Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
98 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 8.5% | — | Opensuse LeapOpensuseDebian LinuxRedhat Enterprise Linux+7 | 9/6/2016 | 17/6/2026 | The smartcard interaction in SPICE allows remote attackers to cause a denial of service (QEMU-KVM process crash) or possibly execute arbitrary code via vectors related to connecting to a guest VM, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.1) | 0.49% | — | Canonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+5 | 7/6/2016 | 17/6/2026 | Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to read and write to arbitrary memory locations on the host via guest QXL commands related to surface creation. | |
| Modificada | Alta (7.8) | 0.57% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+5 | 7/6/2016 | 17/6/2026 | Heap-based buffer overflow in SPICE before 0.12.6 allows guest OS users to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via QXL commands related to the surface_id parameter. | |
| Modificada | Media (6.9) | 1.1% | — | Spice Project SpiceRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+2 | 8/9/2015 | 17/6/2026 | Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | 💥 Exploit | Spiceworks | 17/9/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in SpiceWorks 5.3.75941 allow remote attackers to inject arbitrary web script or HTML via the (1) syslocation, (2) syscontact, or (3) sysName configuration in snmpd.conf. NOTE: this entry was SPLIT from CVE-2012-2956 per ADT2 due to different vulnerability types. | |
| Modificada | Media (6.5) | 1.1% | 💥 Exploit | Spiceworks | 17/9/2014 | 16/6/2026 | SQL injection vulnerability in SpiceWorks 5.3.75941 allows remote authenticated users to execute arbitrary SQL commands via the id parameter to api_v2.json. NOTE: this entry was SPLIT per ADT2 due to different vulnerability types. CVE-2012-6658 is for the XSS. | |
| Modificada | Baja (3.5) | 3.4% | 💥 Exploit | Spiceworks | 11/9/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in SpiceWorks before 7.2.00195 allows remote authenticated users to inject arbitrary web script or HTML via the Summary field in a ticket request to the portal page. | |
| Modificada | Media (5) | 2.7% | — | Spice Project SpiceRedhat Enterprise VirtualizationRedhat Enterprise Linux | 2/11/2013 | 16/6/2026 | Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket. | |
| Modificada | Media (4.6) | 0.38% | — | Spice-gtk Project Spice-gtkRedhat Enterprise Linux | 3/10/2013 | 16/6/2026 | spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related… | |
| Modificada | Media (5) | 2.6% | — | Spice Project SpiceCanonical Ubuntu Linux | 20/8/2013 | 16/6/2026 | The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable assertion and server exit) by triggering a network error. | |
| Modificada | Media (6.9) | 1.1% | 💥 Exploit | Freedesktop Spice-gtkGTK Libgio | 18/9/2012 | 16/6/2026 | libgio, when used in setuid or other privileged programs in spice-gtk and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: it could be argued that this is a vulnerability in the applications that do not cleanse… | |
| Modificada | Media (5.1) | 3.9% | — | Redhat Spice-xpi | 18/4/2011 | 16/6/2026 | The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to (1) plugin/nsScriptablePeer.cpp and (2) plugin/plugin.cpp, which trigger multiple uses of an uninitialized pointer. | |
| Modificada | Baja (3.3) | 0.33% | — | Redhat Spice-xpi | 18/4/2011 | 16/6/2026 | The SPICE Firefox plug-in (spice-xpi) 2.4, 2.3, 2.2, and possibly other versions allows local users to overwrite arbitrary files via a symlink attack on the usbrdrctl log file, which has a predictable name. | |
| Modificada | Media (6.8) | 1.0% | — | Redhat Spice-activexRedhat Enterprise Virtualization Manager | 8/12/2010 | 16/6/2026 | Race condition in the SPICE (aka spice-activex) plug-in for Internet Explorer in Red Hat Enterprise Virtualization (RHEV) Manager before 2.2.4 allows local users to create a certain named pipe, and consequently gain privileges, via vectors involving knowledge of the name of this named pipe, in conjunction with use of… | |
| Modificada | Baja (3.3) | 0.31% | — | Redhat Spice-xpi | 30/8/2010 | 16/6/2026 | The SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file. | |
| Modificada | Baja (3.3) | 0.25% | — | Redhat Spice-xpi | 30/8/2010 | 16/6/2026 | Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client (aka qspice-client) in qspice 0.3.0, and then accessing this socket. | |
| Modificada | Media (6.6) | 0.31% | — | Redhat Enterprise VirtualizationRedhat Qspice | 24/8/2010 | 16/6/2026 | libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly restrict the addresses upon which memory-management actions are performed, which allows guest OS users to cause a denial of service (guest OS crash) or possibly gain… | |
| Modificada | Media (6.6) | 0.31% | — | Redhat Enterprise VirtualizationRedhat Qspice | 24/8/2010 | 16/6/2026 | libspice, as used in QEMU-KVM in the Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2 and qspice 0.3.0, does not properly validate guest QXL driver pointers, which allows guest OS users to cause a denial of service (invalid pointer dereference and guest OS crash) or possibly gain… | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Spice Classifieds | 11/9/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Spice Classifieds allows remote attackers to execute arbitrary SQL commands via the cat_path parameter. | |
| Modificada | Media (5) | 2.0% | — | Mike Spice Quiz ME | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in quiz.cgi for Mike Spice Quiz Me! before 0.6 allows remote attackers to write arbitrary files via .. (dot dot) sequences in the quiz parameter. | |
| Modificada | Media (5) | 2.0% | — | Mike Spice MY Calendar | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in Mike Spice My Calendar before 1.5 allows remote attackers to write arbitrary files via .. (dot dot) sequences in a URL. | |
| Modificada | Media (5) | 3.3% | — | Mike Spice Mikes Vote CGI | 31/12/2002 | 16/6/2026 | Directory traversal vulnerability in vote.cgi for Mike Spice Mike's Vote CGI before 1.3 allows remote attackers to write arbitrary files via .. (dot dot) sequences in the type parameter. | |
| Modificada | Media (5) | 3.2% | — | Mike Spice MY Classifieds | 9/1/2002 | 16/6/2026 | Directory traversal vulnerability in Mike Spice's My Classifieds (classifieds.cgi) before 1.3 allows remote attackers to overwrite arbitrary files via the category parameter. |