Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
28 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.51% | — | QemuDebian LinuxNovell Open Desktop ServerNovell Open Enterprise Server | 30/12/2019 | 16/6/2026 | A flaw was found in the way qemu v1.3.0 and later (virtio-rng) validates addresses when guest accesses the config space of a virtio device. If the virtio device has zero/small sized config space, such as virtio-rng, a privileged guest user could use this flaw to access the matching host's qemu address space and thus… | |
| Modificada | Media (6.1) | 1.0% | — | Microfocus Open Enterprise Server | 2/5/2019 | 17/6/2026 | A DOM based XSS vulnerability has been identified in the Netstorage component of Open Enterprise Server (OES) allowing a remote attacker to execute javascript in the victims browser by tricking the victim into clicking on a specially crafted link. This affects OES versions OES2015SP1, OES2018, and OES2018SP1. Older… | |
| Modificada | Alta (7.5) | 3.2% | — | Novell Open Enterprise Server | 23/1/2017 | 17/6/2026 | Remote Manager in Open Enterprise Server (OES) allows unauthenticated remote attackers to read any arbitrary file, via a specially crafted URL, that allows complete directory traversal and total information disclosure. This vulnerability is present on all versions of OES for linux, it applies to OES2015 SP1 before… | |
| Modificada | Crítica (9.1) | 1.6% | — | Novell Open Enterprise Server 11Novell Open Enterprise Server 2015 | 15/11/2016 | 17/6/2026 | Vulnerability in Novell Open Enterprise Server (OES2015 SP1 before Scheduled Maintenance Update 10992, OES2015 before Scheduled Maintenance Update 10990, OES11 SP3 before Scheduled Maintenance Update 10991, OES11 SP2 before Scheduled Maintenance Update 10989) might allow authenticated remote attackers to perform… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | GNU BashArista EOSOracle LinuxQnap QTS+70 | 25/9/2014 | 17/6/2026 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature… | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | GNU BashArista EOSOracle LinuxQnap QTS+70 | 24/9/2014 | 17/6/2026 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the… | |
| Modificada | Alta (10) | 2.2% | — | Novell Open Enterprise Server | 17/8/2014 | 17/6/2026 | Unspecified vulnerability in Novell Open Enterprise Server (OES) 11 SP1 before Scheduled Maintenance Update 9415 and 11 SP2 before Scheduled Maintenance Update 9413 for Linux has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Novell Open Enterprise Server | 18/6/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 2.5% | — | Novell Open Enterprise Server | 18/6/2014 | 17/6/2026 | Directory traversal vulnerability in iPrint in Novell Open Enterprise Server (OES) 11 SP1 before Maintenance Update 9151 on Linux has unspecified impact and remote attack vectors. | |
| Modificada | Baja (2.6) | 0.34% | — | Novell Open Enterprise Server | 8/5/2014 | 17/6/2026 | /opt/novell/ncl/bin/nwrights in Novell Client for Linux in Novell Open Enterprise Server (OES) 11 Linux SP2 does not properly manage a certain array, which allows local users to obtain the S permission in opportunistic circumstances by leveraging the granting of the F permission by an administrator. | |
| Modificada | Media (4.3) | 1.6% | — | Novell Open Enterprise Server | 1/12/2013 | 16/6/2026 | The HTTPSTK service in the novell-nrm package before 2.0.2-297.305.302.3 in Novell Open Enterprise Server 2 (OES 2) Linux, and OES 11 Linux Gold and SP1, does not make the intended SSL_free and SSL_shutdown calls for the close of a TCP connection, which allows remote attackers to cause a denial of service (service… | |
| Modificada | Alta (7.5) | 3.0% | — | Novell Open Enterprise Server | 2/2/2012 | 16/6/2026 | Buffer overflow in Novell iPrint Server in Novell Open Enterprise Server 2 (OES2) through SP3 on Linux allows remote attackers to execute arbitrary code via a crafted attributes-natural-language field. | |
