Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
222 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 3.3% | — | Cabextract LibmspackCabextract Project CabextractCanonical Ubuntu LinuxDebian Linux+4 | 28/7/2018 | 17/6/2026 | An issue was discovered in mspack/chmd.c in libmspack before 0.7alpha. There is an off-by-one error in the CHM PMGI/PMGL chunk number validity checks, which could lead to denial of service (uninitialized data dereference and application crash). | |
| Modificada | Alta (7.2) | 1.7% | — | Redhat Ansible TowerRedhat Cloudforms | 27/7/2018 | 17/6/2026 | A flaw was found in Ansible Tower's interface before 3.1.5 and 3.2.0 with SCM repositories. If a Tower project (SCM repository) definition does not have the 'delete before update' flag set, an attacker with commit access to the upstream playbook source repository could create a Trojan playbook that, when executed by… | |
| Modificada | Media (6.5) | 3.1% | — | Freedesktop PopplerCanonical Ubuntu LinuxDebian LinuxRedhat Ansible Tower+4 | 25/7/2018 | 17/6/2026 | Poppler through 0.62 contains an out of bounds read vulnerability due to an incorrect memory access that is not mapped in its memory space, as demonstrated by pdfunite. This can result in memory corruption and denial of service. This may be exploitable when a victim opens a specially crafted PDF file. | |
| Modificada | Crítica (9.8) | 4.2% | — | Gnome LibsoupCanonical Ubuntu LinuxDebian LinuxRedhat Ansible Tower+5 | 5/7/2018 | 17/6/2026 | The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname. | |
| Modificada | Alta (7.5) | 4.9% | — | PythonDebian LinuxRedhat Ansible TowerRedhat Enterprise Linux Desktop+4 | 19/6/2018 | 17/6/2026 | python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service. | |
| Modificada | Alta (7.5) | 5.0% | — | PythonFedoraproject FedoraCanonical Ubuntu LinuxRedhat Ansible Tower+4 | 18/6/2018 | 17/6/2026 | python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service. | |
| Modificada | Media (4.7) | 0.89% | — | Gnupg LibgcryptCanonical Ubuntu LinuxDebian LinuxRedhat Ansible Tower+4 | 13/6/2018 | 17/6/2026 | Libgcrypt before 1.7.10 and 1.8.x before 1.8.3 allows a memory-cache side-channel attack on ECDSA signatures that can be mitigated through the use of blinding during the signing process in the _gcry_ecc_ecdsa_sign function in cipher/ecc-ecdsa.c, aka the Return Of the Hidden Number Problem or ROHNP. To discover an… | |
| Modificada | Media (5.5) | 1.9% | — | Freedesktop PopplerCanonical Ubuntu LinuxRedhat Ansible TowerRedhat Enterprise Linux Desktop+3 | 10/5/2018 | 17/6/2026 | The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops. | |
| Modificada | Media (6.5) | 2.4% | — | Freedesktop PopplerCanonical Ubuntu LinuxDebian LinuxRedhat Ansible Tower+3 | 6/5/2018 | 17/6/2026 | There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected. | |
| Modificada | Media (6.5) | 2.2% | — | Gnome LibgxpsRedhat Ansible TowerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 6/5/2018 | 17/6/2026 | There is a stack-based buffer over-read in calling GLib in the function gxps_images_guess_content_type of gxps-images.c in libgxps through 0.3.0 because it does not reject negative return values from a g_input_stream_read call. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Media (6.5) | 2.2% | — | Gnome LibgxpsRedhat Ansible TowerRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 4/5/2018 | 17/6/2026 | There is a heap-based buffer over-read in the function ft_font_face_hash of gxps-fonts.c in libgxps through 0.3.0. A crafted input will lead to a remote denial of service attack. | |
| Modificada | Alta (8.8) | 2.5% | — | Redhat Ansible TowerRedhat Cloudforms | 2/5/2018 | 17/6/2026 | Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server. | |
| Modificada | Alta (7.2) | 2.0% | — | Redhat Ansible TowerRedhat Cloudforms | 2/5/2018 | 17/6/2026 | Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the… | |
| Modificada | Media (5) | 8.5% | 💥 Exploit | Ansible Tower | 4/2/2015 | 17/6/2026 | Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/. | |
| Modificada | Media (6.5) | 6.1% | 💥 Exploit | Ansible Tower | 4/2/2015 | 17/6/2026 | Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account. | |
| Modificada | Media (4.3) | 5.2% | 💥 Exploit | Ansible Tower | 27/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Ansible Tower (aka Ansible UI) before 2.0.5 allow remote attackers to inject arbitrary web script or HTML via the (1) order_by parameter to credentials/, (2) inventories/, (3) projects/, or (4) users/3/permissions/ in api/v1/ or the (5) next_run parameter to… | |
| Modificada | Media (5.4) | 0.27% | — | Mobage Tiny Tower | 9/9/2014 | 17/6/2026 | The Tiny Tower (aka com.mobage.ww.a560.tinytower_android) application 1.7.0.8 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Ember-entertainment Towers N' Trolls | 9/9/2014 | 17/6/2026 | The Towers N' Trolls (aka project.android.ftdjni) application 1.6.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4) | 1.1% | — | Boombatower Subuser | 2/11/2012 | 16/6/2026 | The Subuser module before 6.x-1.8 for Drupal does not properly check "switch subuser" permissions, which allows remote authenticated parent users to change their role by switching to a subuser they created. | |
| Modificada | Media (6.8) | 0.64% | — | Boombatower Subuser | 2/11/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Subuser module before 6.x-1.8 for Drupal allows remote attackers to hijack the authentication of arbitrary users for requests that switch the user to a subuser via unspecified vectors. | |
| Modificada | Alta (10) | 1.6% | — | Watchtower | 2/3/2007 | 16/6/2026 | Unspecified vulnerability in Watchtower (WT) before 0.12 has unknown impact and attack vectors, related to "unauthorized accounts." | |
| Modificada | Alta (7.5) | 1.6% | — | Towerblog | 10/4/2005 | 16/6/2026 | TowerBlog 0.6 and earlier stores the login data file under the web root, which allows remote attackers to obtain the MD5 checksums of the username and password via a direct request to the _dat/login file. |