Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

636 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4)4.1%—MIT Kerberos 5Oracle SolarisCanonical Ubuntu LinuxDebian Linux+59/11/201517/6/2026
The build_principal_va function in lib/krb5/krb/bld_princ.c in MIT Kerberos 5 (aka krb5) before 1.14 allows remote authenticated users to cause a denial of service (out-of-bounds read and KDC crash) via an initial '\0' character in a long realm field within a TGS request.
ModificadaAlta (7.1)4.5%—MIT Kerberos 5Opensuse LeapOpensuseSuse Linux Enterprise Desktop+49/11/201517/6/2026
lib/gssapi/krb5/iakerb.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted IAKERB packet that is mishandled during a gss_inquire_context call.
ModificadaMedia (5)6.2%—MIT Kerberos 5Oracle SolarisCanonical Ubuntu LinuxDebian Linux+59/11/201517/6/2026
lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) before 1.14 relies on an inappropriate context handle, which allows remote attackers to cause a denial of service (incorrect pointer read and process crash) via a crafted SPNEGO packet that is mishandled during a gss_inquire_context call.
ModificadaAlta (7.5)3.5%—QemuDebian LinuxFedoraproject FedoraSuse Linux Enterprise Desktop+36/11/201517/6/2026
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error…
ModificadaMedia (4)3.0%—Oracle SolarisOracle MysqlMariadbCanonical Ubuntu Linux+1321/10/201517/6/2026
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.
ModificadaMedia (4.6)0.49%—Linux KernelCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Desktop+119/10/201517/6/2026
Integer overflow in the sg_start_req function in drivers/scsi/sg.c in the Linux kernel 2.6.x through 4.x before 4.1 allows local users to cause a denial of service or possibly have unspecified other impact via a large iov_count value in a write request.
AnalizadaAlta (7.8)65%⚠ Explotación activa💥 ExploitAdobe Flash PlayerOpensuse EvergreenOpensuseSuse Linux Enterprise Desktop+615/10/201517/6/2026
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535 on Linux allows remote attackers to execute arbitrary code via a crafted SWF file, as exploited in the wild in October 2015.
ModificadaMedia (6.8)5.0%—Suse Linux Enterprise DebuginfoSuse Linux Enterprise DesktopSuse Linux Enterprise ServerGNU Glibc+228/9/201517/6/2026
Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response, which triggers a call with a misaligned buffer.
ModificadaAlta (7.2)0.63%—XENSuse Linux Enterprise DebuginfoSuse Linux Enterprise DesktopSuse Linux Enterprise Server+412/8/201517/6/2026
Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.
AnalizadaAlta (8.8)69%⚠ Explotación activa💥 ExploitMozilla FirefoxMozilla Firefox OSOracle SolarisCanonical Ubuntu Linux+118/8/201517/6/2026
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
ModificadaMedia (6.8)18%—Google ChromeLibexpat Project LibexpatPythonDebian Linux+923/7/201517/6/2026
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to…
AnalizadaCrítica (9.8)25%⚠ Explotación activaOracle JDKOracle JRECanonical Ubuntu LinuxDebian Linux+1716/7/201517/6/2026
Unspecified vulnerability in Oracle Java SE 6u95, 7u80, and 8u45, and Java SE Embedded 7u75 and 8u33 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2015-4732.
AnalizadaCrítica (9.8)19%⚠ Explotación activaRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server EUSRedhat Enterprise Linux Workstation+514/7/201517/6/2026
Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote…
AnalizadaCrítica (9.8)94%⚠ Explotación activa💥 ExploitAdobe Flash PlayerAdobe Flash Player Desktop RuntimeRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+514/7/201517/6/2026
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote…
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitAdobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+78/7/201517/6/2026
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows and OS X and 11.x through 11.2.202.468 on Linux allows remote attackers to execute arbitrary code or cause a denial of service (memory…
ModificadaAlta (7.5)4.7%—Mozilla FirefoxMozilla Firefox ESROracle SolarisNovell Suse Linux Enterprise Software Development KIT+26/7/201517/6/2026
PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workers, which might allow remote attackers to execute arbitrary code by leveraging a Same Origin Policy bypass.
ModificadaAlta (10)5.5%—Mozilla ThunderbirdMozilla FirefoxMozilla Firefox ESRNovell Suse Linux Enterprise Software Development KIT+56/7/201517/6/2026
Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.
ModificadaAlta (10)2.7%—Mozilla FirefoxNovell Suse Linux Enterprise Software Development KITCanonical Ubuntu LinuxNovell Suse Linux Enterprise Desktop+56/7/201517/6/2026
The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.
ModificadaAlta (10)2.7%—Canonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT+66/7/201517/6/2026
The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YCbCr implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
ModificadaAlta (10)2.7%—Mozilla FirefoxMozilla Firefox ESRCanonical Ubuntu LinuxOracle Solaris+66/7/201517/6/2026
The rx::d3d11::SetBufferData function in the Direct3D 11 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
ModificadaAlta (9.3)3.8%—Mozilla FirefoxMozilla ThunderbirdMozilla Firefox ESROracle Solaris+56/7/201517/6/2026
The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.
ModificadaAlta (9.3)3.8%—Mozilla FirefoxMozilla Firefox ESRMozilla ThunderbirdNovell Suse Linux Enterprise Software Development KIT+56/7/201517/6/2026
nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.
ModificadaAlta (10)2.7%—Suse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITSuse Linux Enterprise Server+66/7/201517/6/2026
The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
ModificadaAlta (10)6.2%—Mozilla FirefoxOracle SolarisMozilla Firefox ESRNovell Suse Linux Enterprise Desktop+16/7/201517/6/2026
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a dedicated worker.
ModificadaMedia (4.3)3.6%—Novell Suse Linux Enterprise Software Development KITDebian LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+36/7/201517/6/2026
Mozilla Network Security Services (NSS) before 3.19.1, as used in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and other products, does not properly perform Elliptical Curve Cryptography (ECC) multiplications, which makes it easier for remote attackers to spoof ECDSA signatures via…