Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
593 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.1% | — | FreebsdNetbsd | 25/7/2012 | 16/6/2026 | The ipalloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD does not properly allocate memory, which makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, related to "integer rounding and overflow" errors. | |
| Modificada | Media (5) | 1.1% | — | FreebsdNetbsd | 25/7/2012 | 16/6/2026 | Integer overflow in the calloc function in libc/stdlib/malloc.c in jemalloc in libc for FreeBSD 6.4 and NetBSD makes it easier for context-dependent attackers to perform memory-related attacks such as buffer overflows via a large size value, which triggers a memory allocation of one byte. | |
| Modificada | Media (4.3) | 5.7% | — | PostgresqlFreebsdPHPDebian Linux | 5/7/2012 | 16/6/2026 | The crypt_des (aka DES-based crypt) function in FreeBSD before 9.0-RELEASE-p2, as used in PHP, PostgreSQL, and other products, does not process the complete cleartext password if this password contains a 0x80 character, which makes it easier for context-dependent attackers to obtain access via an authentication… | |
| Modificada | Alta (7.2) | 40% | 💥 Exploit | FreebsdIllumosJoyent SmartosXEN+7 | 12/6/2012 | 16/6/2026 | The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and other products; Oracle Solaris 11 and earlier; illumos before r13724; Joyent SmartOS before 20120614T184600Z; FreeBSD before 9.0-RELEASE-p3; NetBSD 6.0 Beta and earlier; Microsoft Windows Server 2008… | |
| Modificada | Alta (7.5) | 1.4% | — | Freebsd Libarchive | 13/4/2012 | 16/6/2026 | Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image. | |
| Modificada | Media (6.8) | 4.2% | — | Freebsd Libarchive | 13/4/2012 | 16/6/2026 | Buffer overflow in libarchive through 2.8.5 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted TAR archive. | |
| Modificada | Media (6.8) | 4.2% | — | Freebsd Libarchive | 13/4/2012 | 16/6/2026 | Multiple buffer overflows in the (1) heap_add_entry and (2) relocate_dir functions in archive_read_support_format_iso9660.c in libarchive through 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ISO9660 image. | |
| Modificada | Alta (7.5) | 2.1% | — | Freebsd Libarchive | 13/4/2012 | 16/6/2026 | Buffer overflow in libarchive 3.0 pre-release code allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CAB file, which is not properly handled during the reading of Huffman code data within LZX compressed data. | |
| Modificada | Alta (7.8) | 1.9% | — | FreebsdNetbsd | 2/2/2012 | 16/6/2026 | The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD, NetBSD, and possibly other BSD-based operating systems allows remote attackers to cause a denial of service (CPU consumption and device hang) by sending many Router Advertisement (RA) messages with different source addresses, a similar… | |
| Modificada | Alta (10) | 95% | 💥 Exploit | GNU InetutilsHeimdal Project HeimdalMIT Krb5-applFreebsd+6 | 25/12/2011 | 16/6/2026 | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the… | |
| Modificada | Media (6.9) | 0.89% | 💥 Exploit | Freebsd | 17/11/2011 | 16/6/2026 | Directory traversal vulnerability in openpam_configure.c in OpenPAM before r478 on FreeBSD 8.1 allows local users to load arbitrary DSOs and gain privileges via a .. (dot dot) in the service_name argument to the pam_start function, as demonstrated by a .. in the -c option to kcheckpass. | |
| Modificada | Alta (7.2) | 0.91% | 💥 Exploit | Freebsd | 18/10/2011 | 16/6/2026 | Buffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or possibly gain privileges via a bind system call with a long pathname for a UNIX socket. | |
| Modificada | Alta (9.3) | 8.4% | — | FreetypeLibxfontFreebsdNetbsd+1 | 19/8/2011 | 16/6/2026 | The LZW decompressor in (1) the BufCompressedFill function in fontfile/decompress.c in X.Org libXfont before 1.4.4 and (2) compress/compress.c in 4.3BSD, as used in zopen.c in OpenBSD before 3.8, FreeBSD, NetBSD 4.0.x and 5.0.x before 5.0.3 and 5.1.x before 5.1.1, FreeType 2.1.9, and other products, does not properly… | |
| Modificada | Media (4.3) | 30% | 💥 Exploit | Apache Portable RuntimeApache Http ServerApple MAC OS XFreebsd+6 | 16/5/2011 | 16/6/2026 | Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache Portable Runtime (APR) library before 1.4.3 and the Apache HTTP Server before 2.2.18, and in fnmatch.c in libc in NetBSD 5.1, OpenBSD 4.8, FreeBSD, Apple Mac OS X 10.6, Oracle Solaris 10, and Android, allows context-dependent… | |
| Modificada | Media (4.3) | 1.3% | — | Freebsd | 3/5/2011 | 16/6/2026 | The makemask function in mountd.c in mountd in FreeBSD 7.4 through 8.2 does not properly handle a -network field specifying a CIDR block with a prefix length that is not an integer multiple of 8, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances via an NFS mount… | |
| Modificada | Baja (1.9) | 0.52% | — | Freebsd | 4/3/2011 | 16/6/2026 | crontab.c in crontab in FreeBSD allows local users to determine the existence of arbitrary directories via a command-line argument composed of a directory name concatenated with a directory traversal sequence that leads to the /etc/crontab pathname. | |
| Modificada | Baja (1.9) | 0.44% | — | Apple MAC OS XFreebsd | 4/3/2011 | 16/6/2026 | crontab.c in crontab in FreeBSD and Apple Mac OS X allows local users to (1) determine the existence of arbitrary files via a symlink attack on a /tmp/crontab.XXXXXXXXXX temporary file and (2) perform MD5 checksum comparisons on arbitrary pairs of files via two symlink attacks on /tmp/crontab.XXXXXXXXXX temporary… | |
| Modificada | Media (4) | 7.8% | — | Openbsd OpensshFreebsdNetbsdOpenbsd | 2/3/2011 | 16/6/2026 | The (1) remote_glob function in sftp-glob.c and the (2) process_put function in sftp.c in OpenSSH 5.8 and earlier, as used in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, OpenBSD 4.7, and other products, allow remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that… | |
| Modificada | Media (4) | 1.5% | — | Apple MAC OS XFreebsdNetbsdOpenbsd | 2/3/2011 | 16/6/2026 | The glob implementation in libc in FreeBSD 7.3 and 8.1, NetBSD 5.0.2, and OpenBSD 4.7, and Libsystem in Apple Mac OS X before 10.6.8, allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob… | |
| Modificada | Alta (7.8) | 1.1% | 💥 Exploit | Freebsd | 22/11/2010 | 16/6/2026 | The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previously locked, which allows local users to cause a denial of service (kernel panic), overwrite arbitrary memory locations, and possibly execute arbitrary code via vectors related to opening a file on a… | |
| Modificada | Media (4.9) | 0.30% | — | NetbsdApple MAC OS XFreebsd | 29/9/2010 | 16/6/2026 | Multiple integer signedness errors in smb_subr.c in the netsmb module in the kernel in NetBSD 5.0.2 and earlier, FreeBSD, and Apple Mac OS X allow local users to cause a denial of service (panic) via a negative size value in a /dev/nsmb ioctl operation, as demonstrated by a (1) SMBIOC_LOOKUP or (2) SMBIOC_OPENSESSION… | |
| Modificada | Baja (1.2) | 0.27% | — | FreebsdNetbsd | 20/8/2010 | 16/6/2026 | The Coda filesystem kernel module, as used in NetBSD and FreeBSD, when Coda is loaded and Venus is running with /coda mounted, allows local users to read sensitive heap memory via a large out_size value in a ViceIoctl struct to a Coda ioctl, which triggers a buffer over-read. | |
| Modificada | Alta (7.2) | 0.70% | 💥 Exploit | Freebsd | 13/7/2010 | 16/6/2026 | FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, which allows local users to cause a denial of service (system file corruption) and gain privileges via the sendfile system call. | |
| Modificada | Baja (3.3) | 0.32% | — | Freebsd | 28/5/2010 | 16/6/2026 | jail.c in jail in FreeBSD 8.0 and 8.1-PRERELEASE, when the "-l -U root" options are omitted, does not properly restrict access to the current working directory, which might allow local users to read, modify, or create arbitrary files via standard filesystem operations. | |
| Modificada | Media (6.9) | 0.87% | 💥 Exploit | Freebsd | 28/5/2010 | 16/6/2026 | sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is enabled, does not validate the length of a certain fhsize parameter, which allows local users to gain privileges via a crafted mount request. |