Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
519 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (1.9) | 0.40% | — | Oracle JDKOracle JRECanonical Ubuntu LinuxSuse Linux Enterprise Server | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 7u72 and 8u25 allows local users to affect integrity via unknown vectors related to Serviceability. | |
| Modificada | Alta (7.2) | 1.5% | — | Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+4 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JAX-WS. | |
| Modificada | Media (5) | 5.0% | — | Oracle JDKOracle JREOracle JrockitCanonical Ubuntu Linux+5 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in the Java SE, Java SE Embedded, JRockit component in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows remote attackers to affect availability via unknown vectors related to Security. | |
| Modificada | Alta (10) | 6.9% | — | Oracle JDKOracle JRECanonical Ubuntu LinuxDebian Linux+4 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to RMI. | |
| Modificada | Media (5.8) | 3.9% | — | Oracle JDKOracle JRENovell Suse Linux Enterprise Desktop | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality and availability via unknown vectors related to Deployment. | |
| Modificada | Media (6.9) | 0.44% | — | Novell Suse Linux Enterprise DesktopOracle JDKOracle JRE | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Deployment. | |
| Modificada | Media (5) | 4.2% | — | Canonical Ubuntu LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse+2 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Libraries. | |
| Modificada | Alta (9.3) | 5.9% | — | Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise ServerOpensuse+3 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. | |
| Modificada | Media (5.4) | 0.45% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraNovell Suse Linux Enterprise Desktop+6 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related to Hotspot. | |
| Modificada | Alta (10) | 6.9% | — | Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+4 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. | |
| Modificada | Alta (7.8) | 1.5% | 💥 Exploit | Linux KernelRedhat Enterprise Linux EUSCanonical Ubuntu LinuxOpensuse Evergreen+2 | 17/12/2014 | 17/6/2026 | arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space. | |
| Modificada | Baja (3.3) | 0.70% | — | Linux KernelCanonical Ubuntu LinuxOpensuse EvergreenOpensuse+2 | 12/12/2014 | 17/6/2026 | The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value. | |
| Modificada | Media (5) | 9.7% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerMuttDebian Linux+1 | 2/12/2014 | 17/6/2026 | The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function. | |
| Modificada | Media (5.5) | 0.74% | — | Linux KernelCanonical Ubuntu LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+7 | 10/11/2014 | 17/6/2026 | The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application. | |
| Modificada | Alta (7.8) | 0.56% | — | Linux KernelDebian LinuxOpensuse EvergreenSuse Linux Enterprise Real Time Extension+1 | 10/11/2014 | 17/6/2026 | The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS… | |
| Modificada | Alta (7.8) | 0.59% | — | Linux KernelOpensuse EvergreenSuse Linux Enterprise Server | 10/11/2014 | 17/6/2026 | kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via a crafted application. | |
| Modificada | Media (5.5) | 0.52% | — | Linux KernelNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse Evergreen+6 | 10/11/2014 | 17/6/2026 | arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm… | |
| Modificada | Alta (7.5) | 8.6% | — | Linux KernelRedhat Enterprise MRGCanonical Ubuntu LinuxDebian Linux+8 | 10/11/2014 | 17/6/2026 | The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter. | |
| Modificada | Alta (7.5) | 7.5% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRGCanonical Ubuntu Linux+6 | 10/11/2014 | 17/6/2026 | The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c. | |
| Modificada | Media (5.5) | 0.59% | — | Linux KernelRedhat Enterprise LinuxCanonical Ubuntu LinuxDebian Linux+3 | 10/11/2014 | 17/6/2026 | arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. | |
| Modificada | Media (5.5) | 0.43% | — | Linux KernelRedhat Enterprise LinuxCanonical Ubuntu LinuxDebian Linux+2 | 10/11/2014 | 17/6/2026 | arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. | |
| Modificada | Media (5.5) | 0.60% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxOpensuse Evergreen+1 | 10/11/2014 | 17/6/2026 | The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the… | |
| Modificada | Baja (3.4) | 100% | 💥 PoC | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server+16 | 15/10/2014 | 17/6/2026 | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. | |
| Modificada | Media (4.7) | 0.37% | — | Linux KernelSuse Linux Enterprise Server | 13/10/2014 | 17/6/2026 | Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT flag. | |
| Modificada | Media (5.5) | 0.67% | — | Novell Suse Linux Enterprise ServerLinux KernelCanonical Ubuntu Linux | 13/10/2014 | 17/6/2026 | The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call. |