Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
297 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.45% | — | Canonical Ubuntu LinuxDebian LinuxFedoraproject FedoraNovell Suse Linux Enterprise Desktop+6 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related to Hotspot. | |
| Modificada | Alta (10) | 6.9% | — | Canonical Ubuntu LinuxDebian LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+4 | 21/1/2015 | 17/6/2026 | Unspecified vulnerability in Oracle Java SE 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. | |
| Modificada | Alta (7.8) | 1.5% | 💥 Exploit | Linux KernelRedhat Enterprise Linux EUSCanonical Ubuntu LinuxOpensuse Evergreen+2 | 17/12/2014 | 17/6/2026 | arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space. | |
| Modificada | Baja (3.3) | 0.70% | — | Linux KernelCanonical Ubuntu LinuxOpensuse EvergreenOpensuse+2 | 12/12/2014 | 17/6/2026 | The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_enabled setting for KVM guest kernels, which makes it easier for guest OS users to bypass the ASLR protection mechanism via a crafted application that reads a 16-bit value. | |
| Modificada | Media (5) | 9.7% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerMuttDebian Linux+1 | 2/12/2014 | 17/6/2026 | The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function. | |
| Modificada | Media (5.5) | 0.74% | — | Linux KernelCanonical Ubuntu LinuxNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise Server+7 | 10/11/2014 | 17/6/2026 | The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application. | |
| Modificada | Alta (7.8) | 0.56% | — | Linux KernelDebian LinuxOpensuse EvergreenSuse Linux Enterprise Real Time Extension+1 | 10/11/2014 | 17/6/2026 | The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.17.2 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS… | |
| Modificada | Alta (7.8) | 0.59% | — | Linux KernelOpensuse EvergreenSuse Linux Enterprise Server | 10/11/2014 | 17/6/2026 | kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via a crafted application. | |
| Modificada | Media (5.5) | 0.52% | — | Linux KernelNovell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse Evergreen+6 | 10/11/2014 | 17/6/2026 | arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel before 3.17.2 on Intel processors does not ensure that the value in the CR4 control register remains the same after a VM entry, which allows host OS users to kill arbitrary processes or cause a denial of service (system disruption) by leveraging /dev/kvm… | |
| Modificada | Alta (7.5) | 8.6% | — | Linux KernelRedhat Enterprise MRGCanonical Ubuntu LinuxDebian Linux+8 | 10/11/2014 | 17/6/2026 | The sctp_assoc_lookup_asconf_ack function in net/sctp/associola.c in the SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (panic) via duplicate ASCONF chunks that trigger an incorrect uncork within the side-effect interpreter. | |
| Modificada | Alta (7.5) | 7.5% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise MRGCanonical Ubuntu Linux+6 | 10/11/2014 | 17/6/2026 | The SCTP implementation in the Linux kernel through 3.17.2 allows remote attackers to cause a denial of service (system crash) via a malformed ASCONF chunk, related to net/sctp/sm_make_chunk.c and net/sctp/sm_statefuns.c. | |
| Modificada | Media (5.5) | 0.59% | — | Linux KernelRedhat Enterprise LinuxCanonical Ubuntu LinuxDebian Linux+3 | 10/11/2014 | 17/6/2026 | arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. | |
| Modificada | Media (5.5) | 0.43% | — | Linux KernelRedhat Enterprise LinuxCanonical Ubuntu LinuxDebian Linux+2 | 10/11/2014 | 17/6/2026 | arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. | |
| Modificada | Media (5.5) | 0.60% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxOpensuse Evergreen+1 | 10/11/2014 | 17/6/2026 | The WRMSR processing functionality in the KVM subsystem in the Linux kernel through 3.17.2 does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the… | |
| Modificada | Baja (3.4) | 100% | 💥 PoC | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server+16 | 15/10/2014 | 17/6/2026 | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. | |
| Modificada | Media (4.7) | 0.37% | — | Linux KernelSuse Linux Enterprise Server | 13/10/2014 | 17/6/2026 | Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT flag. | |
| Modificada | Media (5.5) | 0.67% | — | Novell Suse Linux Enterprise ServerLinux KernelCanonical Ubuntu Linux | 13/10/2014 | 17/6/2026 | The pivot_root implementation in fs/namespace.c in the Linux kernel through 3.17 does not properly interact with certain locations of a chroot directory, which allows local users to cause a denial of service (mount-tree loop) via . (dot) values in both arguments to the pivot_root system call. | |
| Modificada | Media (4.9) | 0.53% | — | Linux KernelNovell Suse Linux Enterprise Server | 28/9/2014 | 16/6/2026 | The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket. | |
| Modificada | Alta (10) | 9.3% | — | Adobe AIR SDKOpensuseSuse Linux Enterprise DesktopAdobe Flash Player+1 | 10/9/2014 | 17/6/2026 | Use-after-free vulnerability in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS X and before 11.2.202.406 on Linux, Adobe AIR before 15.0.0.249 on Windows and OS X and before 15.0.0.252 on Android, Adobe AIR SDK before 15.0.0.249, and Adobe AIR SDK & Compiler before… | |
| Modificada | Media (4.3) | 1.2% | — | Suse Linux Enterprise Real Time ExtensionOpensuse EvergreenSuse Linux Enterprise ServerSuse Linux Enterprise Server+2 | 1/9/2014 | 17/6/2026 | The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel through 3.16.1 miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to (1) cause a denial of service (host OS memory corruption) or possibly have unspecified other impact by triggering a large… | |
| Modificada | Media (6.5) | 3.5% | — | Oracle MysqlVmware Vcenter Server ApplianceOracle SolarisOpensuse Project Suse Linux Enterprise Desktop+8 | 17/7/2014 | 17/6/2026 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.37 and earlier and 5.6.17 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SRINFOSC. | |
| Modificada | Baja (2.1) | 1.1% | 💥 Exploit | Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise High Availability ExtensionSuse Linux Enterprise Desktop+1 | 23/6/2014 | 17/6/2026 | The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0 read access for a MEDIA_IOC_ENUM_ENTITIES ioctl call. | |
| Modificada | Alta (10) | 6.1% | — | DirectfbOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Software Development KIT+2 | 11/6/2014 | 17/6/2026 | The Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers an out-of-bounds write. | |
| Modificada | Alta (10) | 6.8% | — | OpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Software Development KITSuse Linux Enterprise Workstation Extension+2 | 11/6/2014 | 17/6/2026 | Multiple integer signedness errors in the Dispatch_Write function in proxy/dispatcher/idirectfbsurface_dispatcher.c in DirectFB 1.4.13 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the Voodoo interface, which triggers a stack-based buffer overflow. | |
| Modificada | Media (4.3) | 2.9% | — | Opalvoip Portable Tool LibraryEkigaSuse Linux Enterprise Software Development KITSuse Linux Enterprise Desktop | 23/5/2014 | 16/6/2026 | The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted PXML document containing a large number of nested entity references, aka… |