Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.72% | — | Facebook Fizz | 18/5/2023 | 17/6/2026 | There is a vulnerability in the fizz library prior to v2023.01.30.00 where a CHECK failure can be triggered remotely. This behavior requires the client supported cipher advertisement changing between the original ClientHello and the second ClientHello, crashing the process (impact is limited to denial of service). | |
| Modificada | Alta (7.5) | 2.4% | — | Facebook Fizz | 20/8/2019 | 17/6/2026 | A peer could send empty handshake fragments containing only padding which would be kept in memory until a full handshake was received, resulting in memory exhaustion. This issue affects versions v2019.01.28.00 and above of fizz, until v2019.08.05.00. | |
| Modificada | Alta (7.5) | 2.4% | — | Facebook Fizz | 29/4/2019 | 17/6/2026 | An improperly performed length calculation on a buffer in PlaintextRecordLayer could lead to an infinite loop and denial-of-service based on user input. This issue affected versions of fizz prior to v2019.03.04.00. | |
| Modificada | Crítica (9.8) | 1.5% | — | Fizzday Gorose | 23/2/2019 | 17/6/2026 | GoRose v1.0.4 has SQL Injection when the order_by or group_by parameter can be controlled. | |
| Modificada | Alta (7.5) | 1.00% | — | Fizzmedia Negativekarma Fizzmedia | 30/7/2008 | 16/6/2026 | SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands via the mid parameter. | |
| Modificada | Media (4.3) | 3.7% | — | Fizzle | 26/3/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Fizzle 0.5 extension for Firefox allows remote attackers to inject arbitrary web script or HTML via RSS feeds, which are executed by the chrome: URI handler. |