Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.9% | — | Redhat Icedtea6 | 31/10/2019 | 16/6/2026 | IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended JNLP Services. | |
| Modificada | Crítica (9.1) | 2.0% | — | Redhat Icedtea6 | 31/10/2019 | 16/6/2026 | IcedTea6 before 1.7.4 does not properly check property access, which allows unsigned apps to read and write arbitrary files. | |
| Modificada | Media (6.8) | 2.4% | — | Redhat Icedtea-webRedhat Icedtea6 | 14/5/2014 | 16/6/2026 | The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to trick victims into granting access to local files by modifying the content of the Java Web Start Security Warning dialog box to… | |
| Modificada | Media (5) | 2.5% | — | Redhat Icedtea-webRedhat Icedtea6 | 14/5/2014 | 16/6/2026 | The Java Network Launching Protocol (JNLP) implementation in IcedTea6 1.9.x before 1.9.9 and before 1.8.9, and IcedTea-Web 1.1.x before 1.1.1 and before 1.0.4, allows remote attackers to obtain the username and full path of the home and cache directories by accessing properties of the ClassLoader. | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa | Oracle JDKOracle JRERedhat Icedtea6Redhat Enterprise Linux Desktop+4 | 16/6/2012 | 6/8/2026 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Hotspot. | |
| Modificada | Baja (2.1) | 0.48% | — | Oracle JREOracle JDKRedhat Icedtea6Redhat Satellite With Embedded Oracle+13 | 16/6/2012 | 16/6/2026 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 update 32 and earlier, 5 update 35 and earlier, and 1.4.2_37 and earlier allows local users to affect confidentiality via unknown vectors related to printing on Solaris or Linux. |