Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2538▼ 400 respecto a la semana anterior
Críticas / altas1320▲ 39 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 2.4% | — | Fedoraproject FedoraMageiaCanonical Ubuntu LinuxGNU Patch | 25/8/2017 | 17/6/2026 | GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file. | |
| Modificada | Media (6.8) | 3.4% | — | Mageia Project MageiaPython RequestsCanonical Ubuntu Linux | 18/3/2015 | 17/6/2026 | The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect. | |
| Modificada | Media (5) | 3.9% | — | Debian LinuxMageiaWiresharkOpensuse | 8/3/2015 | 17/6/2026 | Integer overflow in the dissect_tnef function in epan/dissectors/packet-tnef.c in the TNEF dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted length field in a packet. | |
| Modificada | Media (5) | 4.6% | — | WiresharkOracle LinuxOracle SolarisOpensuse+2 | 8/3/2015 | 17/6/2026 | Off-by-one error in the pcapng_read function in wiretap/pcapng.c in the pcapng file parser in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via an invalid Interface Statistics Block (ISB) interface ID in a… | |
| Modificada | Media (5) | 4.4% | — | WiresharkMageiaOpensuseDebian Linux+2 | 8/3/2015 | 17/6/2026 | epan/dissectors/packet-wcp.c in the WCP dissector in Wireshark 1.10.x before 1.10.13 and 1.12.x before 1.12.4 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted packet that is improperly handled during… | |
| Modificada | Baja (3.5) | 1.8% | — | MageiaRedhat LibvirtCanonical Ubuntu LinuxRedhat Enterprise Linux Desktop+3 | 29/1/2015 | 17/6/2026 | libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the VIR_DOMAIN_XML_SECURE flag with a crafted (1) snapshot to the virDomainSnapshotGetXMLDesc interface or (2) image to the virDomainSaveImageGetXMLDesc interface. | |
| Modificada | Baja (2.1) | 0.39% | — | MageiaRedhat LibvirtCanonical Ubuntu LinuxOpensuse+4 | 19/12/2014 | 17/6/2026 | The (1) qemuDomainMigratePerform and (2) qemuDomainMigrateFinish2 functions in qemu/qemu_driver.c in libvirt do not unlock the domain when an ACL check fails, which allow local users to cause a denial of service via unspecified vectors. | |
| Modificada | Media (5) | 5.9% | — | File Project FileFreebsdMageiaCanonical Ubuntu Linux | 17/12/2014 | 17/6/2026 | softmagic.c in file before 5.21 does not properly limit recursion, which allows remote attackers to cause a denial of service (CPU consumption or crash) via unspecified vectors. | |
| Modificada | Media (5) | 4.4% | — | File Project FileFreebsdMageiaCanonical Ubuntu Linux | 17/12/2014 | 17/6/2026 | The ELF parser (readelf.c) in file before 5.21 allows remote attackers to cause a denial of service (CPU consumption or crash) via a large number of (1) program or (2) section headers or (3) invalid capabilities. | |
| Modificada | Media (4.3) | 2.4% | — | DokuwikiMageia | 17/12/2014 | 17/6/2026 | The default file type whitelist configuration in conf/mime.conf in the Media Manager in DokuWiki before 2014-09-29b allows remote attackers to execute arbitrary web script or HTML by uploading an SWF file, then accessing it via the media parameter to lib/exe/fetch.php. | |
| Modificada | Alta (7.5) | 5.8% | — | Unrtf Project UnrtfFedoraproject FedoraMageia Project MageiaDebian Linux | 9/12/2014 | 17/6/2026 | UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999". | |
| Modificada | Media (6.8) | 3.5% | — | MageiaDebian LinuxOpensuseOpenvpn+2 | 3/12/2014 | 17/6/2026 | OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet. | |
| Modificada | Media (5) | 9.7% | — | Suse Linux Enterprise DesktopSuse Linux Enterprise ServerMuttDebian Linux+1 | 2/12/2014 | 17/6/2026 | The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers to cause a denial of service (crash) via a header with an empty body, which triggers a heap-based buffer overflow in the mutt_substrdup function. | |
| Modificada | Alta (7.5) | 5.7% | — | MageiaDebian LinuxGnupg LibksbaCanonical Ubuntu Linux+1 | 1/12/2014 | 17/6/2026 | Integer underflow in the ksba_oid_to_str function in Libksba before 1.3.2, as used in GnuPG, allows remote attackers to cause a denial of service (crash) via a crafted OID in a (1) S/MIME message or (2) ECC based OpenPGP data, which triggers a buffer overflow. | |
| Modificada | Media (4.3) | 2.4% | — | Debian LinuxMageia Project MageiaWordpress | 25/11/2014 | 17/6/2026 | wp-login.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to reset passwords by leveraging access to an e-mail account that received a password-reset message. | |
| Modificada | Media (6.8) | 2.6% | — | Mageia Project MageiaWordpressDebian Linux | 25/11/2014 | 17/6/2026 | WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 might allow remote attackers to obtain access to an account idle since 2008 by leveraging an improper PHP dynamic type comparison for an MD5 hash. | |
| Modificada | Baja (2.1) | 0.59% | — | Freedesktop DbusDebian LinuxMageia Project MageiaCanonical Ubuntu Linux | 18/11/2014 | 17/6/2026 | D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1. | |
| Modificada | Media (5) | 1.7% | — | Mageia Project MageiaDokuwiki | 22/10/2014 | 17/6/2026 | DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a user name and password starting with a null (\0) character, which triggers an anonymous bind. | |
| Modificada | Media (5) | 2.5% | — | DokuwikiMageia Project Mageia | 22/10/2014 | 17/6/2026 | DokuWiki before 2014-05-05b, when using Active Directory for LDAP authentication, allows remote attackers to bypass authentication via a password starting with a null (\0) character and a valid user name, which triggers an unauthenticated bind. | |
| Modificada | Media (5) | 2.2% | — | Debian LinuxPython RequestsCanonical Ubuntu LinuxMageia | 15/10/2014 | 17/6/2026 | Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request. | |
| Modificada | Baja (3.4) | 100% | — | Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Desktop SupplementaryRedhat Enterprise Linux Server+16 | 15/10/2014 | 17/6/2026 | The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue. | |
| Modificada | Media (5) | 4.8% | — | Canonical Ubuntu LinuxDebian LinuxDebian Exuberant CtagsMageia | 7/10/2014 | 17/6/2026 | jscript.c in Exuberant Ctags 5.8 allows remote attackers to cause a denial of service (infinite loop and CPU and disk consumption) via a crafted JavaScript file. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | GNU BashArista EOSOracle LinuxQnap QTS+70 | 25/9/2014 | 17/6/2026 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | GNU BashArista EOSOracle LinuxQnap QTS+70 | 24/9/2014 | 17/6/2026 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the… | |
| Modificada | Media (5) | 12% | — | OpensuseCanonical Ubuntu LinuxDebian LinuxLUA+1 | 4/9/2014 | 17/6/2026 | Buffer overflow in the vararg functions in ldo.c in Lua 5.1 through 5.2.x before 5.2.3 allows context-dependent attackers to cause a denial of service (crash) via a small number of arguments to a function with a large number of fixed arguments. |