Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
247 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.1) | 1.5% | — | Oracle Glassfish Server | 24/4/2017 | 17/6/2026 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces). The supported version that is affected is 3.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GlassFish Server.… | |
| Modificada | Alta (7.3) | 1.3% | — | Oracle Glassfish Server | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are 2.1.1, 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GlassFish Server. Successful… | |
| Modificada | Alta (7.3) | 1.4% | — | Oracle Glassfish Server | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are 2.1.1, 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle GlassFish Server. Successful… | |
| Modificada | Media (4.3) | 1.1% | — | Oracle Glassfish Server | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Core). Supported versions that are affected are 2.1.1, 3.0.1 and 3.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle GlassFish Server. Successful… | |
| Modificada | Baja (3.3) | 0.42% | — | Oracle Glassfish Server | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Administration). Supported versions that are affected are 3.0.1 and 3.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GlassFish Server executes to… | |
| Modificada | Crítica (9) | 1.8% | — | Oracle Glassfish Server | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Security). Supported versions that are affected are 2.1.1, 3.0.1 and 3.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GlassFish… | |
| Modificada | Alta (8.8) | 2.3% | — | Oracle Glassfish Server | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to Java Server Faces. | |
| Modificada | Media (5.8) | 2.4% | — | Oracle Glassfish Server | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1 and 3.0.1 allows remote attackers to affect confidentiality via vectors related to Administration. | |
| Modificada | Media (5.8) | 2.4% | — | Oracle Glassfish Server | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 allows remote attackers to affect confidentiality via vectors related to Administration. | |
| Modificada | Crítica (9.8) | 7.5% | — | Oracle Glassfish Server | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Web Container. | |
| Modificada | Alta (8.8) | 4.2% | — | Mozilla Network Security ServicesMozilla FirefoxOracle LinuxOracle VM Server+8 | 13/3/2016 | 17/6/2026 | Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via crafted ASN.1 data in an X.509 certificate. | |
| Modificada | Alta (7.5) | 2.3% | — | Fisher-price Smart TOY Bear | 4/2/2016 | 17/6/2026 | The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 802.11 network's coverage area and entering an account number. | |
| Modificada | Crítica (9.8) | 10% | — | Oracle Traffic DirectorOracle OpenssoOracle Iplanet WEB Proxy ServerMozilla Firefox+3 | 5/11/2015 | 17/6/2026 | Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary… | |
| Modificada | Media (6.4) | 8.3% | — | Haxx CurlHaxx LibcurlHP System Management HomepageOracle Enterprise Manager OPS Center+1 | 22/6/2015 | 17/6/2026 | The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and crash) via crafted length and offset values. | |
| Modificada | Media (5.4) | 0.27% | — | Clearfishing Pescuit Crap Lite | 26/9/2014 | 17/6/2026 | The Pescuit Crap Lite (aka ro.aventurilapescui.pescuitcrap.lite) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Clearfishing Pesca DE Carpa Lite | 26/9/2014 | 17/6/2026 | The Pesca de Carpa Lite (aka com.clearfishing.pescadecarpa.lite) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Jellyfisher Soccer Blitz | 18/9/2014 | 17/6/2026 | The Soccer Blitz (aka soccer.blitz) application 1.06 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Josiane Sauveterre Goldfish Care | 9/9/2014 | 17/6/2026 | The Kids GoldFish Care (aka air.josiane.sauveterre.kidsgoldfishcare) application 1.0.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Flyfishing-and-flytying FLY Fishing & FLY Tying | 9/9/2014 | 17/6/2026 | The Fly Fishing & Fly Tying (aka air.com.yudu.ReaderAIR3209899) application 3.21.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.9) | 0.35% | — | Fishshell Fish | 2/5/2014 | 17/6/2026 | fish (aka fish-shell) 1.16.0 before 2.1.1 does not properly check the credentials, which allows local users to gain privileges via the universal variable socket, related to /tmp/fishd.socket.user permissions. | |
| Modificada | Media (4.6) | 0.42% | — | Catfish Project Catfish | 26/2/2014 | 17/6/2026 | Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0 allows local users to gain privileges via a Trojan horse bin/catfish.py under the current working directory. | |
| Modificada | Media (4.6) | 0.42% | — | Catfish Project Catfish | 26/2/2014 | 17/6/2026 | Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0, when a Fedora package such as 0.8.2-1 is not used, allows local users to gain privileges via a Trojan horse bin/catfish.pyc under the current working directory. | |
| Modificada | Media (4.6) | 0.42% | — | Catfish Project Catfish | 26/2/2014 | 17/6/2026 | Untrusted search path vulnerability in Catfish through 0.4.0.3, when a Fedora package such as 0.4.0.2-2 is not used, allows local users to gain privileges via a Trojan horse catfish.pyc in the current working directory. | |
| Modificada | Media (4.6) | 0.42% | — | Catfish Project Catfish | 26/2/2014 | 17/6/2026 | Untrusted search path vulnerability in Catfish through 0.4.0.3 allows local users to gain privileges via a Trojan horse catfish.py in the current working directory. | |
| Modificada | Media (4.3) | 1.0% | — | Oracle Glassfish Server | 17/4/2013 | 16/6/2026 | Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Middleware Products 3.0.1 and 3.1.2 allows remote attackers to affect integrity via vectors related to REST Interface. |