Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 7.8% | — | PHPSuse Linux Enterprise Module FOR WEB ScriptingSuse Linux Enterprise Software Development KIT | 8/6/2017 | 17/6/2026 | /ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833. | |
| Modificada | Alta (7.5) | 29% | — | Novell Suse Linux Enterprise Module FOR WEB ScriptingOpensslNodejs Node.js | 26/9/2016 | 17/6/2026 | crypto/x509/x509_vfy.c in OpenSSL 1.0.2i allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) by triggering a CRL operation. | |
| Modificada | Media (5.9) | 42% | — | OpensslHP Icewall Federation AgentHP Icewall McrpHP Icewall SSO+5 | 26/9/2016 | 17/6/2026 | The certificate parser in OpenSSL before 1.0.1u and 1.0.2 before 1.0.2i might allow remote attackers to cause a denial of service (out-of-bounds read) via crafted certificate operations, related to s3_clnt.c and s3_srvr.c. | |
| Modificada | Alta (7.5) | 63% | — | OpensslNodejs Node.jsNovell Suse Linux Enterprise Module FOR WEB Scripting | 26/9/2016 | 17/6/2026 | Multiple memory leaks in t1_lib.c in OpenSSL before 1.0.1u, 1.0.2 before 1.0.2i, and 1.1.0 before 1.1.0a allow remote attackers to cause a denial of service (memory consumption) via large OCSP Status Request extensions. | |
| Modificada | Crítica (9.6) | 4.2% | — | PHPCanonical Ubuntu LinuxOpensuse LeapOpensuse+2 | 22/5/2016 | 17/6/2026 | ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader changes in other threads, which allows remote attackers to conduct XML External Entity (XXE) and XML Entity Expansion (XEE) attacks via a crafted XML document, a related… |