Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
230 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.3) | 0.49% | — | Linux KernelSuse Linux Enterprise Server | 8/6/2013 | 16/6/2026 | The cifs_find_smb_ses function in fs/cifs/connect.c in the Linux kernel before 2.6.36 does not properly determine the associations between users and sessions, which allows local users to bypass CIFS share authentication by leveraging a mount of a share by a different user. | |
| Modificada | Alta (8.8) | 3.8% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdMozilla Thunderbird ESR+10 | 21/11/2012 | 16/6/2026 | Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 on Mac OS X allows remote attackers to execute arbitrary code via an HTML document. | |
| Modificada | Media (6.4) | 8.8% | — | Linux KernelNovell Suse Linux Enterprise Server | 21/6/2012 | 16/6/2026 | The ROSE protocol implementation in the Linux kernel before 2.6.39 does not verify that certain data-length values are consistent with the amount of data sent, which might allow remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read) via crafted data to a… | |
| Modificada | Alta (7.8) | 4.2% | — | Novell Suse Linux Enterprise ServerLinux Kernel | 21/6/2012 | 16/6/2026 | The rose_parse_ccitt function in net/rose/rose_subr.c in the Linux kernel before 2.6.39 does not validate the FAC_CCITT_DEST_NSAP and FAC_CCITT_SRC_NSAP fields, which allows remote attackers to (1) cause a denial of service (integer underflow, heap memory corruption, and panic) via a small length value in data sent to… | |
| Modificada | Baja (1.2) | 0.56% | — | Linux KernelNovell Suse Linux Enterprise ServerRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+4 | 13/6/2012 | 16/6/2026 | The rio_ioctl function in drivers/net/ethernet/dlink/dl2k.c in the Linux kernel before 3.3.7 does not restrict access to the SIOCSMIIREG command, which allows local users to write data to an Ethernet adapter via an ioctl call. | |
| Modificada | Media (6.8) | 73% | 💥 PoC | Google ChromeApple Iphone OSApple MAC OS XApple MAC OS X Server+3 | 16/2/2012 | 16/6/2026 | Integer overflow in libpng, as used in Google Chrome before 17.0.963.56, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an integer truncation. | |
| Modificada | Baja (2.1) | 0.46% | — | Linux KernelRedhat Enterprise Linux ServerRedhat Enterprise Linux WorkstationSuse Linux Enterprise Desktop+2 | 23/12/2010 | 16/6/2026 | arch/x86/kvm/x86.c in the Linux kernel before 2.6.36.2 does not initialize certain structure members, which allows local users to obtain potentially sensitive information from kernel stack memory via read operations on the /dev/kvm device. | |
| Modificada | Alta (7.5) | 5.9% | — | Google ChromeXmlsoft Libxml2Apple ItunesApple Safari+13 | 7/12/2010 | 16/6/2026 | Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling. | |
| Modificada | Media (4.3) | 2.7% | — | Google ChromeApple ItunesApple SafariApple Iphone OS+11 | 17/11/2010 | 16/6/2026 | libxml2 before 2.7.8, as used in Google Chrome before 7.0.517.44, Apple Safari 5.0.2 and earlier, and other products, reads from invalid memory locations during processing of malformed XPath expressions, which allows context-dependent attackers to cause a denial of service (application crash) via a crafted XML… | |
| Modificada | Alta (7.1) | 0.39% | — | Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise High Availability ExtensionSuse Linux Enterprise Desktop+1 | 30/9/2010 | 16/6/2026 | The btrfs_ioctl_clone function in fs/btrfs/ioctl.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a (1) BTRFS_IOC_CLONE or (2) BTRFS_IOC_CLONE_RANGE ioctl call that specifies this file as a donor. | |
| Modificada | Alta (7.8) | 3.5% | 💥 Exploit | Linux KernelVmware ESXSuse Linux Enterprise DesktopSuse Linux Enterprise Server | 24/9/2010 | 16/6/2026 | The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit platforms do not properly allocate the userspace memory required for the 32-bit compatibility layer, which allows local users to gain privileges by leveraging the ability of the compat_mc_getsockopt… | |
| Modificada | Media (5.5) | 0.41% | — | Linux KernelOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server+2 | 21/9/2010 | 16/6/2026 | The xfs_ioc_fsgetxattr function in fs/xfs/linux-2.6/xfs_ioctl.c in the Linux kernel before 2.6.36-rc4 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an ioctl call. | |
