Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.0%—Suse Studio OnsiteSusestudio-ui-server27/1/202017/6/2026
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in susestudio-ui-server of SUSE Studio onsite allows remote attackers with admin privileges in Studio to alter SQL statements, allowing for extraction and modification of data. This issue affects: SUSE Studio onsite…
ModificadaMedia (5.9)0.44%—Suse Studio OnsiteSusestudio-ui-server27/1/202017/6/2026
A Improper Certificate Validation vulnerability in susestudio-common of SUSE Studio onsite allows remote attackers to MITM connections to the repositories, which allows the modification of packages received over these connections. This issue affects: SUSE Studio onsite susestudio-common version 1.3.17-56.6.3 and prior…
ModificadaAlta (8.8)1.3%—Suse Studio OnsiteSuse Studio Onsite Appliance7/6/201816/6/2026
A vulnerability in the listing of available software of SUSE Studio Onsite, SUSE Studio Onsite 1.1 Appliance allows authenticated users to execute arbitrary SQL statements via SQL injection. Affected releases are SUSE Studio Onsite: versions prior to 1.0.3-0.18.1, SUSE Studio Onsite 1.1 Appliance: versions prior to…
ModificadaCrítica (9.8)4.6%—Opensuse Project Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+620/3/201717/6/2026
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
ModificadaCrítica (9.8)4.9%—Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+720/3/201717/6/2026
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
ModificadaMedia (5.5)1.9%—Suse Studio OnsiteOpensuse LeapOpensuseOpensuse Project Leap+720/3/201717/6/2026
The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
ModificadaMedia (5.5)2.1%—Suse Studio OnsiteOpensuseOpensuse Project LeapOpensuse Project Suse Linux Enterprise Debuginfo+620/3/201717/6/2026
The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
ModificadaMedia (5.5)1.9%—GraphicsmagickDebian LinuxSuse Linux Enterprise DebuginfoSuse Studio Onsite+33/2/201717/6/2026
GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath function in magick/render.c.
ModificadaMedia (5.5)2.0%—GraphicsmagickDebian LinuxSuse Linux Enterprise DebuginfoSuse Studio Onsite+33/2/201717/6/2026
Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c.
ModificadaMedia (5.5)1.5%—GraphicsmagickSuse Linux Enterprise DebuginfoSuse Studio OnsiteSuse Linux Enterprise Software Development KIT+113/7/201617/6/2026
The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted GIF file.
ModificadaCrítica (9.8)50%—GraphicsmagickSuse Linux Enterprise DebuginfoSuse Studio OnsiteSuse Linux Enterprise Software Development KIT+1010/6/201617/6/2026
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
ModificadaCrítica (9.8)13%—Mozilla FirefoxApple MAC OS XSuse Linux Enterprise DebuginfoSuse Studio Onsite+1026/5/201617/6/2026
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
ModificadaMedia (6.8)18%—Google ChromeLibexpat Project LibexpatPythonDebian Linux+923/7/201517/6/2026
Multiple integer overflows in the XML_GetBuffer function in Expat through 2.1.0, as used in Google Chrome before 44.0.2403.89 and other products, allow remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via crafted XML data, a related issue to…
AnalizadaCrítica (9.8)100%⚠ Explotación activaGNU BashArista EOSOracle LinuxQnap QTS+7025/9/201417/6/2026
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature…
AnalizadaCrítica (9.8)100%⚠ Explotación activaGNU BashArista EOSOracle LinuxQnap QTS+7024/9/201417/6/2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the…
ModificadaAlta (7.5)1.9%—Suse KiwiSuse Studio Extension FOR System ZSuse Studio Onsite16/4/201416/6/2026
kiwi before 4.98.05, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in an image name.
ModificadaMedia (4.3)0.94%—Suse Studio Extension FOR System ZSuse Studio Onsite16/4/201416/6/2026
Cross-site scripting (XSS) vulnerability in the overlay files tab in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted application, related to cloning.
ModificadaAlta (7.5)1.5%—Suse KiwiSuse Studio Extension FOR System ZSuse Studio Onsite16/4/201416/6/2026
kiwi before 4.85.1, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands as demonstrated by "double quotes in kiwi_oemtitle of .profile."
ModificadaAlta (7.5)2.6%—Suse KiwiSuse Studio Extension FOR System ZSuse Studio Onsite16/4/201416/6/2026
kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.
ModificadaAlta (10)1.4%—Suse Studio Extension FOR System ZSuse Studio Onsite26/2/201416/6/2026
SUSE Studio Onsite 1.3.x before 1.3.6 and SUSE Studio Extension for System z 1.3 uses "static" secret tokens, which has unspecified impact and vectors.
ModificadaAlta (7.2)0.48%—Novell Suse Lifecycle Management ServerSuse Studio OnsiteSuse Webyast23/12/201316/6/2026
WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.
ModificadaAlta (7.5)68%—F5 NginxSuse Lifecycle Management ServerSuse Studio OnsiteSuse Webyast+123/11/201316/6/2026
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
ModificadaMedia (4.3)2.3%—Novell Suse Linux Enterprise Software Development KITNovell Suse Studio OnsiteNovell Suse Linux Enterprise DebuginfoGraphicsmagick+123/11/201316/6/2026
The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.
ModificadaMedia (6.8)6.0%—F5 NginxFedoraproject FedoraSuse StudioSuse Studio Onsite+18/12/201116/6/2026
Heap-based buffer overflow in compression-pointer processing in core/ngx_resolver.c in nginx before 1.0.10 allows remote resolvers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long response.
ModificadaMedia (4.3)1.2%—Marcus Schafer KiwiNovell Suse Studio Onsite23/8/201116/6/2026
Cross-site scripting (XSS) vulnerability in Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via a crafted archive file list that is used in an overlay file.