Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
–

177 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.30%—Opensuse LeapSuse Linux Enterprise High Performance ComputingSuse Linux Enterprise Desktop19/9/202317/6/2026
A Improper Link Resolution Before File Access ('Link Following') vulnerability in SUSE SUSE Linux Enterprise Desktop 15 SP5 postfix, SUSE SUSE Linux Enterprise High Performance Computing 15 SP5 postfix, SUSE openSUSE Leap 15.5 postfix.This issue affects SUSE Linux Enterprise Desktop 15 SP5: before 3.7.3-150500.3.5.1;…
ModificadaAlta (8.8)2.7%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.3%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.3%—Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.4%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+223/3/202017/6/2026
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaMedia (6.5)2.9%—Google ChromeOpensuse Backports SLESuse Linux Enterprise DesktopSuse Linux Enterprise Server+223/3/202017/6/2026
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)3.5%—Google ChromeDebian LinuxFedoraproject FedoraOpensuse Backports SLE+223/3/202017/6/2026
Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaAlta (8.8)2.4%—Google ChromeFedoraproject FedoraDebian LinuxOpensuse Backports SLE+223/3/202017/6/2026
Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
ModificadaBaja (3.5)0.98%—QemuFedoraproject FedoraNovell Suse Linux Enterprise Software Development KITNovell Suse Linux Enterprise Debuginfo+731/1/202017/6/2026
The process_tx_desc function in hw/net/e1000.c in QEMU before 2.4.0.1 does not properly process transmit descriptor data when sending a network packet, which allows attackers to cause a denial of service (infinite loop and guest crash) via unspecified vectors.
ModificadaAlta (8.8)2.9%—Dcraw Project DcrawSuse Linux Enterprise DesktopSuse Linux Enterprise Server29/11/201817/6/2026
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
ModificadaMedia (5.3)0.78%—Suse Linux Enterprise DesktopSuse Linux Enterprise Server8/6/201816/6/2026
The kdump implementation is missing the host key verification in the kdump and mkdumprd OpenSSH integration of kdump prior to version 2012-01-20. This is similar to CVE-2011-3588, but different in that the kdump implementation is specific to SUSE. A remote malicious kdump server could use this flaw to impersonate the…
ModificadaMedia (5.6)94%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+3044/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
ModificadaAlta (7.8)0.38%—Novell Suse Linux Enterprise DesktopNovell Suse Linux Enterprise ServerOpensuse Leap8/9/201717/6/2026
The mkdumprd script called "dracut" in the current working directory "." allows local users to trick the administrator into executing code as root.
ModificadaAlta (7.5)5.3%—NTPDebian LinuxOpensuse Suse Linux Enterprise ServerOpensuse Project Suse Linux Enterprise Desktop+99/8/201717/6/2026
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute…
ModificadaAlta (7.8)2.7%—Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Server AUS+1619/6/201717/6/2026
glibc contains a vulnerability that allows specially crafted LD_LIBRARY_PATH values to manipulate the heap/stack, causing them to alias, potentially resulting in arbitrary code execution. Please note that additional hardening changes have been made to glibc to prevent manipulation of stack and heap memory but these…
ModificadaCrítica (9.8)4.4%—Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+36/6/201717/6/2026
game-music-emu before 0.6.1 mishandles unspecified integer values.
ModificadaMedia (5.5)0.53%—Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+36/6/201717/6/2026
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
ModificadaAlta (7.5)3.7%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+520/3/201717/6/2026
ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
ModificadaAlta (7.5)3.6%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DesktopOpensuse Project Suse Linux Enterprise Server+420/3/201717/6/2026
Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).
ModificadaAlta (7.5)3.6%—OpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise DebuginfoOpensuse Project Suse Linux Enterprise Desktop+520/3/201717/6/2026
The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
ModificadaAlta (7.5)3.7%—Opensuse LeapOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Desktop+620/3/201717/6/2026
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
ModificadaCrítica (9.8)4.6%—Opensuse Project Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+620/3/201717/6/2026
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
ModificadaCrítica (9.8)4.9%—Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+720/3/201717/6/2026
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
ModificadaMedia (5.5)1.9%—Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+720/3/201717/6/2026
The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
ModificadaMedia (5.5)2.1%—Suse Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+620/3/201717/6/2026
The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.