Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
166 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.37% | — | Vmware Horizon ViewVmware Workstation | 8/6/2017 | 17/6/2026 | VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In… | |
| Modificada | Alta (7.8) | 0.37% | — | Vmware Horizon ViewVmware Workstation | 8/6/2017 | 17/6/2026 | VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds write vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of… | |
| Modificada | Alta (7.8) | 0.37% | — | Vmware Horizon ViewVmware Workstation | 8/6/2017 | 17/6/2026 | VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of… | |
| Modificada | Alta (7.8) | 0.37% | — | Vmware Horizon ViewVmware Workstation | 8/6/2017 | 17/6/2026 | VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain a heap buffer-overflow vulnerability in TrueType Font (TTF) parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case… | |
| Modificada | Alta (7.8) | 0.37% | — | Vmware Horizon ViewVmware Workstation | 8/6/2017 | 17/6/2026 | VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple heap buffer-overflow vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case… | |
| Modificada | Crítica (9.8) | 3.8% | — | Vmware Horizon ViewVmware Unified Access Gateway | 8/6/2017 | 17/6/2026 | VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway. | |
| Modificada | Media (5.5) | 1.1% | — | Vmware Horizon Daas | 31/5/2017 | 17/6/2026 | VMware Horizon DaaS before 7.0.0 contains a vulnerability that exists due to insufficient validation of data. An attacker may exploit this issue by tricking DaaS client users into connecting to a malicious server and sharing all their drives and devices. Successful exploitation of this vulnerability requires a victim… | |
| Modificada | Crítica (9.8) | 1.3% | — | Dragonwavex Horizon Wireless Radio Firmware | 6/4/2017 | 17/6/2026 | DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting to the device via TELNET. This is fixed in recent versions… | |
| Modificada | Media (4.8) | 1.1% | — | Openstack Horizon | 3/4/2017 | 17/6/2026 | OpenStack Horizon 9.x through 9.1.1, 10.x through 10.0.2, and 11.0.0 allows remote authenticated administrators to conduct XSS attacks via a crafted federation mapping. | |
| Modificada | Media (5.3) | 4.4% | — | Vmware Horizon View | 29/12/2016 | 17/6/2026 | Directory traversal vulnerability in the Connection Server in VMware Horizon View 5.x before 5.3.7, 6.x before 6.2.3, and 7.x before 7.0.1 allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5.4) | 2.1% | — | Openstack HorizonRedhat OpenstackDebian Linux | 12/7/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in OpenStack Dashboard (Horizon) 8.0.1 and earlier and 9.0.0 through 9.0.1 allows remote authenticated users to inject arbitrary web script or HTML by injecting an AngularJS template in a dashboard form. | |
| Modificada | Media (4.3) | 3.2% | — | Debian LinuxOpenstack HorizonOracle Solaris | 20/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in OpenStack Dashboard (Horizon) 2014.2 before 2014.2.4 and 2015.1.x before 2015.1.1 allows remote attackers to inject arbitrary web script or HTML via the description parameter in a heat template, which is not properly handled in the… | |
| Modificada | Alta (7.2) | 0.46% | — | Vmware PlayerVmware WorkstationVmware Horizon View Client | 10/7/2015 | 17/6/2026 | vmware-vmx.exe in VMware Workstation 7.x through 10.x before 10.0.7 and 11.x before 11.1.1, VMware Player 5.x and 6.x before 6.0.7 and 7.x before 7.1.1, and VMware Horizon Client 5.x local-mode before 5.4.2 on Windows does not provide a valid DACL pointer during the setup of the vprintproxy.exe process, which allows… | |
| Modificada | Media (6.1) | 0.66% | — | Vmware Horizon ClientVmware Horizon View ClientVmware FusionVmware Player+1 | 13/6/2015 | 17/6/2026 | TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of… | |
| Modificada | Media (6.1) | 0.66% | — | Vmware Horizon ClientVmware Horizon View ClientVmware FusionVmware Player+1 | 13/6/2015 | 17/6/2026 | TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of… | |
| Modificada | Media (6.1) | 0.66% | — | Vmware Horizon ClientVmware Horizon View ClientVmware FusionVmware Player+1 | 13/6/2015 | 17/6/2026 | TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of… | |
| Modificada | Media (5.8) | 0.75% | — | Vmware FusionVmware PlayerVmware WorkstationVmware Horizon Client+1 | 13/6/2015 | 17/6/2026 | TPInt.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to execute arbitrary code on the… | |
| Modificada | Media (5.8) | 0.75% | — | Vmware FusionVmware PlayerVmware WorkstationVmware Horizon Client+1 | 13/6/2015 | 17/6/2026 | TPView.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to execute arbitrary code on… | |
| Modificada | Baja (3.5) | 1.8% | — | Openstack HorizonOracle Solaris | 19/5/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2015.1.0 allow remote authenticated users to inject arbitrary web script or HTML via the metadata to a (1) Glance image, (2) Nova flavor or (3) Host Aggregate. | |
| Modificada | Media (5) | 2.9% | — | Openstack HorizonFedoraproject FedoraOpensuseOracle Solaris | 12/12/2014 | 17/6/2026 | OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page. | |
| Modificada | Baja (3.5) | 1.2% | — | Openstack Horizon | 31/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Groups panel in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-3475. | |
| Modificada | Baja (3.5) | 1.2% | — | Openstack HorizonOpensuse | 31/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Users panel (admin/users/) in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote administrators to inject arbitrary web script or HTML via a user email address, a different vulnerability than CVE-2014-8578. | |
| Modificada | Baja (3.5) | 1.9% | — | Openstack HorizonOpensuse | 31/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in horizon/static/horizon/js/horizon.instances.js in the Launch Instance menu in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2 allows remote authenticated users to inject arbitrary web script or HTML via a network name. | |
| Modificada | Media (4.3) | 1.7% | — | Openstack HorizonOpensuse | 31/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Orchestration/Stack section in the Horizon Orchestration dashboard in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-2, when used with Heat, allows remote Orchestration template owners or catalogs to inject arbitrary web… | |
| Modificada | Baja (3.5) | 2.1% | — | Openstack HorizonOpensuse | 22/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name. |