat. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Phplibre Tribunalibre | 17/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in ftag.php in TribunaLibre 3.12 Beta allows remote attackers to execute arbitrary PHP code via a URL in the mostrar parameter. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Phplibre Registrotl | 17/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in main.php in registroTL allows remote attackers to execute arbitrary PHP code via an ftp:// URL in the page parameter. |