Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1353 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.8)1.2%—Insite Node Basket21/4/201517/6/2026
Open redirect vulnerability in the Node basket module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (5.8)0.64%—Insite Node Basket21/4/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the Node basket module for Drupal allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add or (2) remove nodes from a basket via unspecified vectors.
ModificadaBaja (3.5)0.94%—Insite Node Basket21/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Node basket module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaBaja (3.5)0.95%—Node Invite Project Node Invite21/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a node title.
ModificadaMedia (5.8)1.2%—Node Invite Project Node Invite21/4/201517/6/2026
Open redirect vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination parameter.
ModificadaMedia (6.8)0.64%—Node Invite Project Node Invite21/4/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Node Invite module before 6.x-2.5 for Drupal allows remote attackers to hijack the authentication of users with the "node_invite_can_manage_invite" permission for requests that re-enable node invitations via unspecified vectors.
ModificadaBaja (3.5)0.94%—Nodeauthor Project Nodeauthor21/4/201517/6/2026
Cross-site scripting (XSS) vulnerability in the nodeauthor module for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a Profile2 field in a provided block.
ModificadaMedia (4)7.9%—Apache SubversionOpensuseRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+58/4/201517/6/2026
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote authenticated users to spoof the svn:author property via a crafted v1 HTTP protocol request sequences.
ModificadaMedia (5)13%—Apache SubversionOpensuseApple XcodeRedhat Enterprise Linux Desktop+58/4/201517/6/2026
The (1) mod_dav_svn and (2) svnserve servers in Subversion 1.6.0 through 1.7.19 and 1.8.0 through 1.8.11 allow remote attackers to cause a denial of service (assertion failure and abort) via crafted parameter combinations related to dynamically evaluated revision numbers.
ModificadaAlta (7.5)12%—PHPApple MAC OS XRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+530/3/201517/6/2026
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages use of the unset function within an __wakeup function, a…
ModificadaMedia (5)8.6%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+530/3/201517/6/2026
The move_uploaded_file implementation in ext/standard/basic_functions.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 truncates a pathname upon encountering a \x00 character, which allows remote attackers to bypass intended extension restrictions and create files with unexpected names via a crafted…
ModificadaAlta (7.5)15%—Canonical Ubuntu LinuxDebian LinuxOpensusePHP+730/3/201517/6/2026
Use-after-free vulnerability in the phar_rename_archive function in phar_object.c in PHP before 5.5.22 and 5.6.x before 5.6.6 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger an attempted renaming of a Phar archive to the name of an existing file.
ModificadaMedia (4.4)0.34%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+218/3/201517/6/2026
automount 5.0.8, when a program map uses certain interpreted languages, uses the calling user's USER and HOME environment variable values instead of the values for the user used to run the mapped program, which allows local users to gain privileges via a Trojan horse program in the user home directory.
ModificadaMedia (5)4.2%—Canonical Ubuntu LinuxFreetypeDebian LinuxFedoraproject Fedora+78/2/201517/6/2026
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.
ModificadaAlta (7.5)5.7%—Canonical Ubuntu LinuxOracle SolarisFedoraproject FedoraRedhat Enterprise Linux Desktop+78/2/201517/6/2026
The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a…
ModificadaMedia (6.8)3.4%—Canonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+68/2/201517/6/2026
Integer signedness error in the Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
ModificadaMedia (4.3)3.5%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+78/2/201517/6/2026
Off-by-one error in the pcf_get_properties function in pcf/pcfread.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PCF file with a 0xffffffff size value that is improperly incremented.
ModificadaMedia (4.3)4.2%—Debian LinuxOpensuseFedoraproject FedoraOracle Solaris+88/2/201517/6/2026
Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.
ModificadaMedia (6.8)3.9%—Canonical Ubuntu LinuxFreetypeRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+88/2/201517/6/2026
Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT table.
ModificadaMedia (6.8)3.5%—Debian LinuxCanonical Ubuntu LinuxFedoraproject FedoraFreetype+78/2/201517/6/2026
sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted SFNT table.
ModificadaMedia (6.8)4.2%—OpensuseOracle SolarisCanonical Ubuntu LinuxDebian Linux+88/2/201517/6/2026
The tt_sbit_decoder_init function in sfnt/ttsbit.c in FreeType before 2.5.4 proceeds with a count-to-size association without restricting the count value, which allows remote attackers to cause a denial of service (integer overflow and out-of-bounds read) or possibly have unspecified other impact via a crafted…
ModificadaMedia (6.8)4.3%—Redhat Enterprise Linux DesktopRedhat Enterprise Linux HPC NodeRedhat Enterprise Linux HPC Node EUSRedhat Enterprise Linux Server+88/2/201517/6/2026
FreeType before 2.5.4 does not check for the end of the data during certain parsing actions, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted Type42 font, related to type42/t42parse.c and type1/t1load.c.
ModificadaAlta (7.5)5.1%—FreetypeDebian LinuxOpensuseFedoraproject Fedora+88/2/201517/6/2026
The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely calculated, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted cmap SFNT table.
ModificadaAlta (7.5)4.4%—Canonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux HPC Node+78/2/201517/6/2026
type42/t42parse.c in FreeType before 2.5.4 does not consider that scanning can be incomplete without triggering an error, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via a crafted Type42 font.
ModificadaAlta (7.5)5.1%—OpensuseCanonical Ubuntu LinuxDebian LinuxOracle Solaris+88/2/201517/6/2026
The _bdf_parse_glyphs function in bdf/bdflib.c in FreeType before 2.5.4 does not properly handle a missing ENDCHAR record, which allows remote attackers to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a crafted BDF font.
Orbitaley — Vulnerabilidades