Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
85 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.3% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Studio OnsiteNovell Suse Linux Enterprise DebuginfoGraphicsmagick+1 | 23/11/2013 | 16/6/2026 | The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image. | |
| Analizada | Alta (8.8) | 83% | ⚠ Explotación activa💥 Exploit | Adobe AcrobatSuse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise | 13/1/2010 | 16/6/2026 | The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than… | |
| Analizada | Alta (7.8) | 82% | ⚠ Explotación activa💥 Exploit | Adobe AcrobatAdobe Acrobat ReaderSuse Linux Enterprise DebuginfoOpensuse+1 | 15/12/2009 | 16/6/2026 | Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009. | |
| Modificada | Alta (7.8) | 0.43% | — | Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxRedhat MRG Realtime+4 | 22/10/2009 | 16/6/2026 | The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls. | |
| Modificada | Baja (2.1) | 0.41% | — | Linux KernelSuse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise Desktop+9 | 20/10/2009 | 16/6/2026 | arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode. | |
| Modificada | Alta (7.1) | 3.8% | — | Linux KernelSuse Linux Enterprise DebuginfoSuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 15/9/2009 | 16/6/2026 | Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams. | |
| Modificada | Media (4.3) | 2.2% | — | Mozilla FirefoxFedoraproject FedoraSuse Linux Enterprise DebuginfoOpensuse+2 | 22/7/2009 | 16/6/2026 | Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass." | |
| Modificada | Baja (2.1) | 0.54% | — | Udev Project UdevSuse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise Desktop+4 | 17/4/2009 | 16/6/2026 | Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments. | |
| Modificada | Alta (7.2) | 80% | 💥 Exploit | Udev Project UdevSuse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise Desktop+5 | 17/4/2009 | 16/6/2026 | udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space. | |
| Modificada | Alta (9.3) | 3.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+9 | 13/11/2008 | 16/6/2026 | nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized,… |