Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2976▼ 107 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.7% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise ServerCanonical Ubuntu Linux+1 | 23/5/2016 | 17/6/2026 | The llc_cmsg_rcv function in net/llc/af_llc.c in the Linux kernel before 4.5.5 does not initialize a certain data structure, which allows attackers to obtain sensitive information from kernel stack memory by reading a message. | |
| Modificada | Media (6.2) | 0.55% | — | Canonical Ubuntu LinuxLinux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+7 | 23/5/2016 | 17/6/2026 | The proc_connectinfo function in drivers/usb/core/devio.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted USBDEVFS_CONNECTINFO ioctl call. | |
| Modificada | Crítica (9.6) | 4.2% | — | PHPCanonical Ubuntu LinuxOpensuse LeapOpensuse+2 | 22/5/2016 | 17/6/2026 | ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related… | |
| Analizada | Media (5.5) | 77% | ⚠ Explotación activa💥 Exploit | Redhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux FOR IBM Z Systems EUS+26 | 5/5/2016 | 17/6/2026 | The (1) HTTP and (2) FTP coders in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted image. | |
| Analizada | Media (5.5) | 75% | ⚠ Explotación activa💥 Exploit | Redhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z SystemsRedhat Enterprise Linux FOR IBM Z Systems EUS+26 | 5/5/2016 | 17/6/2026 | The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to delete arbitrary files via a crafted image. | |
| Modificada | Media (4.6) | 0.59% | — | Canonical Ubuntu LinuxNovell Suse Linux Enterprise Software Development KITSuse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Desktop+6 | 2/5/2016 | 17/6/2026 | Double free vulnerability in drivers/net/usb/cdc_ncm.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (system crash) or possibly have unspecified other impact by inserting a USB device with an invalid USB descriptor. | |
| Modificada | Media (4.6) | 0.59% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live PatchingNovell Suse Linux Enterprise Module FOR Public Cloud+5 | 2/5/2016 | 17/6/2026 | The ims_pcu_parse_cdc_data function in drivers/input/misc/ims-pcu.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (system crash) via a USB device without both a master and a slave interface. | |
| Modificada | Media (4.6) | 1.8% | 💥 Exploit | Canonical Ubuntu LinuxLinux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+6 | 2/5/2016 | 17/6/2026 | The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Media (4.6) | 0.55% | — | Linux KernelCanonical Ubuntu LinuxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+6 | 2/5/2016 | 17/6/2026 | The acm_probe function in drivers/usb/class/cdc-acm.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both a control and a data endpoint descriptor. | |
| Modificada | Media (4.6) | 0.55% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+6 | 2/5/2016 | 17/6/2026 | drivers/usb/serial/cypress_m8.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a USB device without both an interrupt-in and an interrupt-out endpoint descriptor, related to the cypress_generic_port_probe and… | |
| Modificada | Media (4.6) | 1.8% | 💥 Exploit | Linux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+5 | 2/5/2016 | 17/6/2026 | The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted USB device without two interrupt-in endpoint descriptors. | |
| Modificada | Media (4.6) | 1.8% | 💥 Exploit | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+6 | 2/5/2016 | 17/6/2026 | The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Media (4.6) | 0.59% | — | Canonical Ubuntu LinuxLinux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+1 | 2/5/2016 | 17/6/2026 | The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Media (4.6) | 0.80% | — | Linux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Desktop+6 | 2/5/2016 | 17/6/2026 | The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Media (4.6) | 0.80% | — | Canonical Ubuntu LinuxLinux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+6 | 2/5/2016 | 17/6/2026 | The ati_remote2_probe function in drivers/input/misc/ati_remote2.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Alta (7.8) | 1.2% | 💥 Exploit | Canonical Ubuntu LinuxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+5 | 27/4/2016 | 17/6/2026 | The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid… | |
| Modificada | Media (5.5) | 0.55% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+6 | 27/4/2016 | 17/6/2026 | The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses. | |
| Modificada | Media (4.6) | 1.8% | 💥 Exploit | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+5 | 27/4/2016 | 17/6/2026 | The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Alta (8.4) | 1.2% | 💥 Exploit | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+5 | 27/4/2016 | 17/6/2026 | The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call. | |
| Modificada | Media (6.2) | 0.56% | — | Linux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Desktop+5 | 27/4/2016 | 17/6/2026 | fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes. | |
| Modificada | Media (4.6) | 1.6% | 💥 Exploit | Linux KernelSuse Linux Enterprise DebuginfoSuse Linux Enterprise Module FOR Public CloudSuse Linux Enterprise Desktop+4 | 27/4/2016 | 17/6/2026 | The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint. | |
| Modificada | Media (4.6) | 1.9% | 💥 Exploit | Linux KernelCanonical Ubuntu LinuxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+6 | 27/4/2016 | 17/6/2026 | The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Media (5.5) | 0.39% | — | Linux KernelSuse Linux Enterprise Live PatchingSuse Linux Enterprise Module FOR Public CloudSuse Linux Enterprise Real Time Extension+4 | 27/4/2016 | 17/6/2026 | The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application. | |
| Modificada | Media (6.8) | 0.54% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+7 | 27/4/2016 | 17/6/2026 | The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB… | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa | Oracle JDKOracle JREOracle JrockitOracle Linux+34 | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. |