Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
297 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.59% | — | Canonical Ubuntu LinuxLinux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+1 | 2/5/2016 | 17/6/2026 | The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Media (4.6) | 0.80% | — | Linux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Desktop+6 | 2/5/2016 | 17/6/2026 | The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Media (4.6) | 0.80% | — | Canonical Ubuntu LinuxLinux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+6 | 2/5/2016 | 17/6/2026 | The ati_remote2_probe function in drivers/input/misc/ati_remote2.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Alta (7.8) | 1.2% | 💥 Exploit | Canonical Ubuntu LinuxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+5 | 27/4/2016 | 17/6/2026 | The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid… | |
| Modificada | Media (5.5) | 0.55% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+6 | 27/4/2016 | 17/6/2026 | The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses. | |
| Modificada | Media (4.6) | 1.8% | 💥 Exploit | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+5 | 27/4/2016 | 17/6/2026 | The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Alta (8.4) | 1.2% | 💥 Exploit | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+5 | 27/4/2016 | 17/6/2026 | The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call. | |
| Modificada | Media (6.2) | 0.56% | — | Linux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Desktop+5 | 27/4/2016 | 17/6/2026 | fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes. | |
| Modificada | Media (4.6) | 3.7% | 💥 Exploit | Linux KernelNovell Suse Linux Enterprise Real Time Extension | 27/4/2016 | 17/6/2026 | Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an invalid USB descriptor. | |
| Modificada | Media (4.6) | 1.9% | 💥 Exploit | Linux KernelCanonical Ubuntu LinuxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+6 | 27/4/2016 | 17/6/2026 | The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Media (5.5) | 0.39% | — | Linux KernelSuse Linux Enterprise Live PatchingSuse Linux Enterprise Module FOR Public CloudSuse Linux Enterprise Real Time Extension+4 | 27/4/2016 | 17/6/2026 | The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application. | |
| Modificada | Media (6.8) | 0.54% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+7 | 27/4/2016 | 17/6/2026 | The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB… | |
| Modificada | Crítica (9.8) | 15% | — | Novell Suse Linux Enterprise Real Time ExtensionLinux KernelCanonical Ubuntu Linux | 27/4/2016 | 17/6/2026 | drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets. | |
| Modificada | Media (6.2) | 0.43% | — | Linux KernelNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Real Time Extension | 27/4/2016 | 17/6/2026 | Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times. | |
| Modificada | Crítica (9.8) | 6.2% | — | Suse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+6 | 19/4/2016 | 17/6/2026 | Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name. | |
| Modificada | Crítica (9.8) | 5.7% | — | Fedoraproject FedoraDebian LinuxCanonical Ubuntu LinuxGNU Glibc+6 | 19/4/2016 | 17/6/2026 | Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access. | |
| Modificada | Crítica (9.1) | 4.8% | — | Suse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+6 | 19/4/2016 | 17/6/2026 | The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value. | |
| Modificada | Crítica (9.8) | 5.5% | — | Suse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+5 | 19/4/2016 | 17/6/2026 | Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function. | |
| Modificada | Media (4.3) | 1.2% | — | Novell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapGoogle ChromeDebian Linux | 18/4/2016 | 17/6/2026 | The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension. | |
| Modificada | Media (4.3) | 1.2% | — | Debian LinuxNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapGoogle Chrome | 18/4/2016 | 17/6/2026 | The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL. | |
| Modificada | Alta (8.2) | 1.1% | 💥 PoC | XENNovell Suse Linux Enterprise Real Time Extension | 14/4/2016 | 17/6/2026 | Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability. | |
| Modificada | Media (4.4) | 0.45% | — | XENCanonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise Debuginfo+1 | 13/4/2016 | 17/6/2026 | The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by leveraging a system with access to a passed-through MSI or MSI-X… | |
| Modificada | Crítica (9.8) | 18% | — | Suse Linux Enterprise DebuginfoSuse Openstack CloudOpensuse LeapOpensuse+4 | 8/4/2016 | 17/6/2026 | Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow. | |
| Modificada | Crítica (9.8) | 17% | — | Suse Linux Enterprise DebuginfoSuse Openstack CloudOpensuse LeapOpensuse+4 | 8/4/2016 | 17/6/2026 | revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow. | |
| Modificada | Alta (8.8) | 2.0% | — | Google ChromeDebian LinuxOpensuse LeapOpensuse+1 | 13/3/2016 | 17/6/2026 | Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data. |