| Modificada | Alta (7.5) | 4.8% | — | Novell Iprint Open Enterprise Server 2 | 30/11/2011 | 16/6/2026 | Stack-based buffer overflow in the GetDriverSettings function in nipplib.dll in the iPrint client in Novell Open Enterprise Server 2 (aka OES2) SP3 allows remote attackers to execute arbitrary code via a long (1) hostname or (2) port field. | |
| Modificada | Alta (7.5) | 15% | — | Novell Iprint Open Enterprise Server | 19/2/2011 | 16/6/2026 | Multiple stack-based buffer overflows in opt/novell/iprint/bin/ipsmd in Novell iPrint for Linux Open Enterprise Server 2 SP2 and SP3 allow remote attackers to execute arbitrary code via unspecified LPR opcodes. | |
| Modificada | Alta (7.8) | 0.49% | — | Christophe.varoqui Multipath-toolsFedoraproject FedoraDebian LinuxAvaya Intuity Audix LX+7 | 30/3/2009 | 16/6/2026 | The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly other operating systems, uses world-writable permissions for the socket file (aka /var/run/multipathd.sock), which allows local users to send… | |
| Modificada | Media (4.3) | 2.2% | — | Novell Open Enterprise Server | 17/2/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterprise Server 1.x allow remote attackers to inject arbitrary web script or HTML via (1) the siteloc parameter in a displayaddsite action, the site parameter in a (2) generalproperties or (3)… | |
| Modificada | Alta (9.3) | 3.6% | — | Mozilla FirefoxMozilla SeamonkeyMozilla ThunderbirdDebian Linux+9 | 13/11/2008 | 16/6/2026 | nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized,… | |
| Modificada | Alta (9.3) | 4.3% | — | X.org X ServerCanonical Ubuntu LinuxDebian LinuxApple MAC OS X+7 | 18/1/2008 | 16/6/2026 | The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990. | |
| Modificada | Media (4.4) | 0.33% | — | Suse LinuxSuse Linux Openexchange ServerSuse Linux School ServerSuse Linux Standard Server+3 | 14/5/2007 | 16/6/2026 | xfs_fsr in xfsdump creates a .fsr temporary directory with insecure permissions, which allows local users to read or overwrite arbitrary files on xfs filesystems. | |
| Modificada | Media (4.1) | 0.30% | — | Suse Open Enterprise ServerSuse Linux Enterprise DesktopSuse Linux | 20/12/2006 | 16/6/2026 | Unspecified vulnerability in Linux User Management (novell-lum) on SUSE Linux Enterprise Desktop 10 and Open Enterprise Server 9, under unspecified conditions, allows local users to log in to the console without a password. | |
| Modificada | Media (5) | 3.9% | — | Mono XSPSuse Open Enterprise ServerSuse Linux | 12/9/2006 | 16/6/2026 | Directory traversal vulnerability in the xsp component in mod_mono in Mono/C# web server, as used in SUSE Open-Enterprise-Server 1 and SUSE Linux 9.2 through 10.0, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an HTTP request. | |
| Modificada | Media (5) | 2.3% | — | Novell Open Enterprise ServerNovell Netware | 23/3/2006 | 16/6/2026 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) allows a client to force the server to use weak encryption by stating that a weak cipher is required for client compatibility, which might allow remote attackers to decrypt contents of an SSL protected session. | |
| Modificada | Media (5) | 3.2% | — | Novell Open Enterprise ServerNovell Netware | 23/3/2006 | 16/6/2026 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) sometimes selects a weak cipher instead of an available stronger cipher, which makes it easier for remote attackers to sniff and decrypt an SSL protected session. | |
| Modificada | Media (5) | 1.6% | — | Novell Open Enterprise ServerNovell Netware | 23/3/2006 | 16/6/2026 | The SSL server implementation in NILE.NLM in Novell NetWare 6.5 and Novell Open Enterprise Server (OES) permits encryption with a NULL key, which results in cleartext communication that allows remote attackers to read an SSL protected session by sniffing network traffic. | |
| Modificada | Alta (10) | 7.1% | — | Novell Linux DesktopNovell Open Enterprise Server | 27/2/2006 | 16/6/2026 | Stack-based buffer overflow in the pam_micasa PAM authentication module in CASA on Novell Linux Desktop 9 and Open Enterprise Server 1 allows remote attackers to execute arbitrary code via unspecified vectors. |