Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1353 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 3.0% | — | Fedoraproject FedoraRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+3 | 9/10/2015 | 17/6/2026 | IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page. | |
| Modificada | Media (6.8) | 2.1% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+3 | 9/10/2015 | 17/6/2026 | IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks. | |
| Modificada | Media (6.9) | 1.1% | — | Spice Project SpiceRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+2 | 8/9/2015 | 17/6/2026 | Race condition in the worker_update_monitors_config function in SPICE 0.12.4 allows a remote authenticated guest user to cause a denial of service (heap-based memory corruption and QEMU-KVM crash) or possibly execute arbitrary code on the host via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.62% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUS+2 | 31/8/2015 | 17/6/2026 | arch/x86/entry/entry_64.S in the Linux kernel before 4.1.6 on the x86_64 platform mishandles IRET faults in processing NMIs that occurred during userspace execution, which might allow local users to gain privileges by triggering an NMI. | |
| Modificada | Media (6.9) | 1.6% | 💥 Exploit | QemuLinux KernelArista EOSDebian Linux+15 | 31/8/2015 | 17/6/2026 | The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index. | |
| Modificada | Media (5.8) | 1.1% | — | Cisco Webex Node FOR MCS | 19/8/2015 | 17/6/2026 | Open redirect vulnerability in Cisco WebEx Node for Media Convergence Server (MCS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted HTTP request parameters, aka Bug ID CSCuv32136. | |
| Modificada | Alta (9.3) | 13% | — | XENFedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise Server+20 | 12/8/2015 | 17/6/2026 | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.0% | — | Google V8Iojs Io.jsNodejs Node.js | 9/7/2015 | 17/6/2026 | The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory… | |
| Modificada | Baja (3.5) | 0.95% | — | Node Field Project Node Field | 6/7/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Node Field module 7.x-2.x before 7.x-2.45 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors involving internal fields. | |
| Modificada | Media (4.3) | 4.2% | — | W1.fi WPA SupplicantRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux Server+3 | 15/6/2015 | 17/6/2026 | Integer underflow in the WMM Action frame parser in hostapd 0.5.5 through 2.4 and wpa_supplicant 0.7.0 through 2.4, when used for AP mode MLME/SME functionality, allows remote attackers to cause a denial of service (crash) via a crafted frame, which triggers an out-of-bounds read. | |
| Modificada | Media (6.8) | 0.57% | — | Node Template Project Node Template | 15/6/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Node Template module for Drupal allows remote attackers to hijack the authentication of users with the "access node template" permission for requests that delete node templates via unspecified vectors. | |
| Modificada | Media (5) | 20% | 💥 Exploit | Apple MAC OS XRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+4 | 9/6/2015 | 17/6/2026 | The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property is a string, which allows remote attackers to obtain sensitive information by providing crafted serialized data with an int data type, related to a "type confusion" issue. | |
| Modificada | Alta (7.5) | 12% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+4 | 9/6/2015 | 17/6/2026 | The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_headers is an array, which allows remote attackers to execute arbitrary code by providing crafted serialized data with an unexpected data type, related to a "type confusion"… | |
| Modificada | Alta (7.5) | 20% | — | Redhat Enterprise LinuxPHPApple MAC OS XRedhat Enterprise Linux Desktop+5 | 9/6/2015 | 17/6/2026 | The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass intended extension restrictions and execute files with unexpected names via a crafted first argument. NOTE: this… | |
| Modificada | Alta (7.5) | 19% | — | Apple MAC OS XPHPRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+5 | 9/6/2015 | 17/6/2026 | PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character in certain situations, which allows remote attackers to bypass intended extension restrictions and access files or directories with unexpected names via a crafted argument to (1) set_include_path, (2)… | |
| Modificada | Media (5) | 50% | — | Redhat Enterprise LinuxApple MAC OS XPHPHP System Management Homepage+8 | 9/6/2015 | 17/6/2026 | Algorithmic complexity vulnerability in the multipart_buffer_headers function in main/rfc1867.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote attackers to cause a denial of service (CPU consumption) via crafted form data that triggers an improper order-of-growth outcome. | |
| Modificada | Alta (7.5) | 21% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+5 | 9/6/2015 | 17/6/2026 | Integer overflow in the ftp_genlist function in ext/ftp/ftp.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 allows remote FTP servers to execute arbitrary code via a long reply to a LIST command, leading to a heap-based buffer overflow. | |
| Modificada | Media (5) | 21% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+5 | 9/6/2015 | 17/6/2026 | The phar_parse_tarfile function in ext/phar/tar.c in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 does not verify that the first character of a filename is different from the \0 character, which allows remote attackers to cause a denial of service (integer underflow and memory corruption) via a… | |
| Modificada | Media (6.8) | 14% | — | Oracle LinuxOracle SolarisApple MAC OS XRedhat Enterprise Linux+7 | 9/6/2015 | 17/6/2026 | The php_handler function in sapi/apache2handler/sapi_apache2.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8, when the Apache HTTP Server 2.4.x is used, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via pipelined HTTP requests that… | |
| Modificada | Alta (7.5) | 38% | — | Apple MAC OS XRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+7 | 9/6/2015 | 17/6/2026 | Multiple stack-based buffer overflows in the phar_set_inode function in phar_internal.h in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allow remote attackers to execute arbitrary code via a crafted length value in a (1) tar, (2) phar, or (3) ZIP archive. | |
| Modificada | Alta (7.5) | 6.7% | — | Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+5 | 9/6/2015 | 17/6/2026 | The phar_parse_metadata function in ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to cause a denial of service (heap metadata corruption) or possibly have unspecified other impact via a crafted tar archive. | |
| Modificada | Media (5.8) | 10% | — | PHPRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUS+5 | 9/6/2015 | 17/6/2026 | ext/phar/phar.c in PHP before 5.4.40, 5.5.x before 5.5.24, and 5.6.x before 5.6.8 allows remote attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read and application crash) via a crafted length value in conjunction with crafted serialized data in a phar archive,… | |
| Modificada | Alta (10) | 3.2% | — | Fedoraproject FedoraLibuv Project LibuvNodejs Node.js | 18/5/2015 | 17/6/2026 | libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors. | |
| Modificada | Media (5.8) | 5.2% | — | Canonical Ubuntu LinuxW1.fi WPA SupplicantRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+6 | 28/4/2015 | 17/6/2026 | Heap-based buffer overflow in wpa_supplicant 1.0 through 2.4 allows remote attackers to cause a denial of service (crash), read memory, or possibly execute arbitrary code via crafted SSID information in a management frame when creating or updating P2P entries. | |
| Modificada | Baja (3.5) | 0.94% | — | Node Access Product Project Node Access Product | 21/4/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Node Access Product module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title. |