Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
681 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.3% | — | Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+5 | 12/4/2017 | 17/6/2026 | game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values. | |
| Modificada | Alta (7.8) | 2.3% | — | Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+5 | 12/4/2017 | 17/6/2026 | game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations. | |
| Modificada | Alta (7.8) | 1.9% | — | Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+5 | 12/4/2017 | 17/6/2026 | Stack-based buffer overflow in game-music-emu before 0.6.1. | |
| Modificada | Alta (7.5) | 1.8% | — | FreeradiusSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT | 5/4/2017 | 17/6/2026 | FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates. | |
| Modificada | Alta (7.5) | 6.0% | — | Jasper Project JasperFedoraproject FedoraOpensuse LeapSuse Linux Enterprise Desktop+2 | 23/3/2017 | 17/6/2026 | The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors. | |
| Modificada | Alta (7.8) | 0.53% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Server | 23/3/2017 | 17/6/2026 | A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root). | |
| Modificada | Alta (7.5) | 3.7% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+5 | 20/3/2017 | 17/6/2026 | ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash). | |
| Modificada | Alta (7.5) | 3.6% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+4 | 20/3/2017 | 17/6/2026 | Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption). | |
| Modificada | Alta (7.5) | 3.6% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+5 | 20/3/2017 | 17/6/2026 | The png coder in ImageMagick allows remote attackers to cause a denial of service (crash). | |
| Modificada | Alta (7.5) | 3.7% | — | Opensuse LeapOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Desktop+6 | 20/3/2017 | 17/6/2026 | Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption). | |
| Modificada | Crítica (9.8) | 4.6% | — | Opensuse Project Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+6 | 20/3/2017 | 17/6/2026 | The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact. | |
| Modificada | Crítica (9.8) | 4.9% | — | Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+7 | 20/3/2017 | 17/6/2026 | Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact. | |
| Modificada | Media (5.5) | 1.9% | — | Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+7 | 20/3/2017 | 17/6/2026 | The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file. | |
| Modificada | Media (5.5) | 2.1% | — | Suse Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+6 | 20/3/2017 | 17/6/2026 | The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file. | |
| Modificada | Crítica (9.8) | 3.9% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+4 | 20/3/2017 | 17/6/2026 | The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors. | |
| Modificada | Alta (7.5) | 3.6% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+5 | 20/3/2017 | 17/6/2026 | Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors. | |
| Modificada | Crítica (9.8) | 3.9% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+4 | 20/3/2017 | 17/6/2026 | The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions." | |
| Modificada | Alta (7.5) | 3.7% | — | ImagemagickOpensuse LeapOpensuseSuse Linux Enterprise Server+3 | 17/3/2017 | 17/6/2026 | coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image." | |
| Modificada | Media (5.5) | 1.8% | — | ImagemagickSuse Linux Enterprise DebuginfoNovell LeapOpensuse Leap+7 | 17/3/2017 | 17/6/2026 | Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file. | |
| Modificada | Crítica (9.8) | 2.9% | — | ImagemagickOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+3 | 17/3/2017 | 17/6/2026 | distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors. | |
| Modificada | Media (5.5) | 0.40% | — | QemuSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Server FOR SAP+1 | 15/3/2017 | 17/6/2026 | Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit. | |
| Modificada | Media (4.3) | 3.5% | — | NTPSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+6 | 30/1/2017 | 17/6/2026 | The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename. | |
| Modificada | Media (5.5) | 0.85% | — | Systemd Project SystemdNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+5 | 13/10/2016 | 17/6/2026 | The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled. | |
| Modificada | Media (5.5) | 2.3% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITCanonical Ubuntu Linux+1 | 20/9/2016 | 17/6/2026 | The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file. | |
| Modificada | Media (5.5) | 2.0% | — | LibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+1 | 20/9/2016 | 17/6/2026 | Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file. |