Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
230 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.2% | — | Mozilla FirefoxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+1 | 14/5/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | |
| Modificada | Alta (7.5) | 4.9% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse+3 | 14/5/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | |
| Modificada | Baja (2.9) | 0.79% | — | XENSuse Linux Enterprise Software Development KITSuse Linux Enterprise DesktopSuse Linux Enterprise Server+5 | 28/4/2015 | 17/6/2026 | Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request. | |
| Modificada | Media (4.6) | 0.47% | — | Suse Linux Enterprise ServerLinux KernelDebian Linux | 21/4/2015 | 17/6/2026 | net/llc/sysctl_net_llc.c in the Linux kernel before 3.19 uses an incorrect data type in a sysctl table, which allows local users to obtain potentially sensitive information from kernel memory or possibly have unspecified other impact by accessing a sysctl entry. | |
| Modificada | Media (4) | 2.4% | — | Oracle Communications Policy ManagementSuse Linux Enterprise Software Development KITSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors. | |
| Modificada | Media (4) | 2.3% | — | Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerSuse Linux Enterprise Server+1 | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-4756. | |
| Modificada | Media (4) | 2.3% | — | Oracle MysqlNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition. | |
| Modificada | Media (4) | 2.3% | — | Oracle MysqlOracle Communications Policy ManagementNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Desktop+1 | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer. | |
| Modificada | Media (4) | 2.3% | — | Oracle MysqlNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server | 16/4/2015 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to XA. | |
| Modificada | Media (5) | 5.6% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerGNU GlibcCanonical Ubuntu Linux | 27/3/2015 | 17/6/2026 | DB_LOOKUP in nss_files/files-XXX.c in the Name Service Switch (NSS) in GNU C Library (aka glibc or libc6) 2.21 and earlier does not properly check if a file is open, which allows remote attackers to cause a denial of service (infinite loop) by performing a look-up on a database while iterating over it, which triggers… | |
| Modificada | Alta (10) | 88% | 💥 Exploit | Redhat Enterprise LinuxSambaNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+2 | 24/2/2015 | 17/6/2026 | The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the… | |
| Modificada | Baja (1.9) | 0.40% | — | Oracle JDKOracle JRECanonical Ubuntu LinuxSuse Linux Enterprise Server | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 7u72 and 8u25 allows local users to affect integrity via unknown vectors related to Serviceability. | |
| Modificada | Alta (7.2) | 1.5% | — | Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+4 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS. | |
| Modificada | Media (5) | 5.0% | — | Oracle JDKOracle JREOracle JrockitCanonical Ubuntu Linux+5 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security. | |
| Modificada | Alta (10) | 6.9% | — | Oracle JDKOracle JRECanonical Ubuntu LinuxDebian Linux+4 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI. | |
| Modificada | Media (5) | 4.2% | — | Canonical Ubuntu LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse+2 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries. | |
| Modificada | Alta (9.3) | 5.9% | — | Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise ServerOpensuse+3 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. | |
| Modificada | Media (5.4) | 0.45% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraNovell Suse Linux Enterprise Desktop+6 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related to Hotspot. | |
| Modificada | Alta (10) | 6.9% | — | Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+4 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. | |
| Modificada | Alta (7.8) | 1.5% | 💥 Exploit | Linux KernelRedhat Enterprise Linux EUSCanonical Ubuntu LinuxOpensuse Evergreen+2 | 17/12/2014 | 17/6/2026 | arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space. | |
| Modificada | Baja (3.3) | 0.70% | — | Linux KernelCanonical Ubuntu LinuxOpensuse EvergreenOpensuse+2 | 12/12/2014 | 17/6/2026 | The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value. | |
| Modificada | Media (5) | 9.7% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerMuttDebian Linux+1 | 2/12/2014 | 17/6/2026 | The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function. | |
| Modificada | Media (5.5) | 0.74% | — | Linux KernelCanonical Ubuntu LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+7 | 10/11/2014 | 17/6/2026 | The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application. | |
| Modificada | Alta (7.8) | 0.56% | — | Linux KernelDebian LinuxOpensuse EvergreenSuse Linux Enterprise Real Time Extension+1 | 10/11/2014 | 17/6/2026 | The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS… | |
| Modificada | Alta (7.8) | 0.59% | — | Linux KernelOpensuse EvergreenSuse Linux Enterprise Server | 10/11/2014 | 17/6/2026 | kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via a crafted application. |