Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 4.8% | 💥 Exploit | Nasa Ames Research Center Bigview | 5/6/2008 | 16/6/2026 | Stack-based buffer overflow in the getline function in Ppm/ppm.C in NASA Ames Research Center BigView 1.8 allows user-assisted remote attackers to execute arbitrary code via a crafted PNM file. | |
| Modificada | Alta (7.5) | 0.96% | 💥 Exploit | Acgv.free Acgv News | 22/5/2008 | 16/6/2026 | SQL injection vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Acgv.free Acgv News | 22/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in glossaire.php in ACGV News 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (10) | 7.4% | — | Microsoft Sysinternals Debugview | 8/11/2007 | 16/6/2026 | Dbgv.sys in Microsoft Sysinternals DebugView before 4.72 provides an unspecified mechanism for copying data into kernel memory, which allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (4.3) | 1.3% | — | GNU GnatsYngve Svendsen Gnatsweb | 22/5/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gnatsweb.pl in Gnatsweb 4.00 and Gnats 4.1.99 allows remote attackers to inject arbitrary web script or HTML via the database parameter. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Mentiss Acgv Acgvannu | 9/5/2007 | 16/6/2026 | Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the rubrik parameter. | |
| Modificada | Media (6.4) | 2.9% | 💥 Exploit | Mentiss Acgv Acgvannu | 3/2/2007 | 16/6/2026 | index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modified id parameter, related to templates/modif.html. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.8) | 1.0% | — | Mentiss Acgv Acgvannu | 3/2/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in ACGVannu 1.3 and earlier allow remote attackers to execute arbitrary SQL commands via the id_mod parameter to templates/modif.html, and other unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 2.9% | 💥 Exploit | Acgvclick | 30/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. | |
| Modificada | Media (5.1) | 15% | 💥 Exploit | GNU GV | 11/11/2006 | 16/6/2026 | Stack-based buffer overflow in the ps_gettext function in ps.c for GNU gv 3.6.2, and possibly earlier versions, allows user-assisted attackers to execute arbitrary code via a PostScript (PS) file with certain headers that contain long comments, as demonstrated using the (1) DocumentMedia, (2) DocumentPaperSizes, and… | |
| Modificada | Media (5.1) | 3.1% | 💥 Exploit | Acgv News | 8/9/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter in (1) header.php or (2) news.php. NOTE: portions of these details are obtained from third party information. | |
| Modificada | Media (5.1) | 3.1% | 💥 Exploit | Acgv News | 8/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter. | |
| Modificada | Alta (10) | 11% | 💥 Exploit | Azerbaijan Development Group Azdgvote | 13/4/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Azerbaijan Design & Development Group (AZDG) AzDGVote allow remote attackers to execute arbitrary PHP code via a URL in the int_path parameter in (1) vote.php, (2) view.php, (3) admin.php, and (4) admin/index.php. | |
| Modificada | Alta (7.5) | 4.2% | — | Xzgv | 11/4/2006 | 16/6/2026 | Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required. | |
| Modificada | Alta (7.2) | 1.4% | 💥 Exploit | Frank Mcingvale Luxman | 2/5/2005 | 16/6/2026 | Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute arbitrary code via a long -f command line argument. | |
| Modificada | Alta (10) | 9.4% | 💥 Exploit | Xzgv Image ViewerZGV Image ViewerDebian Linux | 10/1/2005 | 16/6/2026 | Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be… | |
| Modificada | Alta (10) | 5.1% | — | Xzgv Image ViewerZGV Image ViewerDebian Linux | 10/1/2005 | 16/6/2026 | Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that… | |
| Modificada | Baja (2.6) | 1.4% | — | ZGV Image Viewer | 31/12/2004 | 16/6/2026 | zgv 5.5.3 allows remote attackers to cause a denial of service (application crash via segmentation fault) via crafted multiple-image (animated) GIF images. | |
| Modificada | Alta (7.5) | 5.4% | 💥 Exploit | GV | 16/8/2004 | 16/6/2026 | Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary code via a Postscript file with a long (1) BoundingBox, (2) comment, (3) Orientation, (4) PageOrder, or (5) Pages value. | |
| Modificada | Alta (7.5) | 2.4% | — | GhostviewGV | 17/11/2003 | 16/6/2026 | gv 3.5.8, and possibly earlier versions, allows remote attackers to execute arbitrary commands via shell metacharacters in the filename for (1) a PDF file or (2) a gzip file. | |
| Modificada | Alta (7.2) | 0.46% | — | Frank Mcingvale Luxman | 12/11/2002 | 16/6/2026 | Maped in LuxMan 0.41 uses the user-provided search path to find and execute the gzip program, which allows local users to modify /dev/mem and gain privileges via a modified PATH environment variable that points to a Trojan horse gzip program. | |
| Modificada | Media (4.6) | 2.0% | 💥 Exploit | GGVGhostviewGV | 10/10/2002 | 16/6/2026 | Buffer overflow in (1) gv 3.5.8 and earlier, (2) gvv 1.0.2 and earlier, (3) ggv 1.99.90 and earlier, (4) gnome-gv, and (5) kghostview in kdegraphics 2.2.2 and earlier, allows attackers to execute arbitrary code via a malformed (a) PDF or (b) PostScript file, which is processed by an unsafe call to sscanf. | |
| Modificada | Alta (10) | 3.5% | — | Yngve Svendsen Gnatsweb | 6/12/2001 | 16/6/2026 | gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter. | |
| Modificada | Alta (7.2) | 0.46% | — | Svgalib ZGV | 19/2/1999 | 16/6/2026 | SVGAlib zgv 3.0-7 and earlier allows local users to gain root access via a privilege leak of the iopl(3) privileges to child processes. |