Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

297 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.59%—Canonical Ubuntu LinuxLinux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+12/5/201617/6/2026
The gtco_probe function in drivers/input/tablet/gtco.c in the Linux kernel through 4.5.2 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
ModificadaMedia (4.6)0.80%—Linux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Desktop+62/5/201617/6/2026
The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
ModificadaMedia (4.6)0.80%—Canonical Ubuntu LinuxLinux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+62/5/201617/6/2026
The ati_remote2_probe function in drivers/input/misc/ati_remote2.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
ModificadaAlta (7.8)1.2%💥 ExploitCanonical Ubuntu LinuxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+527/4/201617/6/2026
The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid…
ModificadaMedia (5.5)0.55%—Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+627/4/201617/6/2026
The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses.
ModificadaMedia (4.6)1.8%💥 ExploitNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+527/4/201617/6/2026
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor.
ModificadaAlta (8.4)1.2%💥 ExploitNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+527/4/201617/6/2026
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call.
ModificadaMedia (6.2)0.56%—Linux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Desktop+527/4/201617/6/2026
fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes.
ModificadaMedia (4.6)3.7%💥 ExploitLinux KernelNovell Suse Linux Enterprise Real Time Extension27/4/201617/6/2026
Double free vulnerability in the snd_usbmidi_create function in sound/usb/midi.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (panic) or possibly have unspecified other impact via vectors involving an invalid USB descriptor.
ModificadaMedia (4.6)1.9%💥 ExploitLinux KernelCanonical Ubuntu LinuxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+627/4/201617/6/2026
The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via a crafted endpoints value in a USB device descriptor.
ModificadaMedia (5.5)0.39%—Linux KernelSuse Linux Enterprise Live PatchingSuse Linux Enterprise Module FOR Public CloudSuse Linux Enterprise Real Time Extension+427/4/201617/6/2026
The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application.
ModificadaMedia (6.8)0.54%—Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+727/4/201617/6/2026
The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB…
ModificadaCrítica (9.8)15%—Novell Suse Linux Enterprise Real Time ExtensionLinux KernelCanonical Ubuntu Linux27/4/201617/6/2026
drivers/infiniband/hw/cxgb3/iwch_cm.c in the Linux kernel before 4.5 does not properly identify error conditions, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted packets.
ModificadaMedia (6.2)0.43%—Linux KernelNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Real Time Extension27/4/201617/6/2026
Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times.
ModificadaCrítica (9.8)6.2%—Suse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+619/4/201617/6/2026
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.
ModificadaCrítica (9.8)5.7%—Fedoraproject FedoraDebian LinuxCanonical Ubuntu LinuxGNU Glibc+619/4/201617/6/2026
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access.
ModificadaCrítica (9.1)4.8%—Suse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+619/4/201617/6/2026
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.
ModificadaCrítica (9.8)5.5%—Suse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+519/4/201617/6/2026
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function.
ModificadaMedia (4.3)1.2%—Novell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapGoogle ChromeDebian Linux18/4/201617/6/2026
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.
ModificadaMedia (4.3)1.2%—Debian LinuxNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapGoogle Chrome18/4/201617/6/2026
The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.
ModificadaAlta (8.2)1.1%💥 PoCXENNovell Suse Linux Enterprise Real Time Extension14/4/201617/6/2026
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
ModificadaMedia (4.4)0.45%—XENCanonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise Debuginfo+113/4/201617/6/2026
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by leveraging a system with access to a passed-through MSI or MSI-X…
ModificadaCrítica (9.8)18%—Suse Linux Enterprise DebuginfoSuse Openstack CloudOpensuse LeapOpensuse+48/4/201617/6/2026
Integer overflow in Git before 2.7.4 allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, which triggers a heap-based buffer overflow.
ModificadaCrítica (9.8)17%—Suse Linux Enterprise DebuginfoSuse Openstack CloudOpensuse LeapOpensuse+48/4/201617/6/2026
revision.c in git before 2.7.4 uses an incorrect integer data type, which allows remote attackers to execute arbitrary code via a (1) long filename or (2) many nested trees, leading to a heap-based buffer overflow.
ModificadaAlta (8.8)2.0%—Google ChromeDebian LinuxOpensuse LeapOpensuse+113/3/201617/6/2026
Multiple integer signedness errors in the opj_j2k_update_image_data function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 49.0.2623.87, allow remote attackers to cause a denial of service (incorrect cast and out-of-bounds write) or possibly have unspecified other impact via crafted JPEG 2000 data.