Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

405 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)4.9%—Novell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse+314/5/201517/6/2026
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
ModificadaMedia (6.8)5.4%—GstreamerMozilla FirefoxMozilla SeamonkeyMozilla Thunderbird+1014/5/201517/6/2026
GStreamer before 1.4.5, as used in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 on Linux, allows remote attackers to cause a denial of service (buffer over-read and application crash) or possibly execute arbitrary code via crafted H.264 video data in an m4v file.
ModificadaBaja (2.9)0.79%—XENSuse Linux Enterprise Software Development KITSuse Linux Enterprise DesktopSuse Linux Enterprise Server+528/4/201517/6/2026
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service domains to obtain sensitive information from memory via a (1) XEN_DOMCTL_gettscinfo or (2) XEN_SYSCTL_getdomaininfolist request.
ModificadaBaja (2.1)0.44%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITOracle Mysql16/4/201517/6/2026
Unspecified vulnerability in the MySQL Utilities component in Oracle MySQL 1.5.1 and earlier, when running on Windows, allows local users to affect integrity via unknown vectors related to Installation.
ModificadaMedia (4.9)3.6%—Debian LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+116/4/201517/6/2026
Unspecified vulnerability in the MySQL Connectors component in Oracle MySQL 5.1.34 and earlier allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Connector/J.
ModificadaMedia (4)5.1%—Oracle SolarisOracle MysqlMariadbCanonical Ubuntu Linux+1016/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
ModificadaMedia (4)5.2%—Oracle MysqlOracle SolarisDebian LinuxMariadb+1016/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Optimizer.
ModificadaMedia (5)7.1%—Oracle SolarisOracle Communications Policy ManagementOracle MysqlDebian Linux+1116/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote attackers to affect availability via unknown vectors related to Server : Security : Privileges.
ModificadaBaja (3.5)5.0%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITOracle Mysql+1016/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
ModificadaMedia (5.7)9.9%—Juniper Junos SpaceOracle MysqlDebian LinuxCanonical Ubuntu Linux+1016/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Compiling.
ModificadaMedia (4)2.4%—Oracle Communications Policy ManagementSuse Linux Enterprise Software Development KITSuse Linux Enterprise DesktopSuse Linux Enterprise Server+116/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.6.23 and earlier allows remote authenticated users to affect availability via unknown vectors.
ModificadaBaja (3.5)4.7%—Oracle MysqlOracle SolarisDebian LinuxCanonical Ubuntu Linux+1016/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.42 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Federated.
ModificadaMedia (4)4.5%—Oracle MysqlDebian LinuxCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+916/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Security : Encryption.
ModificadaMedia (4)2.3%—Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerSuse Linux Enterprise Server+116/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB, a different vulnerability than CVE-2015-4756.
ModificadaMedia (4)2.3%—Oracle MysqlNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server16/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition.
ModificadaMedia (4)5.4%—Oracle Communications Policy ManagementOracle MysqlOracle SolarisDebian Linux+1116/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
ModificadaMedia (4)2.3%—Oracle MysqlOracle Communications Policy ManagementNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Desktop+116/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
ModificadaMedia (4)2.3%—Oracle MysqlNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server16/4/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.6.22 and earlier allows remote authenticated users to affect availability via unknown vectors related to XA.
ModificadaBaja (3.7)74%—Oracle Communications Application Session ControllerOracle Communications Policy ManagementOracle Http ServerOracle Integrated Lights OUT Manager Firmware+571/4/201517/6/2026
The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally…
ModificadaMedia (5)5.5%—Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Real Time Extension+112/3/201517/6/2026
net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.
ModificadaAlta (10)88%💥 ExploitRedhat Enterprise LinuxSambaNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+224/2/201517/6/2026
The Netlogon server implementation in smbd in Samba 3.5.x and 3.6.x before 3.6.25, 4.0.x before 4.0.25, 4.1.x before 4.1.17, and 4.2.x before 4.2.0rc5 performs a free operation on an uninitialized stack pointer, which allows remote attackers to execute arbitrary code via crafted Netlogon packets that use the…
ModificadaMedia (4)3.9%—Oracle SolarisCanonical Ubuntu LinuxDebian LinuxOracle Mysql+1021/1/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.
ModificadaMedia (4)7.2%—Oracle MysqlRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+821/1/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.38 and earlier, and 5.6.19 and earlier, allows remote authenticated users to affect availability via vectors related to DDL.
ModificadaMedia (4.3)10%—Oracle Communications Policy ManagementOracle SolarisOracle MysqlCanonical Ubuntu Linux+1321/1/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381.
ModificadaMedia (4.3)5.4%—Oracle SolarisOracle MysqlCanonical Ubuntu LinuxDebian Linux+1321/1/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382.