Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
332 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.4% | — | Privawall Antivirus | 28/3/2012 | 16/6/2026 | The scanner engine in PrivaWall Antivirus 5.6 and earlier does not recognize the Office XML (aka Open Document XML) file format, which allows remote attackers to bypass malware detection via a crafted file embedded in a WordML document. | |
| Modificada | Alta (10) | 2.3% | — | FfmpegMplayerhq MplayerMandriva Corporate ServerMandriva Enterprise Server+1 | 20/5/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (aka CS4.0); and Mandriva Enterprise Server 5 (aka MES5) have unknown impact and attack vectors, related to issues "originally discovered by… | |
| Modificada | Alta (7.2) | 0.38% | — | Mandriva Multi Network FirewallMandriva LinuxMandriva Linux Corporate Server | 16/3/2009 | 16/6/2026 | perl-MDK-Common 1.1.11 and 1.1.24, 1.2.9 through 1.2.14, and possibly other versions, in Mandriva Linux does not properly handle strings when writing them to configuration files, which allows attackers to gain privileges via "special characters" in unspecified vectors. | |
| Modificada | Media (5.1) | 2.0% | 💥 Exploit | Punbb Private Messaging System | 27/2/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to include and execute arbitrary files via a .. (dot dot) in the pun_user[language] parameter to (1) functions_navlinks.php, (2) header_new_messages.php, (3) profile_send.php, and (4)… | |
| Modificada | Alta (10) | 2.3% | — | Privacy-cd Unbuntu Privacy Remix | 9/12/2008 | 16/6/2026 | UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypass intended isolation mechanisms by (1) reading from or (2) writing to these arrays. | |
| Modificada | Media (6.9) | 0.39% | — | Manoj Srivastava Dist | 5/11/2008 | 16/6/2026 | dist 3.5 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/cil#####, (b) /tmp/pdo#####, and (c) /tmp/pdn##### temporary files, related to the (1) patcil and (2) patdiff scripts. | |
| Modificada | Alta (7.5) | 1.4% | — | Trivantis Coursemill Enterprise Learning Management System | 15/12/2007 | 16/6/2026 | SQL injection vulnerability in userlogin.jsp in Trivantis CourseMill Enterprise Learning Management System 4.1 SP4 allows remote attackers to execute arbitrary SQL commands via the user parameter (username field). NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.4) | 0.28% | — | Privacyware Privatefirewall | 19/9/2007 | 16/6/2026 | Privatefirewall 5.0.14.2 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for (1) NtOpenProcess and (2) NtOpenThread. | |
| Modificada | Alta (9.3) | 2.7% | — | Enriva Development Magellan Explorer | 12/9/2007 | 16/6/2026 | Directory traversal vulnerability in Enriva Development Magellan Explorer 3.32 build 2305 and earlier allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder. | |
| Modificada | Media (6.8) | 6.0% | 💥 Exploit | Rebellion Rogue TrooperRival Interactive Prism | 23/8/2007 | 16/6/2026 | Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows remote attackers to execute arbitrary code via a long string in a 0xf007 packet for the challenge B query. | |
| Modificada | Alta (10) | 5.9% | — | GNU Privacy GuardGpg4winRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+5 | 7/12/2006 | 16/6/2026 | A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory. | |
| Modificada | Media (6.8) | 34% | 💥 Exploit | Mcafee AntispywareMcafee Internet Security SuiteMcafee Personal Firewall PlusMcafee Privacy Service+5 | 1/8/2006 | 16/6/2026 | Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands… | |
| Modificada | Alta (7.5) | 62% | 💥 Exploit | Algorithmic Research Privatewire Gateway | 27/6/2006 | 16/6/2026 | Buffer overflow in the Online Registration Facility for Algorithmic Research PrivateWire VPN software up to 3.7 allows remote attackers to execute arbitrary code via a long GET request. | |
| Modificada | Baja (2.1) | 0.47% | — | Virtual Private Server Vserver | 1/5/2006 | 16/6/2026 | Virtual Private Server (Vserver) 2.0.x before 2.0.2-rc18 and 2.1.x before 2.1.1-rc18 provides certain context capabilities (ccaps) that allow local guest users to perform operations that were only intended to be allowed by the guest-root. | |
| Modificada | Media (5) | 2.4% | — | GNU Privacy Guard | 13/3/2006 | 16/6/2026 | gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than… | |
| Modificada | Media (4.6) | 1.4% | 💥 Exploit | GNU Privacy Guard | 15/2/2006 | 16/6/2026 | gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. Note: this also occurs when running the… | |
| Modificada | Baja (2.1) | 0.50% | — | Linux KernelCanonical Ubuntu LinuxDebian LinuxMandriva Linux | 12/10/2005 | 16/6/2026 | The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak that allows attackers to cause a denial of service (memory… | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Privashare | 11/7/2005 | 16/6/2026 | PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message. | |
| Modificada | Alta (7.5) | 5.0% | 💥 Exploit | Akella Privateers Bounty AGE OF Sail II | 20/10/2004 | 16/6/2026 | Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname. | |
| Modificada | Alta (7.5) | 2.8% | — | GNU Privacy Guard | 5/1/2004 | 16/6/2026 | Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows remote attackers or a malicious keyserver to cause a denial of service (crash) and possibly execute arbitrary code during key retrieval. | |
| Modificada | Media (5) | 2.9% | — | GNU Privacy Guard | 15/12/2003 | 16/6/2026 | GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature. | |
| Modificada | Media (5) | 1.3% | — | Privacyware Privatefirewall | 2/7/2003 | 16/6/2026 | Privacyware Privatefirewall 3.0 does not block certain incoming packets when in "Filter Internet Traffic" or Deny Internet Traffic" modes, which allows remote attackers to identify running services via FIN scans or Xmas scans. | |
| Modificada | Alta (10) | 6.6% | — | GNU Privacy Guard | 27/5/2003 | 16/6/2026 | The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path. | |
| Modificada | Alta (7.5) | 2.1% | — | PGP Personal Privacy | 31/12/2002 | 16/6/2026 | PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted. | |
| Modificada | Media (5.5) | 0.25% | — | PGP Personal Privacy | 31/12/2002 | 16/6/2026 | Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" option is not checked, and the user replies to an encrypted message. |