Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
681 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 73% | 💥 PoC | Google ChromeApple Iphone OSApple MAC OS XApple MAC OS X Server+3 | 16/2/2012 | 16/6/2026 | Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation. | |
| Modificada | Media (4.3) | 1.7% | — | Google ChromeXmlsoft LibxsltSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 9/2/2012 | 16/6/2026 | libxslt, as used in Google Chrome before 17.0.963.46, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | |
| Modificada | Alta (9.3) | 5.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+4 | 1/2/2012 | 16/6/2026 | Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document. | |
| Modificada | Alta (10) | 7.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+5 | 1/2/2012 | 16/6/2026 | Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize nsChildView data structures, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via… | |
| Modificada | Alta (9.3) | 4.5% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+4 | 1/2/2012 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via… | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdOpensuse+3 | 1/2/2012 | 16/6/2026 | Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed… | |
| Modificada | Media (4.3) | 82% | 💥 Exploit | Apache Http ServerDebian LinuxOpensuseSuse Linux Enterprise Server+7 | 28/1/2012 | 16/6/2026 | protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with… | |
| Modificada | Baja (2.1) | 0.47% | — | Linux KernelSuse Linux Enterprise Server | 27/1/2012 | 16/6/2026 | The cleanup_journal_tail function in the Journaling Block Device (JBD) functionality in the Linux kernel 2.6 allows local users to cause a denial of service (assertion error and kernel oops) via an ext3 or ext4 image with an "invalid log first block value." | |
| Modificada | Media (4.6) | 2.8% | 💥 Exploit | Apache Http ServerDebian LinuxOpensuseSuse Linux Enterprise Server+8 | 18/1/2012 | 16/6/2026 | scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function. | |
| Modificada | Alta (7.5) | 2.4% | — | Google ChromeApple Iphone OSApple MAC OS XSuse Linux Enterprise Server+5 | 7/1/2012 | 16/6/2026 | Heap-based buffer overflow in libxml2, as used in Google Chrome before 16.0.912.75, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | |
| Modificada | Alta (10) | 95% | 💥 Exploit | GNU InetutilsHeimdal Project HeimdalMIT Krb5-applFreebsd+6 | 25/12/2011 | 16/6/2026 | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the… | |
| Modificada | Media (6.8) | 10% | — | Jasper Project JasperOracle Outside IN TechnologyCanonical Ubuntu LinuxDebian Linux+5 | 15/12/2011 | 16/6/2026 | The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component… | |
| Modificada | Media (6.8) | 10% | — | Jasper Project JasperOracle Outside IN TechnologyCanonical Ubuntu LinuxDebian Linux+4 | 15/12/2011 | 16/6/2026 | Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file. | |
| Modificada | Alta (9.3) | 5.3% | — | Apple Iphone OSSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT | 11/11/2011 | 16/6/2026 | FreeType in CoreGraphics in Apple iOS before 5.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font in a document. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Oracle JDKOracle JRECanonical Ubuntu LinuxRedhat Satellite With Embedded Oracle+2 | 19/10/2011 | 16/6/2026 | Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Scripting. | |
| Modificada | Alta (7.8) | 99% | 💥 Exploit | Apache Http ServerOpensuseSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+1 | 29/8/2011 | 16/6/2026 | The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attackers to cause a denial of service (memory and CPU consumption) via a Range header that expresses multiple overlapping ranges, as exploited in the wild in August 2011, a different vulnerability than… | |
| Modificada | Media (6.5) | 3.9% | — | MIT Krb5-applDebian LinuxFedoraproject FedoraOpensuse+3 | 11/7/2011 | 16/6/2026 | ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related… | |
| Modificada | Media (4.3) | 30% | 💥 Exploit | Apache Portable RuntimeApache Http ServerApple MAC OS XFreebsd+6 | 16/5/2011 | 16/6/2026 | Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent… | |
| Modificada | Baja (2.1) | 0.41% | — | Linux KernelSuse Linux Enterprise ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+3 | 10/4/2011 | 16/6/2026 | The osf_partition function in fs/partitions/osf.c in the Linux kernel before 2.6.38 does not properly handle an invalid number of partitions, which might allow local users to obtain potentially sensitive information from kernel heap memory via vectors related to partition-table parsing. | |
| Modificada | Media (4.9) | 0.80% | 💥 Exploit | Linux KernelSuse Linux Enterprise DesktopSuse Linux Enterprise ServerRedhat Enterprise Linux Desktop+2 | 4/4/2011 | 16/6/2026 | The epoll implementation in the Linux kernel 2.6.37.2 and earlier does not properly traverse a tree of epoll file descriptors, which allows local users to cause a denial of service (CPU consumption) via a crafted application that makes epoll_create and epoll_ctl system calls. | |
| Modificada | Media (4) | 74% | 💥 Exploit | Vsftpd Project VsftpdCanonical Ubuntu LinuxFedoraproject FedoraDebian Linux+2 | 2/3/2011 | 16/6/2026 | The vsf_filename_passes_filter function in ls.c in vsftpd before 2.3.3 allows remote authenticated users to cause a denial of service (CPU consumption and process slot exhaustion) via crafted glob expressions in STAT commands in multiple FTP sessions, a different vulnerability than CVE-2010-2632. | |
| Modificada | Media (6.9) | 0.53% | — | Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 7/1/2011 | 16/6/2026 | Multiple integer overflows in the (1) pppol2tp_sendmsg function in net/l2tp/l2tp_ppp.c, and the (2) l2tp_ip_sendmsg function in net/l2tp/l2tp_ip.c, in the PPPoL2TP and IPoL2TP implementations in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (heap memory corruption and panic) or… | |
| Modificada | Alta (7.8) | 4.3% | — | Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+3 | 3/1/2011 | 16/6/2026 | Multiple integer underflows in the x25_parse_facilities function in net/x25/x25_facilities.c in the Linux kernel before 2.6.36.2 allow remote attackers to cause a denial of service (system crash) via malformed X.25 (1) X25_FAC_CLASS_A, (2) X25_FAC_CLASS_B, (3) X25_FAC_CLASS_C, or (4) X25_FAC_CLASS_D facility data, a… | |
| Modificada | Media (4.7) | 0.39% | — | Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+1 | 3/1/2011 | 16/6/2026 | The blk_rq_map_user_iov function in block/blk-map.c in the Linux kernel before 2.6.36.2 allows local users to cause a denial of service (panic) via a zero-length I/O request in a device ioctl to a SCSI device. | |
| Modificada | Media (4.7) | 0.39% | — | Linux KernelFedoraproject FedoraOpensuseSuse Linux Enterprise Desktop+3 | 3/1/2011 | 16/6/2026 | Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device. |