Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

375 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)3.1%—Openbsd3/5/200116/6/2026
Buffer overflow in IPSEC authentication mechanism for OpenBSD 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed Authentication header (AH) IPv4 option.
ModificadaMedia (4.6)0.29%—Openbsd12/3/200116/6/2026
Vulnerability in OpenBSD 2.6 allows a local user to change interface media configurations.
ModificadaAlta (7.2)0.54%—Openbsd12/3/200116/6/2026
cron in OpenBSD 2.5 allows local users to gain root privileges via an argv[] that is not NULL terminated, which is passed to cron's fake popen function.
ModificadaBaja (2.1)0.27%—Openbsd12/3/200116/6/2026
The i386 trace-trap handling in OpenBSD 2.4 with DDB enabled allows a local user to cause a denial of service.
ModificadaAlta (10)32%💥 ExploitOpenbsd OpensshSSH12/3/200116/6/2026
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.
ModificadaMedia (5)1.2%—Openbsd12/3/200116/6/2026
IP fragment assembly in OpenBSD 2.4 allows a remote attacker to cause a denial of service by sending a large number of fragmented packets.
ModificadaAlta (10)18%💥 ExploitDavid Madore Ftpd-bsdNetbsdOpenbsd12/2/200116/6/2026
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
ModificadaAlta (7.5)1.8%—Openbsd Openssh9/1/200116/6/2026
OpenSSH SSH client before 2.3.0 does not properly disable X11 or agent forwarding, which could allow a malicious SSH server to gain access to the X11 display and sniff X11 events, or gain access to the ssh-agent.
ModificadaMedia (5)1.6%—Openbsd19/12/200016/6/2026
The IPSEC implementation in OpenBSD 2.7 does not properly handle empty AH/ESP packets, which allows remote attackers to cause a denial of service.
ModificadaMedia (5)3.0%💥 ExploitOpenbsd19/12/200023/9/2026
OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.
ModificadaAlta (7.2)1.7%💥 ExploitFreebsdNetbsdOpenbsd19/12/200023/9/2026
Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.
ModificadaAlta (7.2)0.54%—Openbsd19/12/200023/9/2026
Format string vulnerability in OpenBSD su program (and possibly other BSD-based operating systems) allows local attackers to gain root privileges via a malformed shell.
ModificadaAlta (7.2)0.57%—Openbsd19/12/200023/9/2026
Format string vulnerability in OpenBSD yp_passwd program (and possibly other BSD-based operating systems) allows attackers to gain root privileges a malformed name.
ModificadaAlta (7.2)0.54%—NetbsdOpenbsd19/12/200023/9/2026
Format string vulnerabilities in eeprom program in OpenBSD, NetBSD, and possibly other operating systems allows local attackers to gain root privileges.
ModificadaAlta (7.2)1.4%💥 ExploitOpenbsd19/12/200023/9/2026
Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users to gain root privileges via the PWD environmental variable.
ModificadaMedia (5)6.0%💥 ExploitOpenbsd OpensshSSH19/12/200023/9/2026
Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.
ModificadaMedia (4.6)0.36%—Openbsd11/12/200016/6/2026
Format string vulnerability in OpenBSD photurisd allows local users to execute arbitrary commands via a configuration file directory name that contains formatting characters.
ModificadaAlta (10)12%—Openbsd Openssh11/12/200016/6/2026
Format string vulnerabilities in OpenBSD ssh program (and possibly other BSD-based operating systems) allow attackers to gain root privileges.
ModificadaAlta (10)4.6%—OpenbsdRedhat Linux11/12/200016/6/2026
Format string vulnerability in talkd in OpenBSD and possibly other BSD-based OSes allows remote attackers to execute arbitrary commands via a user name that contains format characters.
ModificadaAlta (7.5)3.8%💥 ExploitNetbsdOpenbsdRedhat Linux20/10/200016/6/2026
mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.
ModificadaAlta (7.5)2.3%—NetbsdOpenbsdRedhat Linux20/10/200016/6/2026
Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.
ModificadaMedia (5)59%💥 ExploitOpenbsd FtpdWashington University Wu-ftpd7/7/200016/6/2026
FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.
ModificadaAlta (10)2.6%—Openbsd Openssh8/6/200016/6/2026
OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon.
ModificadaMedia (5.1)0.97%—Openbsd OpensshSSHSsh224/2/200016/6/2026
The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.
ModificadaMedia (4.6)0.35%—Openbsd OpensshSSH11/2/200016/6/2026
The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP.