Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
656 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 4.9% | — | Apple MAC OS XApple MAC OS X ServerMicrosoft Windows VistaMicrosoft Windows XP+1 | 12/8/2009 | 16/6/2026 | Unspecified vulnerability in Apple Safari 4 before 4.0.3 allows remote web servers to place an arbitrary web site in the Top Sites view, and possibly conduct phishing attacks, via unknown vectors. | |
| Modificada | Media (6.5) | 1.8% | — | Xmlsoft LibxmlXmlsoft Libxml2Fedoraproject FedoraDebian Linux+15 | 11/8/2009 | 16/6/2026 | Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing… | |
| Modificada | Media (4.9) | 0.40% | — | Apple MAC OS XApple MAC OS X Server | 6/8/2009 | 16/6/2026 | Apple Mac OS X 10.5 before 10.5.8 does not properly share file descriptors over local sockets, which allows local users to cause a denial of service (system crash) by placing file descriptors in messages sent to a socket that has no receiver, related to a "synchronization issue." | |
| Modificada | Alta (10) | 9.5% | — | Apple MAC OS XApple MAC OS X Server | 6/8/2009 | 16/6/2026 | Buffer overflow in the kernel in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (system crash) via a crafted AppleTalk response packet. | |
| Modificada | Alta (7.5) | 2.5% | — | Apple MAC OS XApple MAC OS X Server | 6/8/2009 | 16/6/2026 | MobileMe in Apple Mac OS X 10.5 before 10.5.8 does not properly delete credentials upon signout from the preference pane, which makes it easier for attackers to hijack a MobileMe session via unspecified vectors, related to a "logic issue." | |
| Modificada | Alta (7.5) | 4.2% | — | Apple MAC OS XApple MAC OS X Server | 6/8/2009 | 16/6/2026 | Format string vulnerability in Login Window in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in an application name. | |
| Modificada | Alta (7.8) | 4.3% | — | Apple MAC OS XApple MAC OS X Server | 6/8/2009 | 16/6/2026 | launchd in Apple Mac OS X 10.5 before 10.5.8 allows remote attackers to cause a denial of service (individual service outage) by making many connections to an inetd-based launchd service. | |
| Modificada | Alta (9.3) | 7.9% | — | Apple MAC OS XApple MAC OS X Server | 6/8/2009 | 16/6/2026 | Buffer overflow in ImageIO in Apple Mac OS X 10.5 before 10.5.8, and Safari before 4.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image with crafted EXIF metadata. | |
| Modificada | Media (6.8) | 5.6% | — | Apple MAC OS XApple MAC OS X Server | 6/8/2009 | 16/6/2026 | Stack-based buffer overflow in Image RAW in Apple Mac OS X 10.5 before 10.5.8, and 10.4 before Digital Camera RAW Compatibility Update 2.6, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image. | |
| Modificada | Media (6.8) | 2.7% | — | Apple MAC OS XApple MAC OS X Server | 6/8/2009 | 16/6/2026 | Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari. | |
| Modificada | Alta (9.3) | 8.4% | — | Apple MAC OS XApple MAC OS X Server | 6/8/2009 | 16/6/2026 | Heap-based buffer overflow in ColorSync in Apple Mac OS X 10.4.11 and 10.5 before 10.5.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image containing an embedded ColorSync profile. | |
| Modificada | Media (4.3) | 1.4% | — | Apple MAC OS XApple MAC OS X Server | 6/8/2009 | 16/6/2026 | CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into visiting an arbitrary https web site by leveraging an open redirect vulnerability, a different issue than CVE-2009-2062. | |
| Modificada | Alta (7.2) | 0.36% | — | Apple MAC OS XApple MAC OS X Server | 6/8/2009 | 16/6/2026 | The screen saver in Dock in Apple Mac OS X 10.5 before 10.5.8 does not prevent four-finger Multi-Touch gestures, which allows physically proximate attackers to bypass locking and "manage applications or use Expose" via unspecified vectors. | |
| Modificada | Crítica (9.8) | 3.4% | — | Rubyonrails Ruby ON RailsApple MAC OS XApple MAC OS X Server | 10/7/2009 | 16/6/2026 | The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for… | |
| Modificada | Alta (7.5) | 20% | 💥 Exploit | Apple CupsCanonical Ubuntu LinuxDebian LinuxApple MAC OS X+3 | 9/6/2009 | 16/6/2026 | The ippReadIO function in cups/ipp.c in cupsd in CUPS before 1.3.10 does not properly initialize memory for IPP request packets, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a scheduler request with two consecutive IPP_TAG_UNSUPPORTED tags. | |
| Modificada | Media (6.8) | 3.0% | — | Apple MAC OS XApple MAC OS X Server | 5/6/2009 | 16/6/2026 | Integer overflow in Terminal in Apple Mac OS X 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted size value in a CSI[4 xterm resize escape sequence that triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 4.1% | — | Apple MAC OS XApple MAC OS X Server | 13/5/2009 | 16/6/2026 | The Microsoft Office Spotlight Importer in Spotlight in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not properly validate Microsoft Office files, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a file that triggers memory corruption. | |
| Modificada | Media (6.8) | 4.2% | — | Apple MAC OS XApple MAC OS X Server | 13/5/2009 | 16/6/2026 | Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that HTML pathnames are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files. | |
| Modificada | Media (6.8) | 4.2% | — | Apple MAC OS XApple MAC OS X Server | 13/5/2009 | 16/6/2026 | Help Viewer in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 does not verify that certain Cascading Style Sheets (CSS) are located in a registered help book, which allows remote attackers to execute arbitrary code via a help: URL that triggers invocation of AppleScript files. | |
| Modificada | Media (6.4) | 2.3% | — | Apple MAC OS XApple MAC OS X Server | 13/5/2009 | 16/6/2026 | The OpenSSL::OCSP module for Ruby in Apple Mac OS X 10.5 before 10.5.7 misinterprets an unspecified invalid response as a successful OCSP certificate validation, which might allow remote attackers to spoof certificate authentication via a revoked certificate. | |
| Modificada | Media (6.8) | 4.1% | — | Apple MAC OS XApple MAC OS X Server | 13/5/2009 | 16/6/2026 | QuickDraw Manager in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image that triggers memory corruption. | |
| Modificada | Media (6.8) | 4.7% | — | Apple MAC OS XApple MAC OS X Server | 13/5/2009 | 16/6/2026 | Stack-based buffer overflow in telnet in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long hostname for a telnet server. | |
| Modificada | Media (6.8) | 2.8% | — | Apple MAC OS XApple MAC OS X Server | 13/5/2009 | 16/6/2026 | Heap-based buffer overflow in CFNetwork in Apple Mac OS X 10.5 before 10.5.7 allows remote web servers to execute arbitrary code or cause a denial of service (application crash) via long HTTP headers. | |
| Modificada | Media (4.3) | 3.1% | — | Apple MAC OS XApple MAC OS X Server | 13/5/2009 | 16/6/2026 | Launch Services in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to cause a denial of service (persistent Finder crash) via a crafted Mach-O executable that triggers an out-of-bounds memory read. | |
| Modificada | Media (6.8) | 5.8% | — | Apple MAC OS XApple MAC OS X Server | 13/5/2009 | 16/6/2026 | Integer underflow in CoreGraphics in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers a heap-based buffer overflow. |