Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.9) | 0.40% | — | Oracle Solaris | 24/4/2017 | 17/6/2026 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require… | |
| Modificada | Alta (8.2) | 0.47% | — | Oracle Solaris | 24/4/2017 | 17/6/2026 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require… | |
| Modificada | Media (6.6) | 0.39% | — | Oracle Solaris | 24/4/2017 | 17/6/2026 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Smartcard Libraries). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful… | |
| Modificada | Alta (7.7) | 2.1% | — | Oracle Solaris | 24/4/2017 | 17/6/2026 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized NIC driver). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise Solaris. While the… | |
| Modificada | Crítica (9.6) | 1.6% | — | Oracle Solaris | 24/4/2017 | 17/6/2026 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized NIC driver). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise Solaris. While the… | |
| Modificada | Baja (3.3) | 0.39% | — | Oracle Solaris | 24/4/2017 | 17/6/2026 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this… | |
| Modificada | Alta (7.3) | 1.7% | — | Oracle Solaris | 24/4/2017 | 17/6/2026 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Remote Administration Daemon). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful… | |
| Modificada | Baja (3.3) | 0.39% | — | Oracle Solaris | 24/4/2017 | 17/6/2026 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Zone). The supported version that is affected is 11.3. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this… | |
| Modificada | Baja (2.8) | 0.37% | — | Oracle Solaris Cluster | 24/4/2017 | 17/6/2026 | Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition). The supported version that is affected is 4.3. Easily "exploitable" vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris Cluster executes to compromise… | |
| Modificada | Alta (7.5) | 6.2% | — | Xmlsoft Libxml2Debian LinuxOracle Solaris | 11/4/2017 | 17/6/2026 | The xmlBufAttrSerializeTxtContent function in xmlsave.c in libxml2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and application crash) via a non-UTF-8 attribute value, related to serialization. NOTE: this vulnerability may be a duplicate of CVE-2016-3627. | |
| Modificada | Baja (3.3) | 0.43% | — | Oracle Solaris | 27/1/2017 | 17/6/2026 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks require… | |
| Modificada | Media (5.7) | 0.33% | — | Oracle Solaris | 27/1/2017 | 17/6/2026 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized block driver). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Solaris executes to compromise… | |
| Modificada | Baja (3.7) | 1.2% | — | Oracle Solaris | 27/1/2017 | 17/6/2026 | Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported version that is affected is 11.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris. Successful attacks of this… | |
| Modificada | Alta (7.8) | 15% | 💥 PoC | 7-zipFedoraproject FedoraOracle Solaris | 13/12/2016 | 17/6/2026 | Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image. | |
| Modificada | Alta (8.8) | 5.0% | — | ImagemagickOracle Solaris | 13/12/2016 | 17/6/2026 | Buffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5-4 and 7.x before 7.0.2-6 allows remote attackers to cause a denial of service (out-of-bounds read, memory leak, and crash) via a crafted image. | |
| Modificada | Alta (7.5) | 6.5% | — | ImagemagickOracle Solaris | 13/12/2016 | 17/6/2026 | MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read. | |
| Modificada | Crítica (9.8) | 13% | — | ImagemagickOracle Solaris | 13/12/2016 | 17/6/2026 | Integer overflow in MagickCore/profile.c in ImageMagick before 7.0.2-1 allows remote attackers to cause a denial of service (segmentation fault) or possibly execute arbitrary code via vectors involving the offset variable. | |
| Modificada | Crítica (9.8) | 6.1% | — | Oracle SolarisImagemagick | 13/12/2016 | 17/6/2026 | The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validation of (1) pixel.red, (2) pixel.green, and (3) pixel.blue. | |
| Modificada | Crítica (9.8) | 6.1% | — | Oracle SolarisImagemagick | 13/12/2016 | 17/6/2026 | The ReadDCMImage function in DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact via vectors involving the for statement in computing the pixel scaling table. | |
| Modificada | Crítica (9.8) | 5.4% | — | Oracle SolarisImagemagick | 13/12/2016 | 17/6/2026 | The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of NULL pointer checks. | |
| Modificada | Alta (8.1) | 4.8% | — | Oracle SolarisImagemagick | 13/12/2016 | 17/6/2026 | The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in… | |
| Modificada | Crítica (9.8) | 4.8% | — | ImagemagickOracle Solaris | 13/12/2016 | 17/6/2026 | The VerticalFilter function in the DDS coder in ImageMagick before 6.9.4-3 and 7.x before 7.0.1-4 allows remote attackers to have unspecified impact via a crafted DDS file, which triggers an out-of-bounds read. | |
| Modificada | Media (6.5) | 3.5% | — | Oracle SolarisPivotal Software Rabbitmq | 9/12/2016 | 17/6/2026 | The Management plugin in RabbitMQ before 3.6.1 allows remote authenticated users with certain privileges to cause a denial of service (resource consumption) via the (1) lengths_age or (2) lengths_incr parameter. | |
| Modificada | Baja (3.3) | 0.34% | — | Oracle Solaris | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect availability via vectors related to Lynx. | |
| Modificada | Media (6.1) | 0.34% | — | Oracle Solaris | 25/10/2016 | 17/6/2026 | Unspecified vulnerability in Oracle Sun Solaris 11.3 allows local users to affect integrity and availability via vectors related to Kernel Zones. |