Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
593 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.9) | 0.41% | — | Freebsd | 15/2/2008 | 16/6/2026 | The sendfile system call in FreeBSD 5.5 through 7.0 does not check the access flags of the file descriptor used for sending a file, which allows local users to read the contents of write-only files. | |
| Modificada | Media (6.9) | 0.30% | — | Freebsd | 16/1/2008 | 16/6/2026 | The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script. | |
| Modificada | Baja (2.1) | 0.31% | — | Freebsd | 16/1/2008 | 16/6/2026 | The ptsname function in FreeBSD 6.0 through 7.0-PRERELEASE does not properly verify that a certain portion of a device name is associated with a pty of a user who is calling the pt_chown function, which might allow local users to read data from the pty from another user. | |
| Modificada | Baja (2.1) | 0.33% | — | Freebsd | 30/11/2007 | 16/6/2026 | The "internal state tracking" code for the random and urandom devices in FreeBSD 5.5, 6.1 through 6.3, and 7.0 beta 4 allows local users to obtain portions of previously-accessed random values, which could be leveraged to bypass protection mechanisms that rely on secrecy of those values. | |
| Modificada | Crítica (9.8) | 70% | 💥 Exploit | TcpdumpCanonical Ubuntu LinuxDebian LinuxSlackware+3 | 16/7/2007 | 16/6/2026 | Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value. | |
| Modificada | Media (4.3) | 3.4% | — | Freebsd Libarchive | 15/7/2007 | 16/6/2026 | archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (crash) via (1) an end-of-file condition within a tar header that follows a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive, which results in a… | |
| Modificada | Media (4.3) | 3.9% | — | Freebsd Libarchive | 14/7/2007 | 16/6/2026 | archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive. | |
| Modificada | Alta (9.3) | 7.4% | — | Freebsd Libarchive | 14/7/2007 | 16/6/2026 | archive_read_support_format_tar.c in libarchive before 2.2.4 does not properly compute the length of a certain buffer when processing a malformed pax extension header, which allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) PAX or (2) TAR… | |
| Modificada | Baja (2.1) | 0.26% | — | Freebsd | 12/7/2007 | 16/6/2026 | The 4BSD process scheduler in the FreeBSD kernel performs scheduling based on CPU billing gathered from periodic process sampling ticks, which allows local users to cause a denial of service (CPU consumption) by performing voluntary nanosecond sleeps that result in the process not being active during a clock… | |
| Modificada | Baja (2.1) | 0.26% | — | Freebsd | 12/7/2007 | 16/6/2026 | The ULE process scheduler in the FreeBSD kernel gives preference to "interactive" processes that perform voluntary sleeps, which allows local users to cause a denial of service (CPU consumption), as described in "Secretly Monopolizing the CPU Without Superuser Privileges." | |
| Modificada | Media (6.6) | 0.95% | 💥 Exploit | Apple MAC OS XFreebsd | 17/1/2007 | 16/6/2026 | The ufs_lookup function in the Mac OS X 10.4.8 and FreeBSD 6.1 kernels allows local users to cause a denial of service (kernel panic) and possibly corrupt other filesystems by mounting a crafted UNIX File System (UFS) DMG image that contains a corrupted directory entry (struct direct), related to the ufs_dirbad… | |
| Modificada | Alta (7.2) | 1.1% | 💥 Exploit | Apple MAC OS XApple MAC OS X ServerFreebsd | 13/1/2007 | 16/6/2026 | Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679.… | |
| Modificada | Media (6.6) | 0.41% | — | Freebsd | 11/1/2007 | 16/6/2026 | The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack. | |
| Modificada | Media (4.4) | 0.27% | — | FreebsdNetbsdOpenbsd | 8/12/2006 | 16/6/2026 | Integer overflow in banner/banner.c in FreeBSD, NetBSD, and OpenBSD might allow local users to modify memory via a long banner. NOTE: CVE and multiple third parties dispute this issue. Since banner is not setuid, an exploit would not cross privilege boundaries in normal operations. This issue is not a vulnerability | |
| Modificada | Alta (7.8) | 0.35% | — | FreebsdNetbsd | 29/11/2006 | 16/6/2026 | ld.so in FreeBSD, NetBSD, and possibly other BSD distributions does not remove certain harmful environment variables, which allows local users to gain privileges by passing certain environment variables to loading processes. NOTE: this issue has been disputed by a third party, stating that it is the responsibility of… | |
| Modificada | Baja (2.1) | 0.41% | — | DragonflybsdFreebsdMidnightbsdNetbsd+1 | 21/11/2006 | 16/6/2026 | Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to… | |
| Modificada | Media (4.9) | 0.38% | — | Freebsd | 9/11/2006 | 16/6/2026 | Integer overflow in the ffs_rdextattr function in FreeBSD 6.1 allows local users to cause a denial of service (kernel panic) and trigger a heap-based buffer overflow via a crafted UFS filesystem, a different vulnerability than CVE-2006-5679. NOTE: a third party states that this issue does not cross privilege… | |
| Modificada | Media (5) | 1.6% | — | Freebsd | 9/11/2006 | 16/6/2026 | The libarchive library in FreeBSD 6-STABLE after 2006-09-05 and before 2006-11-08 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive that causes libarchive to skip a region past the actual end of the archive, which triggers an infinite loop that attempts to read… | |
| Modificada | Media (4.6) | 1.0% | — | Freebsd | 3/11/2006 | 16/6/2026 | Integer overflow in the ffs_mountfs function in FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly execute arbitrary code via a crafted UFS filesystem that causes invalid or large size parameters to be provided to the kmem_alloc function. NOTE: a third party states that this issue does… | |
| Modificada | Media (4.9) | 0.99% | 💥 Exploit | FreebsdOpenbsd | 26/10/2006 | 16/6/2026 | The kernel in FreeBSD 6.1 and OpenBSD 4.0 allows local users to cause a denial of service via unspecified vectors involving certain ioctl requests to /dev/crypto. | |
| Modificada | Baja (2.1) | 0.66% | 💥 Exploit | Freebsd | 24/10/2006 | 16/6/2026 | ufs_vnops.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by calling the ftruncate function on a file type that is not VREG, VLNK or VDIR, which is not defined in POSIX. | |
| Modificada | Baja (2.1) | 0.67% | 💥 Exploit | Freebsd | 24/10/2006 | 16/6/2026 | p1003_1b.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by setting a scheduler policy, which should only be settable by root. | |
| Modificada | Media (4.9) | 0.81% | 💥 Exploit | Freebsd | 12/10/2006 | 16/6/2026 | Integer signedness error in FreeBSD 6.0-RELEASE allows local users to cause a denial of service (memory corruption and kernel panic) via a PT_LWPINFO ptrace command with a large negative data value that satisfies a signed maximum value check but is used in an unsigned copyout function call. | |
| Modificada | Alta (7.2) | 0.41% | — | Freebsd | 26/9/2006 | 16/6/2026 | Integer overflow vulnerability in the i386_set_ldt call in FreeBSD 5.5, and possibly earlier versions down to 5.2, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2006-4178. | |
| Modificada | Media (4.9) | 0.79% | 💥 Exploit | Freebsd | 26/9/2006 | 16/6/2026 | Integer signedness error in the i386_set_ldt call in FreeBSD 5.5, and possibly earlier versions down to 5.2, allows local users to cause a denial of service (crash) via unspecified arguments that use negative signed integers to cause the bzero function to be called with a large length parameter, a different… |