Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.22% | — | IBM Java SDKSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KITRedhat Satellite+4 | 29/9/2022 | 17/6/2026 | IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, which allows local users to obtain sensitive information by reading a file. | |
| Modificada | Alta (7.8) | 0.58% | — | Samba Cifs-utilsDebian LinuxSuse Caas PlatformSuse Enterprise Storage+15 | 27/4/2022 | 17/6/2026 | In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges. | |
| Modificada | Crítica (9.3) | 0.47% | — | Suse Linux Enterprise High Performance ComputingSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT | 7/8/2020 | 17/6/2026 | A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to… | |
| Modificada | Alta (7.8) | 7.0% | — | ImagemagickSuse Linux Enterprise DesktopSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT | 17/2/2020 | 17/6/2026 | Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than… | |
| Modificada | Baja (3.5) | 0.98% | — | QemuFedoraproject FedoraNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+7 | 31/1/2020 | 17/6/2026 | The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors. | |
| Modificada | Media (6.5) | 3.6% | — | QemuFedoraproject FedoraCanonical Ubuntu LinuxSuse Linux Enterprise Debuginfo+4 | 23/1/2020 | 17/6/2026 | Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. | |
| Modificada | Media (5.3) | 4.3% | — | LibgdPHPCanonical Ubuntu LinuxDebian Linux+9 | 19/6/2019 | 17/6/2026 | When using the gdImageCreateFromXbm() function in the GD Graphics Library (aka LibGD) 2.2.5, as used in the PHP GD extension in PHP versions 7.1.x below 7.1.30, 7.2.x below 7.2.19 and 7.3.x below 7.3.6, it is possible to supply data that will cause the function to use the value of uninitialized variable. This may lead… | |
| Modificada | Alta (7.5) | 5.6% | — | LibtiffOpensuse LeapSuse Linux Enterprise DesktopSuse Linux Enterprise Server+1 | 21/3/2019 | 17/6/2026 | LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue | |
| Modificada | Media (5.3) | 1.7% | — | Suse Linux Enterprise Software Development KITOpensuse Leap | 1/3/2018 | 17/6/2026 | The build package before 20171128 did not check directory names during extraction of build results that allowed untrusted builds to write outside of the target system,allowing escape out of buildroots. | |
| Modificada | Media (5.6) | 94% | — | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Crítica (9.8) | 53% | — | Linux KernelDebian LinuxArista EOSF5 ARX+25 | 3/1/2018 | 17/6/2026 | The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action. | |
| Modificada | Alta (7.5) | 9.1% | — | Fedoraproject FedoraSuse Linux Enterprise DebuginfoOpensuse LeapOpensuse+16 | 21/7/2017 | 17/6/2026 | The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to… | |
| Modificada | Alta (7.8) | 2.7% | — | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+16 | 19/6/2017 | 17/6/2026 | glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these… | |
| Modificada | Crítica (9.8) | 7.8% | — | PHPSuse Linux Enterprise Module FOR WEB ScriptingSuse Linux Enterprise Software Development KIT | 8/6/2017 | 17/6/2026 | /ext/phar/phar_object.c in PHP 7.0.7 and 5.6.x allows remote attackers to execute arbitrary code. NOTE: Introduced as part of an incomplete fix to CVE-2015-6833. | |
| Modificada | Crítica (9.8) | 4.4% | — | Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+3 | 6/6/2017 | 17/6/2026 | game-music-emu before 0.6.1 mishandles unspecified integer values. | |
| Modificada | Media (5.5) | 0.53% | — | Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+3 | 6/6/2017 | 17/6/2026 | game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash). | |
| Modificada | Alta (7.7) | 5.6% | — | QemuCanonical Ubuntu LinuxDebian LinuxSuse Linux Enterprise Debuginfo+6 | 13/4/2017 | 17/6/2026 | Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption). | |
| Modificada | Alta (7.8) | 2.3% | — | Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+5 | 12/4/2017 | 17/6/2026 | game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values. | |
| Modificada | Alta (7.8) | 2.3% | — | Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+5 | 12/4/2017 | 17/6/2026 | game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations. | |
| Modificada | Alta (7.8) | 1.9% | — | Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+5 | 12/4/2017 | 17/6/2026 | Stack-based buffer overflow in game-music-emu before 0.6.1. | |
| Modificada | Alta (7.5) | 1.8% | — | FreeradiusSuse Linux Enterprise ServerSuse Linux Enterprise Software Development KIT | 5/4/2017 | 17/6/2026 | FreeRADIUS 2.2.x before 2.2.8 and 3.0.x before 3.0.9 does not properly check revocation of intermediate CA certificates. | |
| Modificada | Alta (7.5) | 3.3% | — | Clusterlabs PacemakerOpensuse LeapOpensuse Project LeapSuse Linux Enterprise High Availability+3 | 24/3/2017 | 17/6/2026 | Pacemaker before 1.1.15, when using pacemaker remote, might allow remote attackers to cause a denial of service (node disconnection) via an unauthenticated connection. | |
| Modificada | Alta (7.5) | 6.0% | — | Jasper Project JasperFedoraproject FedoraOpensuse LeapSuse Linux Enterprise Desktop+2 | 23/3/2017 | 17/6/2026 | The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.7% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+5 | 20/3/2017 | 17/6/2026 | ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash). | |
| Modificada | Alta (7.5) | 3.6% | — | OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+4 | 20/3/2017 | 17/6/2026 | Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption). |