Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.2)0.43%—Linux KernelNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Real Time Extension27/4/201617/6/2026
Memory leak in the cuse_channel_release function in fs/fuse/cuse.c in the Linux kernel before 4.4 allows local users to cause a denial of service (memory consumption) or possibly have unspecified other impact by opening /dev/cuse many times.
ModificadaMedia (5.4)2.4%💥 ExploitNovell Service Desk22/4/201617/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Micro Focus Novell Service Desk before 7.2 allow remote authenticated users to inject arbitrary web script or HTML via a certain (1) user name, (2) tf_aClientFirstName, (3) tf_aClientLastName, (4) ta_selectedTopicContent, (5) tf_orgUnitName, (6)…
ModificadaMedia (6.5)6.6%💥 ExploitNovell Service Desk22/4/201617/6/2026
LiveTime/WebObjects/LiveTime.woa/wa/DownloadAction/downloadFile in Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to conduct Hibernate Query Language (HQL) injection attacks and obtain sensitive information via the entityName parameter.
ModificadaMedia (6.5)6.9%💥 ExploitNovell Service Desk22/4/201617/6/2026
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request to a LiveTime.woa URL, as demonstrated by obtaining sensitive information via a (1) downloadLogFiles or (2) downloadFile action.
ModificadaAlta (7.2)64%💥 ExploitNovell Service Desk22/4/201617/6/2026
Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.
ModificadaMedia (4.3)1.2%—Novell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapGoogle ChromeDebian Linux18/4/201617/6/2026
The Extensions subsystem in Google Chrome before 50.0.2661.75 incorrectly relies on GetOrigin method calls for origin comparisons, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted extension.
ModificadaMedia (4.3)1.2%—Debian LinuxNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapGoogle Chrome18/4/201617/6/2026
The WebContentsImpl::FocusLocationBarByDefault function in content/browser/web_contents/web_contents_impl.cc in Google Chrome before 50.0.2661.75 mishandles focus for certain about:blank pages, which allows remote attackers to spoof the address bar via a crafted URL.
ModificadaAlta (8.2)1.1%💥 PoCXENNovell Suse Linux Enterprise Real Time Extension14/4/201617/6/2026
Xen, when used on a system providing PV backends, allows local guest OS administrators to cause a denial of service (host OS crash) or gain privileges by writing to memory shared between the frontend and backend, aka a double fetch vulnerability.
ModificadaMedia (4.4)0.45%—XENCanonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise Debuginfo+113/4/201617/6/2026
The PCI backend driver in Xen, when running on an x86 system and using Linux 3.1.x through 4.3.x as the driver domain, allows local guest administrators to generate a continuous stream of WARN messages and cause a denial of service (disk consumption) by leveraging a system with access to a passed-through MSI or MSI-X…
ModificadaMedia (6.1)0.86%—Novell Filr18/3/201617/6/2026
Cross-site scripting (XSS) vulnerability in Novell Filr 1.2 before Hot Patch 4 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
ModificadaMedia (4.3)2.2%—Novell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuseMozilla Firefox+213/3/201617/6/2026
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.
ModificadaMedia (6.5)2.4%—Mozilla FirefoxNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse13/3/201617/6/2026
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.
ModificadaMedia (4.3)2.0%—Novell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuseMozilla Firefox13/3/201617/6/2026
Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.
ModificadaAlta (8.8)2.3%—Mozilla FirefoxMozilla ThunderbirdNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse Leap+213/3/201617/6/2026
The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or…
ModificadaAlta (8.8)3.2%—Mozilla FirefoxMozilla ThunderbirdNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse Leap+113/3/201617/6/2026
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/arm/Assembler-arm.cpp, and unknown other vectors.
ModificadaAlta (8.8)3.0%—Oracle LinuxNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse+213/3/201617/6/2026
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
ModificadaCrítica (9.8)2.6%—Google ChromeNovell Suse Package HUB FOR Suse Linux EnterpriseOpensuse LeapOpensuse+121/2/201617/6/2026
Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.
ModificadaMedia (5.3)1.3%—Novell Zenworks Configuration Management18/2/201617/6/2026
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.
ModificadaMedia (4.6)1.8%💥 ExploitNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise DebuginfoNovell Suse Linux Enterprise Real Time ExtensionNovell Suse Linux Enterprise Server+18/2/201617/6/2026
The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by inserting a USB device that lacks a bulk-out endpoint.
ModificadaMedia (4.9)0.68%—Novell Suse Linux Enterprise Real Time ExtensionRedhat Enterprise Linux19/10/201517/6/2026
The usbvision driver in the Linux kernel package 3.10.0-123.20.1.el7 through 3.10.0-229.14.1.el7 in Red Hat Enterprise Linux (RHEL) 7.1 allows physically proximate attackers to cause a denial of service (panic) via a nonzero bInterfaceNumber value in a USB device descriptor.
ModificadaMedia (4.3)2.3%—Novell Groupwise22/7/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in WebAccess in Novell GroupWise 2012 before Support Pack 4 and 2014 before Support Pack 2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)4.7%—Mozilla FirefoxMozilla Firefox ESROracle SolarisNovell Suse Linux Enterprise Software Development KIT+26/7/201517/6/2026
PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workers, which might allow remote attackers to execute arbitrary code by leveraging a Same Origin Policy bypass.
ModificadaAlta (10)5.5%—Mozilla ThunderbirdMozilla FirefoxMozilla Firefox ESRNovell Suse Linux Enterprise Software Development KIT+56/7/201517/6/2026
Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.
ModificadaAlta (10)2.7%—Mozilla FirefoxNovell Suse Linux Enterprise Software Development KITCanonical Ubuntu LinuxNovell Suse Linux Enterprise Desktop+56/7/201517/6/2026
The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.
ModificadaAlta (9.3)3.8%—Mozilla FirefoxMozilla ThunderbirdMozilla Firefox ESROracle Solaris+56/7/201517/6/2026
The nsZipArchive::BuildFileList function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.
Orbitaley — Vulnerabilidades