Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

656 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.3%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5 through 10.5.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message that reaches a mailing-list archive, aka "persistent JavaScript injection."
ModificadaAlta (9.3)5.8%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
VideoConference in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving H.264 encoded media.
ModificadaBaja (2.1)0.37%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Time Machine in Apple Mac OS X 10.5 through 10.5.4 uses weak permissions for Time Machine Backup log files, which allows local users to obtain sensitive information by reading these files.
ModificadaMedia (5)1.5%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Remote Management and Screen Sharing in Apple Mac OS X 10.5 through 10.5.4, when used to set a password for a VNC viewer, displays additional input characters beyond the maximum password length, which might make it easier for attackers to guess passwords that the user believed were longer.
ModificadaAlta (10)3.5%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via vectors associated with "passing untrusted input" to unspecified API functions.
ModificadaMedia (6.3)0.36%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same…
ModificadaAlta (7.6)2.0%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.
ModificadaAlta (7.2)0.36%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during recycling (aka purging) of a vnode, which might allow local users to bypass the intended read or write permissions of a file.
ModificadaAlta (9.3)3.4%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted JPEG image with an embedded ICC profile.
ModificadaAlta (9.3)3.4%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted TIFF image.
ModificadaMedia (5)1.5%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sharing & Permissions in a filesystem, which might allow local users to leverage weak permissions that were not intended by an administrator.
ModificadaMedia (4.9)0.34%—Apple MAC OS X Server16/9/200816/6/2026
slapconfig in Directory Services in Apple Mac OS X 10.5 through 10.5.4 allows local users to select a readable output file into which the server password will be written by an OpenLDAP system administrator, related to the mkfifo function, aka an "insecure file operation issue."
ModificadaBaja (1.9)0.33%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Directory Services in Apple Mac OS X 10.5 through 10.5.4, when Active Directory is used, allows attackers to enumerate user names via wildcard characters in the Login Window.
ModificadaMedia (4.9)0.34%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Network Preferences in Apple Mac OS X 10.4.11 stores PPP passwords in cleartext in a world-readable file, which allows local users to obtain sensitive information by reading this file.
ModificadaAlta (9.3)5.4%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript font names."
ModificadaMedia (4.6)0.34%—Apple MAC OS XApple MAC OS X Server4/8/200816/6/2026
The Repair Permissions tool in Disk Utility in Apple Mac OS X 10.4.11 adds the setuid bit to the emacs executable file, which allows local users to gain privileges by executing commands within emacs.
ModificadaMedia (6.8)2.5%—Apple MAC OS XApple MAC OS X Server1/7/200816/6/2026
Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code.
ModificadaMedia (6.8)2.6%—Apple MAC OS XApple MAC OS X Server1/7/200816/6/2026
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine…
ModificadaMedia (4.4)0.32%—Apple MAC OS XApple MAC OS X Server1/7/200816/6/2026
Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors.
ModificadaMedia (4.6)0.32%—Apple MAC OS XApple MAC OS X Server1/7/200816/6/2026
Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local users to gain privileges by inserting a Trojan horse file into this directory.
ModificadaAlta (7.6)3.0%—Apple MAC OS XApple MAC OS X Server1/7/200816/6/2026
Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file.
ModificadaMedia (4.6)0.32%—Apple MAC OS XApple MAC OS X Server1/7/200816/6/2026
Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms allows local users to gain privileges or cause a denial of service (memory corruption and application crash) by resolving an alias that contains crafted AFP volume mount information.
ModificadaAlta (9.3)4.6%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document file, as demonstrated by opening the document with TextEdit.
ModificadaMedia (4.3)3.2%—Apple MAC OS XApple MAC OS X ServerRedhat Enterprise Linux2/6/200816/6/2026
The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks.
ModificadaAlta (9.3)5.9%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document, related to an uninitialized variable.
Orbitaley — Vulnerabilidades