Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
137 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 49% | ⚠ Explotación activa💥 Exploit | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 17/4/2018 | 17/6/2026 | The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any… | |
| Modificada | Alta (8.8) | 1.5% | — | Tibco Jasperreports ServerTibco Jasperreports LibraryTibco JaspersoftTibco Jaspersoft Reporting AND Analytics+1 | 17/4/2018 | 17/6/2026 | A vulnerability in the report scripting component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library Community Edition, TIBCO JasperReports Library for ActiveMatrix… | |
| Modificada | Media (6.5) | 2.0% | — | Jasper Project Jasper | 4/4/2018 | 17/6/2026 | JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c. | |
| Modificada | Media (5.5) | 1.7% | — | Jasper Project Jasper | 27/3/2018 | 17/6/2026 | JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_firstone in libjasper/jpc/jpc_math.c. | |
| Modificada | Media (6.5) | 1.5% | — | Jasper Project JasperCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+4 | 12/3/2018 | 17/6/2026 | JasPer before version 2.0.10 is vulnerable to a null pointer dereference was found in the decoded creation of JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash. | |
| Modificada | Media (5.5) | 1.4% | — | Jasper Project JasperRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+2 | 9/3/2018 | 17/6/2026 | JasPer before version 2.0.12 is vulnerable to a use-after-free in the way it decodes certain JPEG 2000 image files resulting in a crash on the application using JasPer. | |
| Modificada | Crítica (9.8) | 2.0% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 15/11/2017 | 17/6/2026 | A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contains a vulnerability which fails to prevent… | |
| Modificada | Media (5.4) | 0.69% | — | Tibco Jasperreports ServerTibco Jasperreports LibraryTibco JaspersoftTibco Jaspersoft Reporting AND Analytics+1 | 15/11/2017 | 17/6/2026 | A vulnerability in the report renderer component of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO JasperReports Library, TIBCO JasperReports Library for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, TIBCO Jaspersoft… | |
| Modificada | Media (6.5) | 1.0% | — | Jaspersoft Jasperreports | 2/10/2017 | 17/6/2026 | Jaspersoft JasperReports 4.7 suffers from a saved credential disclosure vulnerability, which allows a remote authenticated user to retrieve stored Data Source passwords by accessing flow.html and reading the HTML source code of the page reached in an Edit action for a Data Source connector. | |
| Modificada | Alta (7.5) | 3.0% | — | Jasper Project Jasper | 9/9/2017 | 17/6/2026 | There is an infinite loop in the jpc_dec_tileinit function in jpc/jpc_dec.c of Jasper 2.0.13. It will lead to a remote denial of service attack. | |
| Modificada | Media (6.5) | 2.2% | — | Jasper Project JasperDebian Linux | 4/9/2017 | 17/6/2026 | JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9,… | |
| Modificada | Alta (7.5) | 3.6% | — | Jasper Project JasperFedoraproject Fedora | 29/8/2017 | 17/6/2026 | There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack. | |
| Modificada | Alta (7.5) | 3.6% | — | Jasper Project JasperFedoraproject Fedora | 29/8/2017 | 17/6/2026 | There is a reachable assertion abort in the function calcstepsizes() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack. | |
| Modificada | Alta (7.5) | 3.7% | — | Jasper Project JasperFedoraproject Fedora | 29/8/2017 | 17/6/2026 | There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that will lead to a remote denial of service attack. | |
| Modificada | Alta (7.5) | 3.6% | — | Jasper Project JasperFedoraproject Fedora | 29/8/2017 | 17/6/2026 | There is a reachable assertion abort in the function jpc_pi_nextrpcl() in jpc/jpc_t2cod.c in JasPer 2.0.12 that will lead to a remote denial of service attack. | |
| Modificada | Alta (7.5) | 4.7% | — | Jasper Project JasperFedoraproject FedoraDebian Linux | 29/8/2017 | 17/6/2026 | There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack. | |
| Modificada | Alta (7.5) | 3.6% | — | Jasper Project JasperFedoraproject Fedora | 29/8/2017 | 17/6/2026 | There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a remote denial of service attack. | |
| Modificada | Alta (7.5) | 4.0% | — | Jasper Project JasperFedoraproject Fedora | 29/8/2017 | 17/6/2026 | There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial of service attack. | |
| Modificada | Alta (7.5) | 3.9% | — | Jasper Project Jasper | 29/8/2017 | 17/6/2026 | There is a reachable assertion abort in the function jpc_dec_process_sot() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack by triggering an unexpected jpc_ppmstabtostreams return value, a different vulnerability than CVE-2018-9154. | |
| Modificada | Media (5.5) | 1.9% | — | Fedoraproject FedoraOpensuse LeapOpensuseOpensuse Project Leap+1 | 2/8/2017 | 17/6/2026 | Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file. | |
| Modificada | Media (5.5) | 2.2% | — | Fedoraproject FedoraOpensuse LeapOpensuseOpensuse Project Leap+1 | 25/7/2017 | 17/6/2026 | Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file. | |
| Modificada | Alta (7.5) | 3.3% | — | Jasper Project JasperFedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 17/7/2017 | 17/6/2026 | JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service. | |
| Modificada | Media (6.5) | 1.3% | — | Tibco Jasperreports Library Community EditionTibco Jasperreports Library FOR Activematrix BPMTibco Jasperreports ProfessionalTibco Jasperreports Server+5 | 29/6/2017 | 17/6/2026 | JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versions 6.4.0 and below), TIBCO JasperReports Library for… | |
| Modificada | Alta (8.8) | 0.57% | — | Tibco Jasperreports ServerTibco JaspersoftTibco Jaspersoft Reporting AND Analytics | 29/6/2017 | 17/6/2026 | Multiple JasperReports Server components contain vulnerabilities which may allow authorized users to perform cross-site scripting (XSS) and cross-site request forgery (CSRF) attacks. The impact of this vulnerability includes the theoretical disclosure of sensitive information. Affects TIBCO JasperReports Server… | |
| Modificada | Media (5.5) | 1.6% | — | Jasper Project Jasper | 21/6/2017 | 17/6/2026 | JasPer 2.0.12 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted image, related to the jp2_decode function in libjasper/jp2/jp2_dec.c. |