Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

681 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)5.6%—LibtiffOpensuse LeapSuse Linux Enterprise DesktopSuse Linux Enterprise Server+121/3/201917/6/2026
LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue
ModificadaAlta (8.1)5.0%—Golang GOOpensuse Backports SLEOpensuse LeapSuse Linux Enterprise Server+114/12/201817/6/2026
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the import path of a malicious Go package which contains curly braces (both '{' and '}' characters). Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the distinction is…
ModificadaAlta (8.1)66%—Golang GOOpensuse Backports SLEOpensuse LeapSuse Linux Enterprise Server+114/12/201817/6/2026
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -u flag and the import path of a malicious Go package, or a package that imports it directly or indirectly. Specifically, it is only vulnerable in GOPATH mode, but not in module mode (the…
ModificadaAlta (8.8)2.9%—Dcraw Project DcrawSuse Linux Enterprise DesktopSuse Linux Enterprise Server29/11/201817/6/2026
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
ModificadaAlta (7.5)41%—Nodejs Node.jsSuse Enterprise StorageSuse Linux Enterprise ServerSuse Openstack Cloud28/11/201817/6/2026
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connections and associated resources alive for a long period of time.
ModificadaAlta (7.5)4.6%—Nodejs Node.jsSuse Enterprise StorageSuse Linux Enterprise ServerSuse Openstack Cloud28/11/201817/6/2026
Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provided which will trigger a second, unexpected, and user-defined HTTP request to made to the same…
ModificadaAlta (7.8)1.6%—Jasper Project JasperCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Desktop+126/11/201817/6/2026
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
ModificadaMedia (6.5)1.9%—Jasper Project JasperCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+226/11/201817/6/2026
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function jp2_decode in libjasper/jp2/jp2_dec.c, leading to a denial of service.
ModificadaAlta (8.8)2.8%—Jasper Project JasperCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server+126/11/201817/6/2026
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5,…
ModificadaAlta (8.8)2.3%—Jasper Project JasperSuse Linux Enterprise DesktopSuse Linux Enterprise ServerDebian Linux26/11/201817/6/2026
An issue was discovered in JasPer 1.900.8, 1.900.9, 1.900.10, 1.900.11, 1.900.12, 1.900.13, 1.900.14, 1.900.15, 1.900.16, 1.900.17, 1.900.18, 1.900.19, 1.900.20, 1.900.21, 1.900.22, 1.900.23, 1.900.24, 1.900.25, 1.900.26, 1.900.27, 1.900.28, 1.900.29, 1.900.30, 1.900.31, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5,…
ModificadaMedia (6.5)1.9%—Jasper Project JasperSuse Linux Enterprise DesktopSuse Linux Enterprise ServerDebian Linux+126/11/201817/6/2026
An issue was discovered in JasPer 2.0.14. There is an access violation in the function jas_image_readcmpt in libjasper/base/jas_image.c, leading to a denial of service.
ModificadaMedia (6.5)1.5%—Libwpd Project LibwpdRedhat Enterprise LinuxSuse Linux Enterprise Server12/11/201817/6/2026
In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.
ModificadaAlta (7.5)14%—LighttpdOpensuse Backports SLEOpensuse LeapSuse Linux Enterprise Server+17/11/201817/6/2026
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does…
ModificadaMedia (5.5)1.4%—Jasper Project JasperCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Desktop+131/10/201817/6/2026
An issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
ModificadaMedia (4.3)3.1%—Kyzer LibmspackDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+423/10/201817/6/2026
chmd_read_headers in mspack/chmd.c in libmspack before 0.8alpha accepts a filename that has '\0' as its first or second character (such as the "/\0" name).
ModificadaMedia (6.5)3.1%—Cabextract Project CabextractLibmspack Project LibmspackDebian LinuxRedhat Enterprise Linux+323/10/201817/6/2026
In mspack/cab.h in libmspack before 0.8alpha and cabextract before 1.8, the CAB block input buffer is one byte too small for the maximal Quantum block, leading to an out-of-bounds write.
ModificadaAlta (7.5)4.5%—QemuCanonical Ubuntu LinuxDebian LinuxOracle Linux+29/10/201817/6/2026
Qemu has a Buffer Overflow in pcnet_receive in hw/net/pcnet.c because an incorrect integer data type is used.
ModificadaCrítica (9.8)1.8%—Suse Linux Enterprise ServerPidgin5/9/201817/6/2026
Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploitable via custom X.509 certificate from another client. This…
ModificadaBaja (3.3)0.35%—Canonical Ubuntu LinuxLinuxcontainers LXCSuse Caas PlatformSuse Openstack Cloud+210/8/201817/6/2026
lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of…
ModificadaMedia (5.3)0.78%—Suse Linux Enterprise DesktopSuse Linux Enterprise Server8/6/201816/6/2026
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the…
ModificadaCrítica (9.8)1.0%—Suse Linux Enterprise Server8/6/201816/6/2026
A vulnerability in pam_modules of SUSE Linux Enterprise allows attackers to log into accounts that should have been disabled. Affected releases are SUSE Linux Enterprise: versions prior to 12.
ModificadaAlta (7.8)0.47%—Linux KernelSuse Linux Enterprise Module FOR Public CloudSuse Linux Enterprise ServerCanonical Ubuntu Linux+830/3/201817/6/2026
The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user.
ModificadaAlta (7)1.00%—PostgresqlSuse Linux Enterprise Server1/3/201817/6/2026
A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.
ModificadaMedia (5.6)94%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+3044/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
ModificadaCrítica (9.8)53%—Linux KernelDebian LinuxArista EOSF5 ARX+253/1/201817/6/2026
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.