Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.94% | — | Cisco Scientific Atlanta Dpc/epc 3208Cisco Scientific Atlanta Dpc/epc2100Cisco Scientific Atlanta Dpc/epc2202Cisco Scientific Atlanta Dpc/epc2203+33 | 10/12/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable modems allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.5) | 4.1% | — | X.org X11 | 10/10/2013 | 16/6/2026 | Use-after-free vulnerability in the doImageText function in dix/dixfonts.c in the xorg-server module before 1.14.4 in X.Org X11 allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted ImageText request that triggers memory-allocation failure. | |
| Modificada | Alta (7.8) | 1.9% | — | Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+9 | 11/7/2013 | 16/6/2026 | flowd in Juniper Junos 10.4 before 10.4R11 on SRX devices, when the MSRPC Application Layer Gateway (ALG) is enabled, allows remote attackers to cause a denial of service (daemon crash) via crafted MSRPC requests, aka PR 772834. | |
| Modificada | Alta (7.8) | 2.6% | — | Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+9 | 11/7/2013 | 16/6/2026 | flowd in Juniper Junos 10.4 before 10.4S14, 11.2 and 11.4 before 11.4R6-S2, and 12.1 before 12.1R6 on SRX devices, when certain Application Layer Gateways (ALGs) are enabled, allows remote attackers to cause a denial of service (daemon crash) via crafted TCP packets, aka PRs 727980, 806269, and 835593. | |
| Modificada | Alta (10) | 7.6% | — | Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+9 | 11/7/2013 | 16/6/2026 | Buffer overflow in flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7, 12.1 before 12.1R6, and 12.1X44 before 12.1X44-D15 on SRX devices, when Captive Portal is enabled with the UAC enforcer role, allows remote attackers to execute arbitrary code via crafted HTTP requests, aka PR 849100. | |
| Modificada | Alta (7.8) | 2.8% | — | Juniper JunosJuniper Srx100Juniper Srx110Juniper Srx1400+9 | 11/7/2013 | 16/6/2026 | flowd in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R8, 12.1 before 12.1R7, and 12.1X44 before 12.1X44-D15 on SRX devices, when PIM and NAT are enabled, allows remote attackers to cause a denial of service (daemon crash) via crafted PIM packets, aka PR 842253. | |
| Modificada | Media (6.8) | 1.6% | — | Libx11 | 15/6/2013 | 16/6/2026 | The (1) GetDatabase and (2) _XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier do not restrict the recursion depth when processing directives to include files, which allows X servers to cause a denial of service (stack consumption) via a crafted file. | |
| Modificada | Media (6.8) | 2.1% | — | Libx11 | 15/6/2013 | 16/6/2026 | Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XAllocColorCells, (2) _XkbReadGetDeviceInfoReply, (3) _XkbReadGeomShapes, (4) _XkbReadGetGeometryReply, (5)… | |
| Modificada | Media (6.8) | 1.4% | — | Libx11Canonical Ubuntu Linux | 15/6/2013 | 16/6/2026 | Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XQueryFont, (2) _XF86BigfontQueryFont, (3) XListFontsWithInfo, (4) XGetMotionEvents, (5) XListHosts, (6) XGetModifierMapping, (7)… | |
| Modificada | Media (6.9) | 0.40% | — | Xfree86 X11perf | 8/3/2013 | 16/6/2026 | Untrusted search path vulnerability in x11perfcomp in XFree86 x11perf before 1.5.4 allows local users to gain privileges via unspecified Trojan horse code in the current working directory. | |
| Modificada | Baja (3.6) | 0.35% | — | X.org X11Xfree86 | 21/12/2012 | 16/6/2026 | The ProcSetEventMask function in difs/events.c in the xfs font server for X.Org X11R6 through X11R6.6 and XFree86 before 3.3.3 calls the SendErrToClient function with a mask value instead of a pointer, which allows local users to cause a denial of service (memory corruption and crash) or obtain potentially sensitive… | |
| Modificada | Alta (10) | 2.7% | — | X.org X11 | 18/5/2012 | 16/6/2026 | Format string vulnerability in the LogVHdrMessageVerb function in os/log.c in X.Org X11 1.11 allows attackers to cause a denial of service or possibly execute arbitrary code via format string specifiers in an input device name. | |
