Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

656 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)5.5%—Apple MAC OS XApple MAC OS X Server13/5/200916/6/2026
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows remote attackers to execute arbitrary code via a crafted Compact Font Format (CFF) font.
ModificadaMedia (4.3)3.7%—Apple MAC OS XApple MAC OS X Server13/5/200916/6/2026
International Components for Unicode (ICU) 4.0, 3.6, and other 3.x versions, as used in Apple Mac OS X 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, iPhone OS for iPod touch 1.1 through 2.2.1, Fedora 9 and 10, and possibly other operating systems, does not properly handle invalid byte sequences during Unicode…
ModificadaAlta (7.5)2.2%—Apple MAC OS XApple MAC OS X Server13/5/200916/6/2026
iChat in Apple Mac OS X 10.5 before 10.5.7 disables SSL for AOL Instant Messenger (AIM) communication in certain circumstances that are inconsistent with the Require SSL setting, which allows remote attackers to obtain sensitive information by sniffing the network.
ModificadaMedia (4.4)0.36%—Apple MAC OS XApple MAC OS X Server13/5/200916/6/2026
Stack-based buffer overflow in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image.
ModificadaMedia (4.4)0.39%—Apple MAC OS XApple MAC OS X Server13/5/200916/6/2026
Apple Mac OS X 10.4.11 and 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (application crash) by attempting to mount a crafted sparse disk image that triggers memory corruption.
ModificadaMedia (6.8)5.2%—Apple MAC OS XApple MAC OS X Server13/5/200916/6/2026
CoreGraphics in Apple Mac OS X 10.4.11 and 10.5 before 10.5.7, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file that triggers memory corruption.
ModificadaMedia (4.3)1.5%—Apple MAC OS XApple MAC OS X Server13/5/200916/6/2026
CFNetwork in Apple Mac OS X 10.5 before 10.5.7 does not properly parse noncompliant Set-Cookie headers, which allows remote attackers to obtain sensitive information by sniffing the network for "secure cookies" that are sent over unencrypted HTTP connections.
ModificadaAlta (7.2)0.38%—Apple MAC OS XApple MAC OS X Server13/5/200916/6/2026
Array index error in the xnu (Mach) kernel in Apple Mac OS X 10.5 before 10.5.7 allows local users to gain privileges or cause a denial of service (system shutdown) via unspecified vectors related to workqueues.
ModificadaAlta (7.5)8.5%—FreetypeDebian LinuxCanonical Ubuntu LinuxOpensuse+517/4/200916/6/2026
Multiple integer overflows in FreeType 2.3.9 and earlier allow remote attackers to execute arbitrary code via vectors related to large values in certain inputs in (1) smooth/ftsmooth.c, (2) sfnt/ttcmap.c, and (3) cff/cffload.c.
ModificadaAlta (7.2)0.62%💥 ExploitApple MAC OS XApple MAC OS X Server2/4/200916/6/2026
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows local users to cause a denial of service (kernel memory corruption) by simultaneously executing the same HFS_SET_PKG_EXTENSIONS code path in multiple threads, which is problematic because of lack of…
ModificadaMedia (4.9)0.91%💥 ExploitApple MAC OS XApple MAC OS X Server2/4/200916/6/2026
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a denial of service (kernel memory consumption) via a crafted (1) SYS_add_profil or (2) SYS___mac_getfsstat system call.
ModificadaAlta (10)8.4%💥 ExploitApple MAC OS XApple MAC OS X Server2/4/200916/6/2026
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allows remote attackers to cause a denial of service (system crash) via a ZIP NOTIFY (aka ZIPOP_NOTIFY) packet that overwrites a certain ifPort structure member.
ModificadaAlta (7.2)0.98%💥 ExploitApple MAC OS XApple MAC OS X Server2/4/200916/6/2026
XNU 1228.9.59 and earlier on Apple Mac OS X 10.5.6 and earlier does not properly restrict interaction between user space and the HFS IOCTL handler, which allows local users to overwrite kernel memory and gain privileges by attaching an HFS+ disk image and performing certain steps involving HFS_GET_BOOT_INFO fcntl…
ModificadaMedia (5.5)0.30%—Apple MAC OS XApple MAC OS X Server13/2/200916/6/2026
XTerm in Apple Mac OS X 10.4.11 and 10.5.6, when used with luit, creates tty devices with insecure world-writable permissions, which allows local users to write to the Xterm of another user.
ModificadaAlta (9.3)1.7%—Apple MAC OS XApple MAC OS X Server13/2/200916/6/2026
Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.
ModificadaAlta (9.3)2.9%—Apple MAC OS XApple MAC OS X Server13/2/200916/6/2026
Integer overflow in the SMB component in Apple Mac OS X 10.5.6 allows remote SMB servers to cause a denial of service (system shutdown) or execute arbitrary code via a crafted SMB file system that triggers a heap-based buffer overflow.
ModificadaAlta (10)4.2%—Apple MAC OS XApple MAC OS X Server13/2/200916/6/2026
servermgrd (Server Manager) in Apple Mac OS X 10.5.6 does not properly validate authentication credentials, which allows remote attackers to modify the system configuration.
ModificadaAlta (7.8)2.9%—Apple MAC OS XApple MAC OS X Server13/2/200916/6/2026
Unspecified vulnerability in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted resource fork that triggers memory corruption.
ModificadaAlta (7.5)2.1%—Apple MAC OS XApple MAC OS X Server13/2/200916/6/2026
Remote Apple Events in Apple Mac OS X 10.4.11 and 10.5.6 allows remote attackers to cause a denial of service (application termination) or obtain sensitive information via unspecified vectors that trigger an out-of-bounds memory access.
ModificadaAlta (7.8)2.5%—Apple MAC OS XApple MAC OS X Server13/2/200916/6/2026
The Remote Apple Events server in Apple Mac OS X 10.4.11 and 10.5.6 does not properly initialize a buffer, which allows remote attackers to read portions of memory.
ModificadaAlta (7.2)0.45%—Apple MAC OS XApple MAC OS X Server13/2/200916/6/2026
csregprinter in the Printing component in Apple Mac OS X 10.4.11 and 10.5.6 does not properly handle error conditions, which allows local users to execute arbitrary code via unknown vectors that trigger a heap-based buffer overflow.
ModificadaMedia (4.9)0.32%—Apple MAC OS XApple MAC OS X Server13/2/200916/6/2026
Unspecified vulnerability in fseventsd in the FSEvents framework in Apple Mac OS X 10.5.6 allows local users to obtain sensitive information (filesystem activities and directory names) via unknown vectors related to "credential management."
ModificadaBaja (2.1)0.38%—Apple MAC OS XApple MAC OS X Server13/2/200916/6/2026
Folder Manager in Apple Mac OS X 10.5.6 uses insecure default permissions when recreating a Downloads folder after it has been deleted, which allows local users to bypass intended access restrictions and read the Downloads folder.
ModificadaBaja (2.1)0.32%—Apple MAC OS XApple MAC OS X Server13/2/200916/6/2026
dscl in DS Tools in Apple Mac OS X 10.4.11 and 10.5.6 requires that passwords must be provided as command line arguments, which allows local users to gain privileges by listing process information.
ModificadaAlta (10)5.4%—Apple MAC OS XApple MAC OS X Server13/2/200916/6/2026
Heap-based buffer overflow in CoreText in Apple Mac OS X 10.5.6 allows remote attackers to execute arbitrary code via a crafted Unicode string.
Orbitaley — Vulnerabilidades