Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.9%—Google ChromeDebian LinuxFedoraproject FedoraNovell Suse Package HUB FOR Suse Linux Enterprise+510/12/201917/6/2026
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.3)2.6%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdDebian Linux+223/7/201917/6/2026
As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
ModificadaMedia (5.3)2.1%—Mozilla FirefoxMozilla ThunderbirdDebian LinuxNovell Suse Package HUB FOR Suse Linux Enterprise+123/7/201917/6/2026
A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.
ModificadaAlta (8.8)2.4%—FfmpegDebian LinuxNovell Suse Package HUB FOR Suse Linux EnterpriseCanonical Ubuntu Linux19/4/201917/6/2026
libavcodec/hevcdec.c in FFmpeg 3.4 and 4.1.2 mishandles detection of duplicate first slices, which allows remote attackers to cause a denial of service (NULL pointer dereference and out-of-array access) or possibly have unspecified other impact via crafted HEVC data.
ModificadaAlta (7.5)1.3%—Novell Edirectory2/3/201817/6/2026
The LDAP backend in Novell eDirectory before 9.0 SP4 when switched to EBA (Enhanced Background Authentication) kept open connections without EBA.
ModificadaAlta (7.5)1.0%—Novell Edirectory2/3/201817/6/2026
In Novell eDirectory before 9.0.3.1 the LDAP interface was not strictly enforcing cipher restrictions allowing weaker ciphers to be used during SSL BIND operations.
ModificadaAlta (7.5)66%💥 ExploitCanonical Ubuntu LinuxDebian LinuxGoogle AndroidNovell Leap+43/10/201717/6/2026
Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.
ModificadaMedia (5.9)68%💥 ExploitCanonical Ubuntu LinuxDebian LinuxNovell LeapRedhat Enterprise Linux Desktop+33/10/201717/6/2026
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.
ModificadaAlta (7.5)65%—Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraNovell Leap+43/10/201717/6/2026
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.
ModificadaAlta (7.8)0.38%—Novell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse Leap8/9/201717/6/2026
The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
ModificadaCrítica (9.8)24%—Novell Zenworks Configuration Management9/8/201717/6/2026
Stack-based buffer overflow in the logging functionality in the Preboot Policy service in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaAlta (7.5)6.5%—Novell Zenworks Configuration Management9/8/201717/6/2026
com.novell.zenworks.inventory.rtr.actionclasses.wcreports in Novell ZENworks Configuration Management (ZCM) allows remote attackers to read arbitrary folders via the dirname variable.
ModificadaAlta (7.5)6.6%—Novell Zenworks Configuration Management9/8/201717/6/2026
Rtrlet.class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to obtain Session IDs of logged in users via a value of ShowLogins for the maintenance variable.
ModificadaMedia (6.5)5.0%—Novell Zenworks Configuration Management9/8/201717/6/2026
The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename variable.
ModificadaCrítica (9.8)7.1%—Novell Zenworks Configuration Management9/8/201717/6/2026
SQL injection vulnerability in the ScheduleQuery method of the schedule class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaCrítica (9.8)4.3%—Novell Zenworks Configuration Management9/8/201717/6/2026
Directory traversal vulnerability in the doPost method of the Rtrlet class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to upload and execute arbitrary files via unspecified vectors.
ModificadaCrítica (9.8)8.2%—Novell Zenworks Configuration Management9/8/201717/6/2026
SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)6.1%—Fedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise ServerSuse Manager+1421/7/201717/6/2026
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.
ModificadaMedia (5.9)2.2%—Golang GONovell Suse Package HUB FOR Suse Linux EnterpriseFedoraproject FedoraOpensuse Leap6/7/201717/6/2026
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted…
ModificadaAlta (7.8)2.7%💥 ExploitRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+1619/6/201717/6/2026
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these…
ModificadaCrítica (9.8)4.4%—Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+36/6/201717/6/2026
game-music-emu before 0.6.1 mishandles unspecified integer values.
ModificadaMedia (5.5)0.53%—Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+36/6/201717/6/2026
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
ModificadaBaja (3.8)0.37%—XENSuse ManagerSuse Manager ProxySuse Openstack Cloud+23/5/201717/6/2026
Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.
ModificadaCrítica (9.8)1.5%—Novell ImanagerNetiq Imanager3/5/201717/6/2026
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a webshell upload vulnerability.
ModificadaAlta (8.8)0.58%—Novell ImanagerNetiq Imanager3/5/201717/6/2026
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have persistent CSRF in object management.
Orbitaley — Vulnerabilidades