Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

167 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.27%—Google Android Debug Bridge14/2/201316/6/2026
android-tools 4.1.1 in Android Debug Bridge (ADB) allows local users to overwrite arbitrary files via a symlink attack on /tmp/adb.log.
ModificadaMedia (5)1.4%—Asial Monaca Debugger16/11/201216/6/2026
The Asial Monaca Debugger application before 1.4.2 for Android allows remote attackers to obtain sensitive (1) account or (2) session ID information in a system log file via a crafted application.
ModificadaMedia (6.9)0.39%—Debian Mono-debugger20/10/201016/6/2026
The (1) mdb and (2) mdb-symbolreader scripts in mono-debugger 2.4.3, and other versions before 2.8.1, place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
AnalizadaAlta (8.8)83%⚠ Explotación activaAdobe AcrobatSuse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise13/1/201016/6/2026
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x before 7.1.4 allows remote attackers to execute arbitrary code via malformed U3D data in a PDF document, related to a CLODProgressiveMeshDeclaration "array boundary issue," a different vulnerability than…
AnalizadaAlta (7.8)82%⚠ Explotación activaAdobe AcrobatAdobe Acrobat ReaderSuse Linux Enterprise DebuginfoOpensuse+115/12/200916/6/2026
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before 9.3, and 8.x before 8.2 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted PDF file using ZLib compressed streams, as exploited in the wild in December 2009.
ModificadaAlta (7.8)0.43%—Linux KernelFedoraproject FedoraCanonical Ubuntu LinuxRedhat MRG Realtime+422/10/200916/6/2026
The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.
ModificadaBaja (2.1)0.41%—Linux KernelSuse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise Desktop+920/10/200916/6/2026
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.
ModificadaAlta (7.1)3.8%—Linux KernelSuse Linux Enterprise DebuginfoSuse Linux Enterprise DesktopSuse Linux Enterprise Server+215/9/200916/6/2026
Memory leak in the appletalk subsystem in the Linux kernel 2.4.x through 2.4.37.6 and 2.6.x through 2.6.31, when the appletalk and ipddp modules are loaded but the ipddp"N" device is not found, allows remote attackers to cause a denial of service (memory consumption) via IP-DDP datagrams.
ModificadaMedia (4.3)2.2%—Mozilla FirefoxFedoraproject FedoraSuse Linux Enterprise DebuginfoOpensuse+222/7/200916/6/2026
Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."
ModificadaBaja (2.1)0.54%—Udev Project UdevSuse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise Desktop+417/4/200916/6/2026
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
ModificadaAlta (7.2)80%—Udev Project UdevSuse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise Desktop+517/4/200916/6/2026
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to gain privileges by sending a NETLINK message from user space.
ModificadaAlta (9.3)3.6%—Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+913/11/200816/6/2026
nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized,…
ModificadaMedia (5)26%—Microsoft Debug Diagnostic Tool31/10/200816/6/2026
The DebugDiag ActiveX control in CrashHangExt.dll, possibly 1.0, in Microsoft Debug Diagnostic Tool allows remote attackers to cause a denial of service (NULL pointer dereference and Internet Explorer 6.0 crash) via a large negative integer argument to the GetEntryPointForThread method. NOTE: this issue might only be…
ModificadaAlta (10)7.4%—Microsoft Sysinternals Debugview8/11/200716/6/2026
Dbgv.sys in Microsoft Sysinternals DebugView before 4.72 provides an unspecified mechanism for copying data into kernel memory, which allows local users to gain privileges via unspecified vectors.
ModificadaAlta (7.5)3.6%—Vernet Loic PHP Debug15/12/200616/6/2026
PHP remote file inclusion vulnerability in tests/debug_test.php in Vernet Loic PHP_Debug 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the debugClassLocation parameter.
ModificadaAlta (7.2)0.58%—GNU Data Display Debugger31/12/200216/6/2026
Buffer overflow in the GNU DataDisplay Debugger (DDD) 3.3.1 allows local users to execute arbitrary code and possibly gain privileges via a long HOME environment variable. NOTE: since DDD is not installed setuid or setgid, perhaps this issue should not be included in CVE.
ModificadaAlta (7.2)0.36%—SGI Workshop Debugger AND Performance Tools20/6/200016/6/2026
Vulnerability in cvconnect in SGI IRIX WorkShop allows local users to overwrite arbitrary files.