Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
2067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.1% | — | Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 25/9/2018 | 17/6/2026 | Use after free in PDFium in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | |
| Modificada | Alta (7.5) | 7.2% | — | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 25/9/2018 | 17/6/2026 | Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (7.5) | 11% | — | PythonCanonical Ubuntu LinuxDebian LinuxFedoraproject Fedora+4 | 24/9/2018 | 7/10/2026 | Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and… | |
| Modificada | Alta (7.8) | 1.8% | — | Artifex GhostscriptCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+5 | 19/9/2018 | 17/6/2026 | Artifex Ghostscript before 9.25 allowed a user-writable error exception table, which could be used by remote attackers able to supply crafted PostScript to potentially overwrite or replace error handlers to inject code. | |
| Modificada | Alta (7.8) | 0.98% | — | Apache SpamassassinCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+3 | 17/9/2018 | 17/6/2026 | Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax. | |
| Modificada | Media (5.3) | 7.9% | — | Apache SpamassassinCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+3 | 17/9/2018 | 17/6/2026 | A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan timeouts. In Apache SpamAssassin, using HTML::Parser, we setup an object and hook into the begin… | |
| Modificada | Alta (7.5) | 2.6% | — | Fedoraproject 389 Directory ServerRedhat Enterprise Linux AUSRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 14/9/2018 | 17/6/2026 | A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service. | |
| Modificada | Alta (7.8) | 2.2% | — | Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+5 | 10/9/2018 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509. | |
| Modificada | Alta (7.5) | 32% | — | Linux KernelRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+47 | 6/9/2018 | 17/6/2026 | The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered… | |
| Modificada | Alta (7.5) | 2.4% | — | Fedoraproject 389 Directory ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+4 | 6/9/2018 | 17/6/2026 | A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash. | |
| Modificada | Media (5.5) | 1.9% | — | Artifex GhostscriptRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 5/9/2018 | 17/6/2026 | In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter. | |
| Modificada | Media (5.5) | 1.4% | — | Artifex GhostscriptCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+5 | 5/9/2018 | 17/6/2026 | In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter. | |
| Modificada | Alta (7.8) | 1.6% | — | Artifex GhostscriptRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+7 | 5/9/2018 | 17/6/2026 | In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact. | |
| Modificada | Media (5.5) | 1.4% | — | Artifex GhostscriptCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+5 | 5/9/2018 | 17/6/2026 | In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable. | |
| Modificada | Alta (7.8) | 1.9% | — | Debian LinuxArtifex GhostscriptCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+5 | 5/9/2018 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact. | |
| Modificada | Alta (7.8) | 92% | 💥 Exploit | Debian LinuxArtifex GhostscriptCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+4 | 5/9/2018 | 17/6/2026 | An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. | |
| Modificada | Alta (7.5) | 3.1% | — | GlusterfsRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 4/9/2018 | 17/6/2026 | A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value. | |
| Modificada | Media (5.5) | 1.7% | — | Littlecms Little CMS Color EngineCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 4/9/2018 | 17/6/2026 | Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile. | |
| Modificada | Crítica (9.8) | 3.7% | — | Elfutils Project ElfutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+3 | 3/9/2018 | 17/6/2026 | libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice. | |
| Modificada | Alta (7.5) | 3.9% | — | Libtirpc Project LibtirpcCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+4 | 30/8/2018 | 17/6/2026 | A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to… | |
| Modificada | Crítica (9.8) | 7.1% | — | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 29/8/2018 | 17/6/2026 | Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to privilege escalation. | |
| Modificada | Alta (7.5) | 32% | 💥 Exploit | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 29/8/2018 | 17/6/2026 | Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Alta (7.5) | 7.4% | — | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 29/8/2018 | 17/6/2026 | Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | |
| Modificada | Crítica (9.8) | 7.1% | — | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 29/8/2018 | 17/6/2026 | Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass. | |
| Modificada | Media (5.9) | 11% | — | Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 29/8/2018 | 17/6/2026 | Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. |