Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

332 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.4%—Privawall Antivirus28/3/201216/6/2026
The scanner engine in PrivaWall Antivirus 5.6 and earlier does not recognize the Office XML (aka Open Document XML) file format, which allows remote attackers to bypass malware detection via a crafted file embedded in a WordML document.
ModificadaAlta (10)2.3%—FfmpegMplayerhq MplayerMandriva Corporate ServerMandriva Enterprise Server+120/5/201116/6/2026
Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (aka CS4.0); and Mandriva Enterprise Server 5 (aka MES5) have unknown impact and attack vectors, related to issues "originally discovered by…
ModificadaAlta (7.2)0.38%—Mandriva Multi Network FirewallMandriva LinuxMandriva Linux Corporate Server16/3/200916/6/2026
perl-MDK-Common 1.1.11 and 1.1.24, 1.2.9 through 1.2.14, and possibly other versions, in Mandriva Linux does not properly handle strings when writing them to configuration files, which allows attackers to gain privileges via "special characters" in unspecified vectors.
ModificadaMedia (5.1)2.0%💥 ExploitPunbb Private Messaging System27/2/200916/6/2026
Multiple directory traversal vulnerabilities in Private Messaging System (PMS) 1.2.3 and earlier for PunBB allow remote attackers to include and execute arbitrary files via a .. (dot dot) in the pun_user[language] parameter to (1) functions_navlinks.php, (2) header_new_messages.php, (3) profile_send.php, and (4)…
ModificadaAlta (10)2.3%—Privacy-cd Unbuntu Privacy Remix9/12/200816/6/2026
UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypass intended isolation mechanisms by (1) reading from or (2) writing to these arrays.
ModificadaMedia (6.9)0.39%—Manoj Srivastava Dist5/11/200816/6/2026
dist 3.5 allows local users to overwrite arbitrary files via a symlink attack on (a) /tmp/cil#####, (b) /tmp/pdo#####, and (c) /tmp/pdn##### temporary files, related to the (1) patcil and (2) patdiff scripts.
ModificadaAlta (7.5)1.4%—Trivantis Coursemill Enterprise Learning Management System15/12/200716/6/2026
SQL injection vulnerability in userlogin.jsp in Trivantis CourseMill Enterprise Learning Management System 4.1 SP4 allows remote attackers to execute arbitrary SQL commands via the user parameter (username field). NOTE: some of these details are obtained from third party information.
ModificadaMedia (4.4)0.28%—Privacyware Privatefirewall19/9/200716/6/2026
Privatefirewall 5.0.14.2 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via kernel SSDT hooks for (1) NtOpenProcess and (2) NtOpenThread.
ModificadaAlta (9.3)2.7%—Enriva Development Magellan Explorer12/9/200716/6/2026
Directory traversal vulnerability in Enriva Development Magellan Explorer 3.32 build 2305 and earlier allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a filename. NOTE: this can be leveraged for code execution by writing to a Startup folder.
ModificadaMedia (6.8)6.0%💥 ExploitRebellion Rogue TrooperRival Interactive Prism23/8/200716/6/2026
Stack-based buffer overflow in Rebellion Asura engine, as used for the server in Rogue Trooper 1.0 and earlier and Prism 1.1.1.0 and earlier, allows remote attackers to execute arbitrary code via a long string in a 0xf007 packet for the challenge B query.
ModificadaAlta (10)5.9%—GNU Privacy GuardGpg4winRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+57/12/200616/6/2026
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.
ModificadaMedia (6.8)34%💥 ExploitMcafee AntispywareMcafee Internet Security SuiteMcafee Personal Firewall PlusMcafee Privacy Service+51/8/200616/6/2026
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands…
ModificadaAlta (7.5)62%💥 ExploitAlgorithmic Research Privatewire Gateway27/6/200616/6/2026
Buffer overflow in the Online Registration Facility for Algorithmic Research PrivateWire VPN software up to 3.7 allows remote attackers to execute arbitrary code via a long GET request.
ModificadaBaja (2.1)0.47%—Virtual Private Server Vserver1/5/200616/6/2026
Virtual Private Server (Vserver) 2.0.x before 2.0.2-rc18 and 2.1.x before 2.1.1-rc18 provides certain context capabilities (ccaps) that allow local guest users to perform operations that were only intended to be allowed by the guest-root.
ModificadaMedia (5)2.4%—GNU Privacy Guard13/3/200616/6/2026
gpg in GnuPG before 1.4.2.2 does not properly verify non-detached signatures, which allows attackers to inject unsigned data via a data packet that is not associated with a control packet, which causes the check for concatenated signatures to report that the signature is valid, a different vulnerability than…
ModificadaMedia (4.6)1.4%💥 ExploitGNU Privacy Guard15/2/200616/6/2026
gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. Note: this also occurs when running the…
ModificadaBaja (2.1)0.50%—Linux KernelCanonical Ubuntu LinuxDebian LinuxMandriva Linux12/10/200516/6/2026
The audit system in Linux kernel 2.6.6, and other versions before 2.6.13.4, when CONFIG_AUDITSYSCALL is enabled, uses an incorrect function to free names_cache memory, which prevents the memory from being tracked by AUDITSYSCALL code and leads to a memory leak that allows attackers to cause a denial of service (memory…
ModificadaMedia (5)3.1%💥 ExploitPrivashare11/7/200516/6/2026
PrivaShare 1.1b allows remote attackers to cause a denial of service (crash) via a malformed message.
ModificadaAlta (7.5)5.0%💥 ExploitAkella Privateers Bounty AGE OF Sail II20/10/200416/6/2026
Buffer overflow in Privateer's Bounty: Age of Sail II allows remote attackers to execute arbitrary code via a long nickname.
ModificadaAlta (7.5)2.8%—GNU Privacy Guard5/1/200416/6/2026
Format string vulnerability in gpgkeys_hkp (experimental HKP interface) for the GnuPG (gpg) client 1.2.3 and earlier, and 1.3.3 and earlier, allows remote attackers or a malicious keyserver to cause a denial of service (crash) and possibly execute arbitrary code during key retrieval.
ModificadaMedia (5)2.9%—GNU Privacy Guard15/12/200316/6/2026
GnuPG (GPG) 1.0.2, and other versions up to 1.2.3, creates ElGamal type 20 (sign+encrypt) keys using the same key component for encryption as for signing, which allows attackers to determine the private key from a signature.
ModificadaMedia (5)1.3%—Privacyware Privatefirewall2/7/200316/6/2026
Privacyware Privatefirewall 3.0 does not block certain incoming packets when in "Filter Internet Traffic" or Deny Internet Traffic" modes, which allows remote attackers to identify running services via FIN scans or Xmas scans.
ModificadaAlta (10)6.6%—GNU Privacy Guard27/5/200316/6/2026
The key validation code in GnuPG before 1.2.2 does not properly determine the validity of keys with multiple user IDs and assigns the greatest validity of the most valid user ID, which prevents GnuPG from warning the encrypting user when a user ID does not have a trusted path.
ModificadaAlta (7.5)2.1%—PGP Personal Privacy31/12/200216/6/2026
PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.
ModificadaMedia (5.5)0.25%—PGP Personal Privacy31/12/200216/6/2026
Microsoft Outlook plug-in PGP version 7.0, 7.0.3, and 7.0.4 silently saves a decrypted copy of a message to hard disk when "Automatically decrypt/verify when opening messages" option is checked, "Always use Secure Viewer when decrypting" option is not checked, and the user replies to an encrypted message.
Orbitaley — Vulnerabilidades