Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2667▼ 241 respecto a la semana anterior
Críticas / altas1361▲ 103 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

215 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)6.3%—Nodejs Node.jsFedoraproject Fedora7/4/201617/6/2026
Node.js 0.10.x before 0.10.42, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allow remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
ModificadaAlta (7.5)27%—OpensslNodejs Node.jsCanonical Ubuntu LinuxDebian Linux3/3/201617/6/2026
Multiple integer overflows in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g allow remote attackers to cause a denial of service (heap memory corruption or NULL pointer dereference) or possibly have unspecified other impact via a long digit string that is mishandled by the (1) BN_dec2bn or (2) BN_hex2bn function,…
ModificadaMedia (5.1)1.9%—OpensslNodejs Node.jsDebian LinuxCanonical Ubuntu Linux3/3/201617/6/2026
The MOD_EXP_CTIME_COPY_FROM_PREBUF function in crypto/bn/bn_exp.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g does not properly consider cache-bank access times during modular exponentiation, which makes it easier for local users to discover RSA keys by running a crafted application on the same Intel Sandy…
ModificadaAlta (7.5)5.4%—Nodejs Node.js2/1/201617/6/2026
Node.js 0.12.x before 0.12.9, 4.x before 4.2.3, and 5.x before 5.1.1 does not ensure the availability of a parser for each HTTP socket, which allows remote attackers to cause a denial of service (uncaughtException and service outage) via a pipelined HTTP request.
ModificadaAlta (7.5)44%—OpensslCanonical Ubuntu LinuxDebian LinuxNodejs Node.js6/12/201517/6/2026
crypto/rsa/rsa_ameth.c in OpenSSL 1.0.1 before 1.0.1q and 1.0.2 before 1.0.2e allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an RSA PSS ASN.1 signature that lacks a mask generation function parameter.
ModificadaAlta (7.5)25%—OpensslNodejs Node.jsCanonical Ubuntu Linux6/12/201517/6/2026
The Montgomery squaring implementation in crypto/bn/asm/x86_64-mont5.pl in OpenSSL 1.0.2 before 1.0.2e on the x86_64 platform, as used by the BN_mod_exp function, mishandles carry propagation and produces incorrect output, which makes it easier for remote attackers to obtain sensitive private-key information via an…
ModificadaCrítica (9.8)5.7%—Google ChromeNodejs Node.jsDebian Linux6/12/201517/6/2026
The BasicJsonStringifier::SerializeJSArray function in json-stringifier.h in the JSON stringifier in Google V8, as used in Google Chrome before 47.0.2526.73, improperly loads array elements, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other…
ModificadaAlta (7.5)3.0%—Google V8Iojs Io.jsNodejs Node.js9/7/201517/6/2026
The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before 2.3.3, and other products, does not verify that there is memory available for a UTF-16 surrogate pair, which allows remote attackers to cause a denial of service (memory…
ModificadaAlta (10)3.2%—Fedoraproject FedoraLibuv Project LibuvNodejs Node.js18/5/201517/6/2026
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
ModificadaAlta (10)13%—Joyent Node.js11/12/201417/6/2026
Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.
ModificadaMedia (5)8.3%—Nodejs Node.js19/10/201417/6/2026
The qs module before 1.0.0 in Node.js does not call the compact function for array data, which allows remote attackers to cause a denial of service (memory consumption) by using a large index value to create a sparse array.
ModificadaAlta (7.5)4.3%—Fedoraproject FedoraApple XcodeJoyent Node.js8/10/201417/6/2026
visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.
ModificadaAlta (7.4)95%—OpensslRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise WEB Server+125/6/201417/6/2026
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive…
ModificadaAlta (7.5)5.7%—Google ChromeGoogle V8Nodejs Node.jsDebian Linux5/3/201417/6/2026
Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
ModificadaAlta (7.5)2.9%—Google ChromeRedhat OpenstackDebian LinuxNodejs Node.js31/7/201316/6/2026
Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."