Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

2003 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)7.9%—Apache SpamassassinCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+317/9/201817/6/2026
A denial of service vulnerability was identified that exists in Apache SpamAssassin before 3.4.2. The vulnerability arises with certain unclosed tags in emails that cause markup to be handled incorrectly leading to scan timeouts. In Apache SpamAssassin, using HTML::Parser, we setup an object and hook into the begin…
ModificadaAlta (7.5)2.6%—Fedoraproject 389 Directory ServerRedhat Enterprise Linux AUSRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+314/9/201817/6/2026
A flaw was found in 389-ds-base before version 1.3.8.4-13. The process ns-slapd crashes in delete_passwdPolicy function when persistent search connections are terminated unexpectedly leading to remote denial of service.
ModificadaAlta (7.8)2.2%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+510/9/201817/6/2026
An issue was discovered in Artifex Ghostscript before 9.25. Incorrect "restoration of privilege" checking when running out of stack during exception handling could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction. This is due to an incomplete fix for CVE-2018-16509.
ModificadaAlta (7.5)32%—Linux KernelRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+476/9/201817/6/2026
The Linux kernel, versions 3.9+, is vulnerable to a denial of service attack with low rates of specially modified packets targeting IP fragment re-assembly. An attacker may cause a denial of service condition by sending specially crafted IP fragments. Various vulnerabilities in IP fragmentation have been discovered…
ModificadaAlta (7.5)2.4%—Fedoraproject 389 Directory ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+46/9/201817/6/2026
A vulnerability was discovered in 389-ds-base through versions 1.3.7.10, 1.3.8.8 and 1.4.0.16. The lock controlling the error log was not correctly used when re-opening the log file in log__error_emergency(). An attacker could send a flood of modifications to a very large DN, which would cause slapd to crash.
ModificadaMedia (5.5)1.9%—Artifex GhostscriptRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+45/9/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.
ModificadaMedia (5.5)1.4%—Artifex GhostscriptCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+55/9/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.
ModificadaAlta (7.8)1.6%—Artifex GhostscriptRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+75/9/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.
ModificadaMedia (5.5)1.4%—Artifex GhostscriptCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux Desktop+55/9/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.
ModificadaAlta (7.8)1.9%—Debian LinuxArtifex GhostscriptCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+55/9/201817/6/2026
An issue was discovered in Artifex Ghostscript before 9.24. A type confusion in "ztype" could be used by remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact.
ModificadaAlta (7.8)92%💥 ExploitDebian LinuxArtifex GhostscriptCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+45/9/201817/6/2026
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.
ModificadaAlta (7.5)3.1%—GlusterfsRedhat Virtualization HostRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+34/9/201817/6/2026
A flaw was found in the way dic_unserialize function of glusterfs does not handle negative key length values. An attacker could use this flaw to read memory from other locations into the stored dict value.
ModificadaMedia (5.5)1.7%—Littlecms Little CMS Color EngineCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+24/9/201817/6/2026
Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.
ModificadaCrítica (9.8)3.7%—Elfutils Project ElfutilsDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+33/9/201817/6/2026
libelf/elf_end.c in elfutils 0.173 allows remote attackers to cause a denial of service (double free and application crash) or possibly have unspecified other impact because it tries to decompress twice.
ModificadaAlta (7.5)3.9%—Libtirpc Project LibtirpcCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+430/8/201817/6/2026
A null-pointer dereference vulnerability was found in libtirpc before version 0.3.3-rc3. The return value of makefd_xprt() was not checked in all instances, which could lead to a crash when the server exhausted the maximum number of available file descriptors. A remote attacker could cause an rpc-based application to…
ModificadaCrítica (9.8)7.1%—Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation29/8/201817/6/2026
Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to privilege escalation.
ModificadaAlta (7.5)32%💥 ExploitAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation29/8/201817/6/2026
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaAlta (7.5)7.4%—Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation29/8/201817/6/2026
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaCrítica (9.8)7.1%—Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation29/8/201817/6/2026
Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass.
ModificadaMedia (5.9)11%—Adobe Flash Player Desktop RuntimeAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+129/8/201817/6/2026
Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
ModificadaMedia (5.5)1.6%—Elfutils Project ElfutilsDebian LinuxOpensuse LeapCanonical Ubuntu Linux+329/8/201817/6/2026
dwarf_getaranges in dwarf_getaranges.c in libdw in elfutils before 2018-08-18 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.
ModificadaMedia (6.1)1.2%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+128/8/201817/6/2026
Inappropriate implementation in V8 WebAssembly JS bindings in Google Chrome prior to 63.0.3239.108 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page.
ModificadaAlta (8.8)4.9%—Google ChromeDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+128/8/201817/6/2026
A use after free in V8 in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaCrítica (9.8)3.8%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+128/8/201817/6/2026
A stack buffer overflow in the QUIC networking stack in Google Chrome prior to 62.0.3202.89 allowed a remote attacker to gain code execution via a malicious server.
ModificadaMedia (6.5)2.2%—Google ChromeRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+228/8/201817/6/2026
A stack buffer overflow in NumberingSystem in International Components for Unicode (ICU) for C/C++ before 60.2, as used in V8 in Google Chrome prior to 62.0.3202.75 and other products, allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.