Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
937 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.43% | — | Yast2-rmt Project Yast2-rmtOpensuse LeapSuse Linux Enterprise Server | 27/1/2020 | 17/6/2026 | A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affects: SUSE Linux Enterprise Server 15 yast2-rmt versions prior to 1.2.2. openSUSE Leap yast2-rmt… | |
| Modificada | Baja (3.3) | 0.27% | — | Suse Linux Enterprise Server | 24/1/2020 | 17/6/2026 | The permission package in SUSE Linux Enterprise Server allowed all local users to run dumpcap in the "easy" permission profile and sniff network traffic. This issue affects: SUSE Linux Enterprise Server permissions versions starting from 85c83fef7e017f8ab7f8602d3163786d57344439 to… | |
| Modificada | Media (6.5) | 3.6% | — | QemuFedoraproject FedoraCanonical Ubuntu LinuxSuse Linux Enterprise Debuginfo+4 | 23/1/2020 | 17/6/2026 | Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. | |
| Modificada | Alta (8.8) | 39% | — | PhpmyadminSuse Linux Enterprise ServerDebian Linux | 9/1/2020 | 17/6/2026 | In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker must have a valid MySQL account to access the server. | |
| Modificada | Alta (8.8) | 1.1% | — | Obs-serverSuse Linux Enterprise Server | 2/1/2020 | 16/6/2026 | obs-server before 1.7.7 allows logins by 'unconfirmed' accounts due to a bug in the REST api implementation. | |
| Modificada | Alta (7.5) | 3.2% | — | EglibcNovell Suse Linux Enterprise ServerDebian LinuxCanonical Ubuntu Linux+1 | 31/12/2019 | 16/6/2026 | The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service. | |
| Modificada | Alta (8.8) | 1.9% | — | Google ChromeDebian LinuxFedoraproject FedoraNovell Suse Package HUB FOR Suse Linux Enterprise+5 | 10/12/2019 | 17/6/2026 | Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | |
| Modificada | Alta (8.8) | 2.0% | — | Canonical Cloud-initDebian LinuxSuse Linux Enterprise Server | 25/11/2019 | 16/6/2026 | An privilege elevation vulnerability exists in Cloud-init before 0.7.0 when requests to an untrusted system are submitted for EC2 instance data. | |
| Modificada | Alta (7.5) | 2.3% | — | Mozilla NSSDebian LinuxRedhat Enterprise LinuxSuse Linux Enterprise Server+23 | 15/11/2019 | 17/6/2026 | A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service. | |
| Modificada | Alta (7.1) | 0.34% | — | Suse Linux Enterprise Server | 7/10/2019 | 17/6/2026 | The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 permissions. This allowed an attacker that compromissed the squid user to gain persistence by… | |
| Modificada | Alta (8.3) | 2.6% | — | Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux+2 | 23/7/2019 | 17/6/2026 | As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | |
| Modificada | Media (5.3) | 2.1% | — | Mozilla FirefoxMozilla ThunderbirdDebian LinuxNovell Suse Package HUB FOR Suse Linux Enterprise+1 | 23/7/2019 | 17/6/2026 | A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8. | |
| Modificada | Media (5.3) | 4.3% | — | LibgdPHPCanonical Ubuntu LinuxDebian Linux+9 | 19/6/2019 | 17/6/2026 | When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead… | |
| Modificada | Alta (8.8) | 2.4% | — | FfmpegDebian LinuxNovell Suse Package HUB FOR Suse Linux EnterpriseCanonical Ubuntu Linux | 19/4/2019 | 17/6/2026 | libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data. | |
| Modificada | Alta (7.5) | 5.6% | — | LibtiffOpensuse LeapSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 21/3/2019 | 17/6/2026 | LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue | |
| Modificada | Alta (8.1) | 5.0% | — | Golang GOOpensuse Backports SLEOpensuse LeapSuse Linux Enterprise Server+1 | 14/12/2018 | 17/6/2026 | In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is… | |
| Modificada | Alta (8.1) | 66% | — | Golang GOOpensuse Backports SLEOpensuse LeapSuse Linux Enterprise Server+1 | 14/12/2018 | 17/6/2026 | In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the… | |
| Modificada | Alta (8.8) | 2.9% | — | Dcraw Project DcrawSuse Linux Enterprise DesktopSuse Linux Enterprise Server | 29/11/2018 | 17/6/2026 | A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file. | |
| Modificada | Alta (7.5) | 41% | — | Nodejs Node.jsSuse Enterprise StorageSuse Linux Enterprise ServerSuse Openstack Cloud | 28/11/2018 | 17/6/2026 | Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time. | |
| Modificada | Alta (7.5) | 4.6% | — | Nodejs Node.jsSuse Enterprise StorageSuse Linux Enterprise ServerSuse Openstack Cloud | 28/11/2018 | 17/6/2026 | Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same… | |
| Modificada | Alta (7.8) | 1.6% | — | Jasper Project JasperCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Desktop+1 | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c. | |
| Modificada | Media (6.5) | 1.9% | — | Jasper Project JasperCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service. | |
| Modificada | Alta (8.8) | 2.8% | — | Jasper Project JasperCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5,… | |
| Modificada | Alta (8.8) | 2.3% | — | Jasper Project JasperSuse Linux Enterprise DesktopSuse Linux Enterprise ServerDebian Linux | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5,… | |
| Modificada | Media (6.5) | 1.9% | — | Jasper Project JasperSuse Linux Enterprise DesktopSuse Linux Enterprise ServerDebian Linux+1 | 26/11/2018 | 17/6/2026 | An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service. |