Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

138 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.84%—Iodata Wn-ax1167gr Firmware2/8/201717/6/2026
WN-AX1167GR firmware version 3.00 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
ModificadaAlta (8.8)0.84%—Iodata Wn-ax1167gr Firmware2/8/201717/6/2026
WN-AX1167GR firmware version 3.00 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary code on the device.
ModificadaCrítica (9.8)4.5%—Fedoraproject FedoraX.org Libx1113/12/201617/6/2026
The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigger out-of-bounds write operations.
ModificadaCrítica (9.8)4.5%—Fedoraproject FedoraX.org Libx1113/12/201617/6/2026
The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, which triggers out-of-bounds read operations.
ModificadaAlta (7.5)4.3%—X.org Libx11Canonical Ubuntu LinuxDebian LinuxX.org X1116/4/201517/6/2026
Multiple off-by-one errors in the (1) MakeBigReq and (2) SetReqLen macros in include/X11/Xlibint.h in X11R6.x and libX11 before 1.6.0 allow remote attackers to have unspecified impact via a crafted request, which triggers a buffer overflow.
ModificadaMedia (6.5)4.4%—X.org X ServerX.org X11Debian Linux10/12/201417/6/2026
The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a…
ModificadaMedia (6.5)4.4%—X.org Xfree86X.org X ServerX.org X1110/12/201417/6/2026
The RandR extension in XFree86 4.2.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1)…
ModificadaMedia (6.5)4.4%—X.org Xfree86X.org X ServerX.org X1110/12/201417/6/2026
The Render extension in XFree86 4.0.1, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the…
ModificadaMedia (6.5)4.3%—X.org X11X.org X ServerX.org Xfree8610/12/201417/6/2026
The XVideo extension in XFree86 4.0.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the…
ModificadaMedia (6.5)5.2%—Debian LinuxX.org X ServerX.org Xfree86X.org X1110/12/201417/6/2026
The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1)…
ModificadaMedia (6.5)4.4%—X.org X ServerX.org X1110/12/201417/6/2026
The DBE extension in X.Org X Window System (aka X11 or X) X11R6.1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1)…
ModificadaMedia (6.5)4.6%—X.org X11X.org X ServerDebian Linux10/12/201417/6/2026
The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length…
ModificadaMedia (6.5)4.4%—Debian LinuxX.org X11X.org X Server10/12/201417/6/2026
The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authenticated users to cause a denial of service (out-of-bounds read or write) or possibly execute arbitrary code via a crafted length or index value to the (1)…
ModificadaMedia (6.5)4.4%—X.org X11X.org X ServerX.org Xfree8610/12/201417/6/2026
Multiple integer overflows in the GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1)…
ModificadaMedia (6.5)4.4%—X.org X11X.org X Server10/12/201417/6/2026
Multiple integer overflows in X.Org X Window System (aka X11 or X) X11R1 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted request to the (1) ProcPutImage, (2) GetHosts, (3) RegionSizeof,…
ModificadaMedia (4.3)4.2%—X.org X ServerX.org X1110/12/201417/6/2026
X.Org X Window System (aka X11 and X) X11R5 and X.Org Server (aka xserver and xorg-server) before 1.16.3, when using SUN-DES-1 (Secure RPC) authentication credentials, does not check the return value of a malloc call, which allows remote attackers to cause a denial of service (NULL pointer dereference and server…
ModificadaMedia (6.8)2.0%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+914/10/201417/6/2026
The Juniper SRX Series devices with Junos 11.4 before 11.4R12-S4, 12.1X44 before 12.1X44-D40, 12.1X45 before 12.1X45-D30, 12.1X46 before 12.1X46-D25, and 12.1X47 before 12.1X47-D10, when an Application Layer Gateway (ALG) is enabled, allows remote attackers to cause a denial of service (flowd crash) via a crafted…
ModificadaMedia (5.4)1.7%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+911/7/201417/6/2026
Juniper Junos 11.4 before 11.4R8, 12.1 before 12.1R5, 12.1X44 before 12.1X44-D20, 12.1X45 before 12.1X45-D15, 12.1X46 before 12.1X46-D10, and 12.1X47 before 12.1X47-D10 on SRX Series devices, allows remote attackers to cause a denial of service (flowd crash) via a malformed packet, related to translating IPv6 to IPv4.
ModificadaAlta (7.8)3.4%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+911/7/201417/6/2026
Juniper Junos 11.4 before 11.4R12, 12.1X44 before 12.1X44-D32, 12.1X45 before 12.1X45-D25, 12.1X46 before 12.1X46-D20, and 12.1X47 before 12.1X47-D10 on SRX Series devices, when NAT protocol translation from IPv4 to IPv6 is enabled, allows remote attackers to cause a denial of service (flowd hang or crash) via a…
ModificadaAlta (7.8)1.8%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+911/7/201417/6/2026
Juniper Junos 12.1X46 before 12.1X46-D20 and 12.1X47 before 12.1X47-D10 on SRX Series devices allows remote attackers to cause a denial of service (flowd crash) via a crafted SIP packet.
ModificadaMedia (5)1.6%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx210+414/4/201417/6/2026
Unspecified vulnerability in Juniper Junos before 11.4R10-S1, before 11.4R11, 12.1X44 before 12.1X44-D26, 12.1X44 before 12.1X44-D30, 12.1X45 before 12.1X45-D20, and 12.1X46 before 12.1X46-D10, when Dynamic IPsec VPN is configured, allows remote attackers to cause a denial of service (new Dynamic VPN connection…
ModificadaMedia (4.6)0.39%—X.org X11Xkeyboard Config Project Xkeyboard-config10/2/201416/6/2026
xkeyboard-config before 2.5 in X.Org before 7.6 enables certain XKB debugging functions by default, which allows physically proximate attackers to bypass an X screen lock via keyboard combinations that break the input grab.
ModificadaMedia (5.4)0.78%—Yamaha Fwx120Yamaha Rt105Yamaha Rt107eYamaha Rt140+1023/1/201417/6/2026
The OSPF implementation on Yamaha routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet…
ModificadaAlta (7.1)2.3%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+915/1/201417/6/2026
Juniper Junos 10.4S before 10.4S15, 10.4R before 10.4R16, 11.4 before 11.4R9, and 12.1R before 12.1R7 on SRX Series service gateways allows remote attackers to cause a denial of service (flowd crash) via a crafted IP packet.
ModificadaAlta (7.8)3.6%—Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+911/1/201417/6/2026
Juniper Junos before 10.4 before 10.4R16, 11.4 before 11.4R8, 12.1R before 12.1R7, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D10 on SRX Series service gateways, when used as a UAC enforcer and captive portal is enabled, allows remote attackers to cause a denial of service (flowd crash) via a crafted HTTP…
Orbitaley — Vulnerabilidades