Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
520 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.53% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Server | 23/3/2017 | 17/6/2026 | A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root). | |
| Modificada | Alta (7.5) | 3.7% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+5 | 20/3/2017 | 17/6/2026 | ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash). | |
| Modificada | Alta (7.5) | 3.6% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+4 | 20/3/2017 | 17/6/2026 | Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption). | |
| Modificada | Alta (7.5) | 3.6% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+5 | 20/3/2017 | 17/6/2026 | The png coder in ImageMagick allows remote attackers to cause a denial of service (crash). | |
| Modificada | Alta (7.5) | 3.7% | — | Opensuse LeapOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Desktop+6 | 20/3/2017 | 17/6/2026 | Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption). | |
| Modificada | Crítica (9.8) | 4.6% | — | Opensuse Project Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+6 | 20/3/2017 | 17/6/2026 | The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact. | |
| Modificada | Crítica (9.8) | 4.9% | — | Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+7 | 20/3/2017 | 17/6/2026 | Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact. | |
| Modificada | Media (5.5) | 1.9% | — | Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+7 | 20/3/2017 | 17/6/2026 | The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file. | |
| Modificada | Media (5.5) | 2.1% | — | Suse Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+6 | 20/3/2017 | 17/6/2026 | The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file. | |
| Modificada | Crítica (9.8) | 3.9% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+4 | 20/3/2017 | 17/6/2026 | The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors. | |
| Modificada | Alta (7.5) | 3.6% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+5 | 20/3/2017 | 17/6/2026 | Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors. | |
| Modificada | Crítica (9.8) | 3.9% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+4 | 20/3/2017 | 17/6/2026 | The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions." | |
| Modificada | Alta (7.5) | 3.7% | — | ImagemagickOpensuse LeapOpensuseSuse Linux Enterprise Server+3 | 17/3/2017 | 17/6/2026 | coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image." | |
| Modificada | Media (5.5) | 1.8% | — | ImagemagickSuse Linux Enterprise DebuginfoNovell LeapOpensuse Leap+7 | 17/3/2017 | 17/6/2026 | Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file. | |
| Modificada | Media (4.3) | 3.5% | — | NTPSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+6 | 30/1/2017 | 17/6/2026 | The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename. | |
| Modificada | Media (5.5) | 0.85% | — | Systemd Project SystemdNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+5 | 13/10/2016 | 17/6/2026 | The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled. | |
| Modificada | Alta (7.5) | 29% | — | Novell Suse Linux Enterprise Module FOR WEB ScriptingOpensslNodejs Node.js | 26/9/2016 | 17/6/2026 | crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation. | |
| Modificada | Media (5.9) | 42% | — | OpensslHP Icewall Federation AgentHP Icewall McrpHP Icewall SSO+5 | 26/9/2016 | 17/6/2026 | The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c. | |
| Modificada | Alta (7.5) | 63% | — | OpensslNodejs Node.jsNovell Suse Linux Enterprise Module FOR WEB Scripting | 26/9/2016 | 17/6/2026 | Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions. | |
| Modificada | Crítica (9.8) | 7.0% | — | ES Iperf3Novell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse+1 | 26/9/2016 | 17/6/2026 | The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow. | |
| Modificada | Media (5.5) | 5.4% | — | LibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+1 | 20/9/2016 | 17/6/2026 | The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file. | |
| Modificada | Media (6.5) | 2.9% | — | LibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+1 | 20/9/2016 | 17/6/2026 | The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file. | |
| Modificada | Media (5.5) | 2.1% | — | LibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+2 | 20/9/2016 | 17/6/2026 | The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct. | |
| Modificada | Alta (7.5) | 12% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerLibarchive+1 | 20/9/2016 | 17/6/2026 | The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file. | |
| Modificada | Media (5.5) | 1.9% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerCanonical Ubuntu Linux+1 | 20/9/2016 | 17/6/2026 | The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file. |