Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

520 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.53%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Server23/3/201717/6/2026
A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root).
ModificadaAlta (7.5)3.7%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+520/3/201717/6/2026
ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
ModificadaAlta (7.5)3.6%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+420/3/201717/6/2026
Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).
ModificadaAlta (7.5)3.6%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+520/3/201717/6/2026
The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
ModificadaAlta (7.5)3.7%—Opensuse LeapOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Desktop+620/3/201717/6/2026
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
ModificadaCrítica (9.8)4.6%—Opensuse Project Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+620/3/201717/6/2026
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
ModificadaCrítica (9.8)4.9%—Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+720/3/201717/6/2026
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
ModificadaMedia (5.5)1.9%—Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+720/3/201717/6/2026
The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
ModificadaMedia (5.5)2.1%—Suse Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+620/3/201717/6/2026
The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
ModificadaCrítica (9.8)3.9%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+420/3/201717/6/2026
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
ModificadaAlta (7.5)3.6%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+520/3/201717/6/2026
Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
ModificadaCrítica (9.8)3.9%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+420/3/201717/6/2026
The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."
ModificadaAlta (7.5)3.7%—ImagemagickOpensuse LeapOpensuseSuse Linux Enterprise Server+317/3/201717/6/2026
coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image."
ModificadaMedia (5.5)1.8%—ImagemagickSuse Linux Enterprise DebuginfoNovell LeapOpensuse Leap+717/3/201717/6/2026
Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
ModificadaMedia (4.3)3.5%—NTPSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+630/1/201717/6/2026
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
ModificadaMedia (5.5)0.85%—Systemd Project SystemdNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+513/10/201617/6/2026
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
ModificadaAlta (7.5)29%—Novell Suse Linux Enterprise Module FOR WEB ScriptingOpensslNodejs Node.js26/9/201617/6/2026
crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation.
ModificadaMedia (5.9)42%—OpensslHP Icewall Federation AgentHP Icewall McrpHP Icewall SSO+526/9/201617/6/2026
The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c.
ModificadaAlta (7.5)63%—OpensslNodejs Node.jsNovell Suse Linux Enterprise Module FOR WEB Scripting26/9/201617/6/2026
Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions.
ModificadaCrítica (9.8)7.0%—ES Iperf3Novell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse+126/9/201617/6/2026
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
ModificadaMedia (5.5)5.4%—LibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+120/9/201617/6/2026
The archive_read_format_tar_read_header function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted tar file.
ModificadaMedia (6.5)2.9%—LibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+120/9/201617/6/2026
The process_extra function in libarchive before 3.2.0 uses the size field and a signed number in an offset, which allows remote attackers to cause a denial of service (crash) via a crafted zip file.
ModificadaMedia (5.5)2.1%—LibarchiveNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+220/9/201617/6/2026
The read_CodersInfo function in archive_read_support_format_7zip.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted 7z file, related to the _7z_folder struct.
ModificadaAlta (7.5)12%—Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerLibarchive+120/9/201617/6/2026
The ae_strtofflags function in archive_entry.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted mtree file.
ModificadaMedia (5.5)1.9%—Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerCanonical Ubuntu Linux+120/9/201617/6/2026
The _ar_read_header function in archive_read_support_format_ar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (out-of-bounds stack read) via a crafted ar file.
Orbitaley — Vulnerabilidades