Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
177 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 6.0% | — | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350,… | |
| Modificada | Alta (10) | 6.0% | — | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350,… | |
| Modificada | Alta (10) | 6.0% | — | Adobe Flash PlayerRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0350,… | |
| Modificada | Alta (10) | 7.8% | — | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0349, CVE-2015-0358, and CVE-2015-3039. | |
| Modificada | Alta (10) | 6.0% | — | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0347, CVE-2015-0352,… | |
| Modificada | Alta (10) | 8.2% | — | Adobe Flash PlayerRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUS+4 | 14/4/2015 | 17/6/2026 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0351, CVE-2015-0358, and CVE-2015-3039. | |
| Modificada | Alta (10) | 8.8% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+4 | 14/4/2015 | 17/6/2026 | Buffer overflow in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 6.2% | — | Adobe Flash PlayerOpensuseSuse Linux Enterprise DesktopSuse Linux Workstation Extension+4 | 14/4/2015 | 17/6/2026 | Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0350, CVE-2015-0352,… | |
| Modificada | Alta (10) | 10% | — | Redhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server SupplementaryRedhat Enterprise Linux Server Supplementary EUSRedhat Enterprise Linux Workstation Supplementary+4 | 14/4/2015 | 17/6/2026 | Double free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0359. | |
| Modificada | Media (5) | 5.6% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerGNU GlibcCanonical Ubuntu Linux | 27/3/2015 | 17/6/2026 | DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up on a database while iterating over it, which triggers… | |
| Modificada | Alta (10) | 88% | 💥 Exploit | Redhat Enterprise LinuxSambaNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+2 | 24/2/2015 | 17/6/2026 | The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the… | |
| Modificada | Alta (9.3) | 4.0% | — | Oracle JDKOracle JRENovell Suse Linux Enterprise Desktop | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. | |
| Modificada | Media (6.9) | 0.39% | — | Oracle JDKOracle JRENovell Suse Linux Enterprise Desktop | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the installation process. | |
| Modificada | Alta (7.2) | 1.5% | — | Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+4 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS. | |
| Modificada | Media (5) | 5.0% | — | Oracle JDKOracle JREOracle JrockitCanonical Ubuntu Linux+5 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security. | |
| Modificada | Alta (10) | 6.9% | — | Oracle JDKOracle JRECanonical Ubuntu LinuxDebian Linux+4 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI. | |
| Modificada | Media (5.8) | 3.9% | — | Oracle JDKOracle JRENovell Suse Linux Enterprise Desktop | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality and availability via unknown vectors related to Deployment. | |
| Modificada | Media (6.9) | 0.44% | — | Novell Suse Linux Enterprise DesktopOracle JDKOracle JRE | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment. | |
| Modificada | Media (5) | 4.2% | — | Canonical Ubuntu LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse+2 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries. | |
| Modificada | Media (5.4) | 0.45% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraNovell Suse Linux Enterprise Desktop+6 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related to Hotspot. | |
| Modificada | Alta (10) | 6.9% | — | Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+4 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. | |
| Modificada | Media (5.5) | 0.74% | — | Linux KernelCanonical Ubuntu LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+7 | 10/11/2014 | 17/6/2026 | The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application. | |
| Modificada | Media (5.5) | 0.52% | — | Linux KernelNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse Evergreen+6 | 10/11/2014 | 17/6/2026 | arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm… | |
| Modificada | Alta (7.5) | 8.6% | — | Linux KernelRedhat Enterprise MRGCanonical Ubuntu LinuxDebian Linux+8 | 10/11/2014 | 17/6/2026 | The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter. | |
| Modificada | Baja (3.4) | 100% | 💥 PoC | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server+16 | 15/10/2014 | 17/6/2026 | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. |