| Modificada | Media (5.5) | 0.42% | — | Linux KernelCanonical Ubuntu LinuxOpensuseSuse Linux Enterprise Desktop+9 | 21/9/2010 | 16/6/2026 | The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump operations, which allows local users to obtain potentially sensitive information from kernel memory via vectors related to (1) the… | |
| Modificada | Alta (7.8) | 0.51% | — | Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise Server | 8/9/2010 | 16/6/2026 | The keyctl_session_to_parent function in security/keys/keyctl.c in the Linux kernel 2.6.35.4 and earlier expects that a certain parent session keyring exists, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a… | |
| Modificada | Alta (7.8) | 0.41% | — | Linux KernelVmware ESXCanonical Ubuntu LinuxDebian Linux+11 | 8/9/2010 | 16/6/2026 | The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, which allows local users to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact by… | |
| Modificada | Alta (7.8) | 0.42% | — | Linux KernelVmware ESXCanonical Ubuntu LinuxSuse Linux Enterprise Desktop+1 | 8/9/2010 | 16/6/2026 | The DNS resolution functionality in the CIFS implementation in the Linux kernel before 2.6.35, when CONFIG_CIFS_DFS_UPCALL is enabled, relies on a user's keyring for the dns_resolver upcall in the cifs.upcall userspace helper, which allows local users to spoof the results of DNS queries and perform arbitrary CIFS… | |
| Modificada | Alta (10) | 2.9% | — | Linux KernelCanonical Ubuntu LinuxSuse Linux Enterprise DesktopSuse Linux Enterprise High Availability Extension+1 | 8/9/2010 | 16/6/2026 | The pppol2tp_xmit function in drivers/net/pppol2tp.c in the L2TP implementation in the Linux kernel before 2.6.34 does not properly validate certain values associated with an interface, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via… | |
| Modificada | Media (5.5) | 0.38% | — | Linux KernelVmware ESXCanonical Ubuntu LinuxSuse Linux Enterprise High Availability Extension+2 | 8/9/2010 | 16/6/2026 | The mext_check_arguments function in fs/ext4/move_extent.c in the Linux kernel before 2.6.35 allows local users to overwrite an append-only file via a MOVE_EXT ioctl call that specifies this file as a donor. | |
| Modificada | Alta (10) | 3.0% | — | Google ChromeOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server | 15/6/2010 | 16/6/2026 | Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remote fonts in conjunction with shadow DOM trees, aka rdar problem 8007953. NOTE: this might overlap… | |
| Modificada | Media (4.3) | 1.3% | — | Google ChromeOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server | 15/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in editing/markup.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to inject arbitrary web script or HTML via vectors related to the node.innerHTML property of a TEXTAREA element. NOTE: this might overlap CVE-2010-1762. | |
| Modificada | Alta (9.3) | 2.8% | — | Google ChromeOpensuseSuse Linux Enterprise DesktopSuse Linux Enterprise Server | 15/6/2010 | 16/6/2026 | rendering/FixedTableLayout.cpp in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an HTML document that has a large colspan attribute within a table. | |
| Modificada | Alta (9.3) | 4.8% | — | Apple SafariApple WebkitGoogle ChromeCanonical Ubuntu Linux+3 | 11/6/2010 | 16/6/2026 | WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Apple Safari before 4.1 on Mac OS X 10.4, and Google Chrome before 5.0.375.70 does not properly handle a transformation of a text node that has the IBM1147 character set, which allows remote attackers to execute arbitrary code or cause a… | |
| Modificada | Alta (7) | 4.9% | 💥 Exploit | Linux KernelNovell Linux DesktopOpensuseSuse Linux Enterprise Desktop+10 | 4/11/2009 | 16/6/2026 | Multiple race conditions in fs/pipe.c in the Linux kernel before 2.6.32-rc6 allow local users to cause a denial of service (NULL pointer dereference and system crash) or gain privileges by attempting to open an anonymous pipe via a /proc/*/fd/ pathname. | |
| Modificada | Media (5.5) | 0.99% | 💥 Exploit | Linux KernelCanonical Ubuntu LinuxFedoraproject FedoraOpensuse+4 | 22/10/2009 | 16/6/2026 | net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on this socket, and then performing a series of connect operations to this socket. | |
| Modificada | Alta (7.8) | 0.36% | — | Gnome GlibOpensuseSuse Linux Enterprise Server | 22/9/2009 | 16/6/2026 | The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory. |