Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2627▼ 298 respecto a la semana anterior
Críticas / altas1348▲ 77 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 463 respecto a la semana anterior
167 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.6) | 4.6% | — | Debian LinuxOpenocd Open On-chip Debugger | 16/1/2018 | 17/6/2026 | Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site. | |
| Modificada | Crítica (9.8) | 53% | — | Linux KernelDebian LinuxArista EOSF5 ARX+25 | 3/1/2018 | 17/6/2026 | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action. | |
| Modificada | Crítica (9.8) | 85% | — | Thekelleys DnsmasqRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+17 | 4/10/2017 | 17/6/2026 | Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response. | |
| Modificada | Alta (7.5) | 9.1% | — | Fedoraproject FedoraSuse Linux Enterprise DebuginfoOpensuse LeapOpensuse+16 | 21/7/2017 | 17/6/2026 | The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to… | |
| Modificada | Alta (7.5) | 5.8% | — | Fedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise ServerSuse Manager+14 | 21/7/2017 | 17/6/2026 | The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet. | |
| Modificada | Alta (7.5) | 5.5% | — | Fedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise ServerSuse Manager+9 | 21/7/2017 | 17/6/2026 | The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands. | |
| Modificada | Alta (7.7) | 5.6% | — | QemuCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Debuginfo+6 | 13/4/2017 | 17/6/2026 | Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption). | |
| Modificada | Alta (7.5) | 3.7% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+5 | 20/3/2017 | 17/6/2026 | ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash). | |
| Modificada | Alta (7.5) | 3.6% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+5 | 20/3/2017 | 17/6/2026 | The png coder in ImageMagick allows remote attackers to cause a denial of service (crash). | |
| Modificada | Crítica (9.8) | 4.6% | — | Opensuse Project Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+6 | 20/3/2017 | 17/6/2026 | The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact. | |
| Modificada | Crítica (9.8) | 4.9% | — | Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+7 | 20/3/2017 | 17/6/2026 | Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact. | |
| Modificada | Media (5.5) | 1.9% | — | Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+7 | 20/3/2017 | 17/6/2026 | The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file. | |
| Modificada | Media (5.5) | 2.1% | — | Suse Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+6 | 20/3/2017 | 17/6/2026 | The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file. | |
| Modificada | Alta (7.5) | 3.6% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+5 | 20/3/2017 | 17/6/2026 | Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors. | |
| Modificada | Media (5.5) | 1.8% | — | ImagemagickSuse Linux Enterprise DebuginfoNovell LeapOpensuse Leap+7 | 17/3/2017 | 17/6/2026 | Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file. | |
| Modificada | Media (5.5) | 1.9% | — | GraphicsmagickDebian LinuxSuse Linux Enterprise DebuginfoSuse Studio Onsite+3 | 3/2/2017 | 17/6/2026 | GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath function in magick/render.c. | |
| Modificada | Media (5.5) | 2.0% | — | GraphicsmagickDebian LinuxSuse Linux Enterprise DebuginfoSuse Studio Onsite+3 | 3/2/2017 | 17/6/2026 | Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c. | |
| Modificada | Media (4.3) | 3.5% | — | NTPSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+6 | 30/1/2017 | 17/6/2026 | The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename. | |
| Modificada | Crítica (9.8) | 9.7% | — | PHPSuse Linux Enterprise DebuginfoOpensuse LeapOpensuse+3 | 7/8/2016 | 17/6/2026 | Double free vulnerability in the php_wddx_process_data function in wddx.c in the WDDX extension in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted XML data that is mishandled in a… | |
| Modificada | Media (5.5) | 1.5% | — | GraphicsmagickSuse Linux Enterprise DebuginfoSuse Studio OnsiteSuse Linux Enterprise Software Development KIT+1 | 13/7/2016 | 17/6/2026 | The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted GIF file. | |
| Modificada | Alta (7.5) | 5.5% | — | Fedoraproject FedoraSuse Linux Enterprise Real Time ExtensionSuse Linux Enterprise DebuginfoSuse Linux Enterprise Server+7 | 27/6/2016 | 17/6/2026 | The rds_inc_info_copy function in net/rds/recv.c in the Linux kernel through 4.6.3 does not initialize a certain structure member, which allows remote attackers to obtain sensitive information from kernel stack memory by reading an RDS message. | |
| Modificada | Alta (7.8) | 1.4% | — | Linux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Desktop+6 | 27/6/2016 | 17/6/2026 | The ecryptfs_privileged_open function in fs/ecryptfs/kthread.c in the Linux kernel before 4.6.3 allows local users to gain privileges or cause a denial of service (stack memory consumption) via vectors involving crafted mmap calls for /proc pathnames, leading to recursive pagefault handling. | |
| Modificada | Crítica (9.8) | 50% | — | GraphicsmagickSuse Linux Enterprise DebuginfoSuse Studio OnsiteSuse Linux Enterprise Software Development KIT+10 | 10/6/2016 | 17/6/2026 | The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename. | |
| Modificada | Crítica (9.8) | 13% | — | Mozilla FirefoxApple MAC OS XSuse Linux Enterprise DebuginfoSuse Studio Onsite+10 | 26/5/2016 | 17/6/2026 | Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow. | |
| Modificada | Alta (7.8) | 0.51% | — | Canonical Ubuntu LinuxLinux KernelOracle LinuxNovell Suse Linux Enterprise Software Development KIT+2 | 23/5/2016 | 17/6/2026 | The get_rock_ridge_filename function in fs/isofs/rock.c in the Linux kernel before 4.5.5 mishandles NM (aka alternate name) entries containing \0 characters, which allows local users to obtain sensitive information from kernel memory or possibly have unspecified other impact via a crafted isofs filesystem. |