Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 5.5% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+13 | 6/2/2014 | 17/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown… | |
| Modificada | Media (5.9) | 2.9% | — | Fedoraproject FedoraMozilla FirefoxMozilla SeamonkeyMozilla Thunderbird+5 | 11/12/2013 | 17/6/2026 | Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it easier for man-in-the-middle attackers to spoof SSL servers in opportunistic circumstances via a valid certificate that… | |
| Modificada | Crítica (9.8) | 11% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+12 | 11/12/2013 | 17/6/2026 | The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements. | |
| Modificada | Crítica (9.8) | 10% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 11/12/2013 | 16/6/2026 | Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper… | |
| Modificada | Crítica (9.8) | 6.7% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 11/12/2013 | 16/6/2026 | Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors… | |
| Modificada | Crítica (9.8) | 4.2% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdCanonical Ubuntu Linux+5 | 11/12/2013 | 16/6/2026 | The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions on the generation of GetElementIC typed array stubs, which has unspecified impact and remote attack vectors. | |
| Modificada | Crítica (9.8) | 9.4% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 11/12/2013 | 16/6/2026 | Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving… | |
| Modificada | Crítica (9.8) | 8.1% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdFedoraproject Fedora+12 | 11/12/2013 | 16/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown… | |
| Modificada | Media (4.3) | 2.3% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Studio OnsiteNovell Suse Linux Enterprise DebuginfoGraphicsmagick+1 | 23/11/2013 | 16/6/2026 | The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image. | |
| Modificada | Media (6.8) | 0.75% | — | LibguestfsSuse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Server | 5/11/2013 | 16/6/2026 | The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by… | |
| Modificada | Alta (7.8) | 34% | — | ISC BindSuse Linux Enterprise Software Development KITNovell Suse LinuxISC Dnsco Bind+8 | 29/7/2013 | 16/6/2026 | The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA… | |
| Modificada | Alta (8.8) | 3.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+10 | 21/11/2012 | 16/6/2026 | Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 on Mac OS X allows remote attackers to execute arbitrary code via an HTML document. |