Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
644 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.80% | — | Linux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Desktop+6 | 2/5/2016 | 17/6/2026 | The powermate_probe function in drivers/input/misc/powermate.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Media (4.6) | 0.80% | — | Canonical Ubuntu LinuxLinux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+6 | 2/5/2016 | 17/6/2026 | The ati_remote2_probe function in drivers/input/misc/ati_remote2.c in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Alta (7.8) | 1.2% | 💥 Exploit | Canonical Ubuntu LinuxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+5 | 27/4/2016 | 17/6/2026 | The arch_pick_mmap_layout function in arch/x86/mm/mmap.c in the Linux kernel through 4.5.2 does not properly randomize the legacy base address, which makes it easier for local users to defeat the intended restrictions on the ADDR_NO_RANDOMIZE flag, and bypass the ASLR protection mechanism for a setuid or setgid… | |
| Modificada | Media (5.5) | 0.55% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+6 | 27/4/2016 | 17/6/2026 | The IPv4 implementation in the Linux kernel before 4.5.2 mishandles destruction of device objects, which allows guest OS users to cause a denial of service (host OS networking outage) by arranging for a large number of IP addresses. | |
| Modificada | Media (4.6) | 1.8% | 💥 Exploit | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+5 | 27/4/2016 | 17/6/2026 | The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Alta (8.4) | 1.2% | 💥 Exploit | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+5 | 27/4/2016 | 17/6/2026 | The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local users to gain privileges or cause a denial of service (heap memory corruption) via an IPT_SO_SET_REPLACE setsockopt call. | |
| Modificada | Media (6.2) | 0.56% | — | Linux KernelNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Desktop+5 | 27/4/2016 | 17/6/2026 | fs/pipe.c in the Linux kernel before 4.5 does not limit the amount of unread data in pipes, which allows local users to cause a denial of service (memory consumption) by creating many pipes with non-default sizes. | |
| Modificada | Media (4.6) | 1.6% | 💥 Exploit | Linux KernelSuse Linux Enterprise DebuginfoSuse Linux Enterprise Module FOR Public CloudSuse Linux Enterprise Desktop+4 | 27/4/2016 | 17/6/2026 | The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a (1) bulk-in or (2) interrupt-in endpoint. | |
| Modificada | Media (4.6) | 1.9% | 💥 Exploit | Linux KernelCanonical Ubuntu LinuxNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+6 | 27/4/2016 | 17/6/2026 | The create_fixed_stream_quirk function in sound/usb/quirks.c in the snd-usb-audio driver in the Linux kernel before 4.5.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference or double free, and system crash) via a crafted endpoints value in a USB device descriptor. | |
| Modificada | Media (5.5) | 0.39% | — | Linux KernelSuse Linux Enterprise Live PatchingSuse Linux Enterprise Module FOR Public CloudSuse Linux Enterprise Real Time Extension+4 | 27/4/2016 | 17/6/2026 | The tm_reclaim_thread function in arch/powerpc/kernel/process.c in the Linux kernel before 4.4.1 on powerpc platforms does not ensure that TM suspend mode exists before proceeding with a tm_reclaim call, which allows local users to cause a denial of service (TM Bad Thing exception and panic) via a crafted application. | |
| Modificada | Media (6.8) | 0.54% | — | Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Live Patching+7 | 27/4/2016 | 17/6/2026 | The hub_activate function in drivers/usb/core/hub.c in the Linux kernel before 4.3.5 does not properly maintain a hub-interface data structure, which allows physically proximate attackers to cause a denial of service (invalid memory access and system crash) or possibly have unspecified other impact by unplugging a USB… | |
| Analizada | Crítica (9.8) | 92% | ⚠ Explotación activa | Oracle JDKOracle JREOracle JrockitOracle Linux+34 | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX. | |
| Modificada | Media (4.1) | 1.6% | — | Oracle MysqlMariadbDebian LinuxOpensuse Leap+6 | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.6.28 and earlier and 5.7.10 and earlier and MariaDB 10.0.x before 10.0.24 and 10.1.x before 10.1.12 allows local users to affect availability via vectors related to InnoDB. | |
| Modificada | Media (5.5) | 1.3% | — | Oracle MysqlMariadbSuse Linux Enterprise DebuginfoOpensuse Leap+11 | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier allows local users to affect availability via vectors related to Optimizer. | |
| Modificada | Media (4.7) | 1.2% | — | Oracle MysqlSuse Linux Enterprise DebuginfoOpensuse LeapOpensuse+13 | 21/4/2016 | 17/6/2026 | Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier allows local users to affect integrity and availability via vectors related to Federated. | |
| Modificada | Crítica (9.8) | 6.2% | — | Suse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+6 | 19/4/2016 | 17/6/2026 | Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name. | |
| Modificada | Crítica (9.8) | 5.7% | — | Fedoraproject FedoraDebian LinuxCanonical Ubuntu LinuxGNU Glibc+6 | 19/4/2016 | 17/6/2026 | Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access. | |
| Modificada | Crítica (9.1) | 4.8% | — | Suse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+6 | 19/4/2016 | 17/6/2026 | The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value. | |
| Modificada | Crítica (9.8) | 5.5% | — | Suse Linux Enterprise DebuginfoOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+5 | 19/4/2016 | 17/6/2026 | Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function. | |
| Modificada | Media (6) | 0.45% | — | Linux KernelDebian LinuxOpensuseSuse Linux Enterprise Desktop+4 | 13/4/2016 | 17/6/2026 | The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to hit BUG conditions and cause a denial of service (NULL pointer dereference and host OS crash) by leveraging a system with access to a passed-through MSI or MSI-X… | |
| Modificada | Media (6.2) | 0.39% | — | Opensuse LeapOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 8/4/2016 | 17/6/2026 | The mysql-systemd-helper script in the mysql-community-server package before 5.6.28-2.17.1 in openSUSE 13.2 and before 5.6.28-13.1 in openSUSE Leap 42.1 and the mariadb package before 10.0.22-2.21.2 in openSUSE 13.2 and before 10.0.22-3.1 in SUSE Linux Enterprise (SLE) 12.1 and openSUSE Leap 42.1 allows local users to… | |
| Modificada | Alta (8.6) | 62% | — | ISC BindSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+10 | 9/3/2016 | 17/6/2026 | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted signature record for a DNAME record, related to db.c and resolver.c. | |
| Modificada | Media (6.8) | 59% | — | ISC BindSuse Linux Enterprise DebuginfoSuse ManagerSuse Manager Proxy+10 | 9/3/2016 | 17/6/2026 | named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to… | |
| Modificada | Alta (8.1) | 91% | 💥 Exploit | Debian LinuxCanonical Ubuntu LinuxHP Helion OpenstackHP Server Migration Pack+26 | 18/2/2016 | 17/6/2026 | Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the… | |
| Analizada | Alta (8.8) | 68% | ⚠ Explotación activa | Adobe AIR SDKAdobe AIR SDK & CompilerAdobe Flash PlayerAdobe AIR+13 | 28/12/2015 | 17/6/2026 | Integer overflow in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on Linux, Adobe AIR before 20.0.0.233, Adobe AIR SDK before 20.0.0.233, and Adobe AIR SDK & Compiler before 20.0.0.233 allows attackers to execute arbitrary code via unspecified… |