Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

681 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.3%—Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+512/4/201717/6/2026
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
ModificadaAlta (7.8)2.3%—Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+512/4/201717/6/2026
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
ModificadaAlta (7.8)1.9%—Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+512/4/201717/6/2026
Stack-based buffer overflow in game-music-emu before 0.6.1.
ModificadaAlta (7.5)1.8%—FreeradiusSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT5/4/201717/6/2026
FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates.
ModificadaAlta (7.5)6.0%—Jasper Project JasperFedoraproject FedoraOpensuse LeapSuse Linux Enterprise Desktop+223/3/201717/6/2026
The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
ModificadaAlta (7.8)0.53%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Server23/3/201717/6/2026
A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root).
ModificadaAlta (7.5)3.7%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+520/3/201717/6/2026
ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
ModificadaAlta (7.5)3.6%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+420/3/201717/6/2026
Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).
ModificadaAlta (7.5)3.6%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+520/3/201717/6/2026
The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
ModificadaAlta (7.5)3.7%—Opensuse LeapOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Desktop+620/3/201717/6/2026
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
ModificadaCrítica (9.8)4.6%—Opensuse Project Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+620/3/201717/6/2026
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
ModificadaCrítica (9.8)4.9%—Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+720/3/201717/6/2026
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
ModificadaMedia (5.5)1.9%—Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+720/3/201717/6/2026
The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
ModificadaMedia (5.5)2.1%—Suse Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+620/3/201717/6/2026
The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
ModificadaCrítica (9.8)3.9%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+420/3/201717/6/2026
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
ModificadaAlta (7.5)3.6%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+520/3/201717/6/2026
Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
ModificadaCrítica (9.8)3.9%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+420/3/201717/6/2026
The ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors, related to "throwing of exceptions."
ModificadaAlta (7.5)3.7%—ImagemagickOpensuse LeapOpensuseSuse Linux Enterprise Server+317/3/201717/6/2026
coders/tiff.c in ImageMagick allows remote attackers to cause a denial of service (application crash) via vectors related to the "identification of image."
ModificadaMedia (5.5)1.8%—ImagemagickSuse Linux Enterprise DebuginfoNovell LeapOpensuse Leap+717/3/201717/6/2026
Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
ModificadaCrítica (9.8)2.9%—ImagemagickOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+317/3/201717/6/2026
distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows remote attackers to have unspecified impact via unspecified vectors.
ModificadaMedia (5.5)0.40%—QemuSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Server FOR SAP+115/3/201717/6/2026
Integer overflow in the emulated_apdu_from_guest function in usb/dev-smartcard-reader.c in Quick Emulator (Qemu), when built with the CCID Card device emulator support, allows local users to cause a denial of service (application crash) via a large Application Protocol Data Units (APDU) unit.
ModificadaMedia (4.3)3.5%—NTPSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+630/1/201717/6/2026
The ntpq saveconfig command in NTP 4.1.2, 4.2.x before 4.2.8p6, 4.3, 4.3.25, 4.3.70, and 4.3.77 does not properly filter special characters, which allows attackers to cause unspecified impact via a crafted filename.
ModificadaMedia (5.5)0.85%—Systemd Project SystemdNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+513/10/201617/6/2026
The manager_dispatch_notify_fd function in systemd allows local users to cause a denial of service (system hang) via a zero-length message received over a notify socket, which causes an error to be returned and the notification handler to be disabled.
ModificadaMedia (5.5)2.3%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITCanonical Ubuntu Linux+120/9/201617/6/2026
The copy_from_lzss_window function in archive_read_support_format_rar.c in libarchive 3.2.0 and earlier allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted rar file.
ModificadaMedia (5.5)2.0%—LibarchiveSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+120/9/201617/6/2026
Integer overflow in the archive_read_format_tar_skip function in archive_read_support_format_tar.c in libarchive before 3.2.0 allows remote attackers to cause a denial of service (crash) via a crafted tar file.
Orbitaley — Vulnerabilidades