Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

278 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.2%—Apple Quicktime Pictureviewer2/5/200516/6/2026
PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximum depth start value, possibly triggering an integer overflow.
ModificadaBaja (2.6)2.1%💥 ExploitApple Quicktime Pictureviewer2/5/200516/6/2026
Buffer overflow in QuickTime PictureViewer 6.5.1 allows remote attackers to cause a denial of service (application crash) via a JPEG file with crafted Huffman Table (marker DHT) data.
ModificadaMedia (5)1.2%—Apple Quicktime1/3/200516/6/2026
Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memory operation.
ModificadaMedia (5)0.97%—Apple QuicktimeApple MAC OS XApple MAC OS X Server27/1/200516/6/2026
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.
ModificadaAlta (7.5)1.1%—Apple QuicktimeApple MAC OS XApple MAC OS X Server27/1/200516/6/2026
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.
ModificadaMedia (5)1.3%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server10/1/200516/6/2026
Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte.
ModificadaAlta (7.5)1.9%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server3/12/200416/6/2026
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization.
ModificadaBaja (2.1)0.34%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode.
ModificadaMedia (4.6)0.34%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus IMAP allows local users to access mailboxes of other users.
ModificadaAlta (7.5)1.7%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information.
ModificadaBaja (2.1)0.34%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict access to a secure text input field, which allows local users to read keyboard input from other applications within the same window session.
ModificadaBaja (2.1)0.35%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could result in a false sense of security for the user.
ModificadaMedia (5)1.6%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles.
ModificadaAlta (7.5)3.4%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server2/12/200416/6/2026
Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file.
ModificadaMedia (5.1)3.2%—Apple Quicktime7/7/200416/6/2026
Integer overflow in Apple QuickTime (QuickTime.qts) before 6.5.1 allows attackers to execute arbitrary code via a large "number of entries" field in the sample-to-chunk table data for a .mov movie file, which leads to a heap-based buffer overflow.
ModificadaMedia (4.3)1.2%—Apple Darwin Streaming ServerApple Quicktime Streaming Server31/12/200316/6/2026
parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages.
ModificadaAlta (7.5)6.4%💥 ExploitApple QuicktimeAIApple Darwin Streaming ServerAI31/12/200316/6/2026
Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed ID3 tags in MP3 files.
ModificadaMedia (4.3)4.5%💥 ExploitApple Darwin Streaming ServerApple Quicktime Streaming Server31/12/200316/6/2026
Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter.
ModificadaAlta (7.5)9.3%—Apple Quicktime2/4/200316/6/2026
Buffer overflow in Apple QuickTime Player 5.x and 6.0 for Windows allows remote attackers to execute arbitrary code via a long QuickTime URL.
ModificadaAlta (7.5)69%💥 ExploitApple Darwin Streaming ServerApple Quicktime Streaming Server7/3/200316/6/2026
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via shell metacharacters.
ModificadaMedia (5)2.1%—Apple Darwin Streaming ServerApple Quicktime Streaming Server7/3/200316/6/2026
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to obtain the physical path of the server's installation path via a NULL file parameter.
ModificadaAlta (7.5)2.3%—Apple Darwin Streaming ServerApple Quicktime Streaming Server7/3/200316/6/2026
Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute certain code via a request to port 7070 with the script in an argument to the rtsp DESCRIBE method, which is inserted into a log file and executed when the log is viewed using a browser.
ModificadaAlta (7.5)3.1%—Apple Quicktime Darwin MP3 Broadcaster7/3/200316/6/2026
Buffer overflow in the MP3 broadcasting module of Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to execute arbitrary code via a long filename.
ModificadaMedia (5)1.4%—Apple Darwin Streaming ServerApple Quicktime Streaming Server7/3/200316/6/2026
parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to list arbitrary directories.
ModificadaMedia (4.3)1.8%—Apple Darwin Streaming ServerApple Quicktime Streaming Server7/3/200316/6/2026
Cross-site scripting (XSS) vulnerability in parse_xml.cgi in Apple Darwin Streaming Administration Server 4.1.2 and QuickTime Streaming Server 4.1.1 allows remote attackers to insert arbitrary script via the filename parameter, which is inserted into an error message.