| Modificada | Media (5) | 1.2% | — | 53x11 WOW Server Status | 24/9/2011 | 16/6/2026 | WoW Server Status 4.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by status.php and certain other files. | |
| Modificada | Alta (7.8) | 1.6% | — | Yamaha Rt100iYamaha Rt102iYamaha Rt103iYamaha Rt105e+48 | 9/5/2011 | 16/6/2026 | Yamaha RTX, RT, SRT, RTV, RTW, and RTA series routers with firmware 6.x through 10.x, and NEC IP38X series routers with firmware 6.x through 10.x, do not properly handle IP header options, which allows remote attackers to cause a denial of service (device reboot) via a crafted option that triggers access to an invalid… | |
| Modificada | Alta (9.3) | 5.8% | — | Matthias Hopf XrdbX11 | 8/4/2011 | 16/6/2026 | xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message. | |
| Modificada | Media (4) | 0.30% | — | SUN OpensolarisSUN SolarisX.org X11 | 8/9/2009 | 16/6/2026 | xscreensaver (aka Gnome-XScreenSaver) in Sun Solaris 9 and 10, OpenSolaris snv_109 through snv_122, and X11 6.4.1 on Solaris 8 does not properly handle Accessibility support, which allows local users to cause a denial of service (system hang) by locking the screen and then attempting to launch an Accessibility pop-up… | |
| Modificada | Media (4.9) | 0.39% | — | SUN OpensolarisSUN SolarisX.org X11 | 7/8/2009 | 16/6/2026 | XScreenSaver in Sun Solaris 9 and 10, OpenSolaris before snv_120, and X11 6.4.1 for Solaris 8, when the Xorg or Xnewt server is used, allows physically proximate attackers to obtain sensitive information by reading popup windows, which are displayed even when the screen is locked, a different vulnerability than… | |
| Modificada | Alta (7.5) | 1.7% | — | Lxde GpicviewLxde Lightweight X11 Desktop Environment | 4/9/2008 | 16/6/2026 | src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a filename. | |
| Modificada | Media (4.6) | 0.34% | — | Lxde Lightweight X11 Desktop Environment | 3/9/2008 | 16/6/2026 | src/main-win.c in GPicView 0.1.9 in Lightweight X11 Desktop Environment (LXDE) allows local users to overwrite arbitrary files via a symlink attack on the /tmp/rot.jpg temporary file. | |
| Modificada | Alta (9) | 2.7% | — | X11 | 16/6/2008 | 16/6/2026 | The (1) SProcRecordCreateContext and (2) SProcRecordRegisterClients functions in the Record extension and the (3) SProcSecurityGenerateAuthorization function in the Security extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via requests with crafted length… | |
| Modificada | Alta (10) | 3.6% | — | X11 | 16/6/2008 | 16/6/2026 | Multiple integer overflows in the Render extension in the X server 1.4 in X.Org X11R7.3 allow context-dependent attackers to execute arbitrary code via a (1) SProcRenderCreateLinearGradient, (2) SProcRenderCreateRadialGradient, or (3) SProcRenderCreateConicalGradient request with an invalid field specifying the number… | |
| Modificada | Media (6.8) | 1.4% | — | X11 | 16/6/2008 | 16/6/2026 | Integer overflow in the fbShmPutImage function in the MIT-SHM extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to read arbitrary process memory via crafted values for a Pixmap width and height. | |
| Modificada | Alta (9) | 3.2% | — | X11 | 16/6/2008 | 16/6/2026 | Integer overflow in the AllocateGlyph function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to execute arbitrary code via unspecified request fields that are used to calculate a heap buffer size, which triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 1.6% | — | Xorg X11 | 16/6/2008 | 16/6/2026 | Integer overflow in the ProcRenderCreateCursor function in the Render extension in the X server 1.4 in X.Org X11R7.3 allows context-dependent attackers to cause a denial of service (daemon crash) via unspecified request fields that are used to calculate a glyph buffer size, which triggers a dereference of unmapped… | |
| Modificada | Alta (7.5) | 0.68% | — | Yamaha Rt107eYamaha Rt52proYamaha Rt56vYamaha Rt57i+14 | 31/1/2008 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the management interface in multiple Yamaha RT series routers allows remote attackers to change password settings and probably other configuration settings as administrators via unspecified vectors. |