Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

667 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)9.2%💥 ExploitApple CupsApple MAC OS XApple MAC OS X ServerOpensuse+121/11/200816/6/2026
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon crash) by adding a large number of RSS Subscriptions, which triggers a NULL pointer dereference. NOTE: this issue can be triggered remotely by leveraging CVE-2008-5184.
ModificadaAlta (7.5)1.4%—Apple MAC OS X Server10/10/200816/6/2026
Weblog in Mac OS X Server 10.4.11 does not properly check an error condition when a weblog posting access control list is specified for a user that has multiple short names, which might allow attackers to bypass intended access restrictions.
ModificadaMedia (4.6)0.32%—Apple MAC OS XApple MAC OS X Server10/10/200816/6/2026
Unspecified vulnerability in Script Editor in Mac OS X 10.4.11 and 10.5.5 allows local users to cause the scripting dictionary to be written to arbitrary locations, related to an "insecure file operation" on temporary files.
ModificadaAlta (10)2.6%—Apple MAC OS XApple MAC OS X Server10/10/200816/6/2026
Unspecified vulnerability in rlogind in the rlogin component in Mac OS X 10.4.11 and 10.5.5 applies hosts.equiv entries to root despite what is stated in documentation, which might allow remote attackers to bypass intended access restrictions.
ModificadaAlta (10)6.6%—Apple MAC OS XApple MAC OS X ServerApple Iphone OS10/10/200816/6/2026
Integer signedness error in (1) QuickLook in Apple Mac OS X 10.5.5 and (2) Office Viewer in Apple iPhone OS 1.0 through 2.1 and iPhone OS for iPod touch 1.1 through 2.1 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a crafted Microsoft Excel file that…
ModificadaAlta (9.3)4.8%—Apple MAC OS XApple MAC OS X Server10/10/200816/6/2026
Buffer overflow in PSNormalizer in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and execute arbitrary code via a PostScript file with a crafted bounding box comment.
ModificadaAlta (7.2)0.45%—Apple MAC OS XApple MAC OS X Server10/10/200816/6/2026
Heap-based buffer overflow in the local IPC component in the EAPOLController plugin for configd (Networking component) in Mac OS X 10.4.11 and 10.5.5 allows local users to execute arbitrary code via unknown vectors.
ModificadaAlta (7.8)1.6%—Apple MAC OS XApple MAC OS X Server10/10/200816/6/2026
Unspecified vulnerability in Finder in Mac OS X 10.5.5 allows user-assisted attackers to cause a denial of service (continuous termination and restart) via a crafted Desktop file that generates an error when producing its icon, related to an "error recovery issue."
ModificadaAlta (9.3)5.5%—Apple MAC OS XApple MAC OS X Server10/10/200816/6/2026
Buffer overflow in ColorSync in Mac OS X 10.4.11 and 10.5.5 allows remote attackers to cause a denial of service (application termination) and possibly execute arbitrary code via an image with a crafted ICC profile.
ModificadaAlta (9.3)3.2%—Apple MAC OS XApple MAC OS X Server26/9/200816/6/2026
Java on Apple Mac OS X 10.5.4 and 10.5.5 does not prevent applets from accessing file:// URLs, which allows remote attackers to execute arbitrary programs.
ModificadaAlta (8.8)5.7%—Apple MAC OS XApple MAC OS X Server26/9/200816/6/2026
The Hash-based Message Authentication Code (HMAC) provider in Java on Apple Mac OS X 10.4.11, 10.5.4, and 10.5.5 uses an uninitialized variable, which allows remote attackers to execute arbitrary code via a crafted applet, related to an "error checking issue."
ModificadaMedia (4.3)2.3%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5 through 10.5.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail message that reaches a mailing-list archive, aka "persistent JavaScript injection."
ModificadaAlta (9.3)5.8%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
VideoConference in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving H.264 encoded media.
ModificadaBaja (2.1)0.37%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Time Machine in Apple Mac OS X 10.5 through 10.5.4 uses weak permissions for Time Machine Backup log files, which allows local users to obtain sensitive information by reading these files.
ModificadaMedia (5)1.5%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Remote Management and Screen Sharing in Apple Mac OS X 10.5 through 10.5.4, when used to set a password for a VNC viewer, displays additional input characters beyond the maximum password length, which might make it easier for attackers to guess passwords that the user believed were longer.
ModificadaAlta (10)3.5%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Multiple integer overflows in the SearchKit API in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allow context-dependent attackers to cause a denial of service (application crash) or execute arbitrary code via vectors associated with "passing untrusted input" to unspecified API functions.
ModificadaMedia (6.3)0.36%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Login Window in Apple Mac OS X 10.4.11 does not clear the current password when a user makes a password-change attempt that is denied by policy, which allows opportunistic, physically proximate attackers to bypass authentication and change this user's password by later entering an acceptable new password on the same…
ModificadaAlta (7.6)2.0%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Race condition in Login Window in Apple Mac OS X 10.5 through 10.5.4, when a blank-password account is enabled, allows attackers to bypass password authentication and login to any account via multiple attempts to login to the blank-password account, followed by selection of an arbitrary account from the user list.
ModificadaAlta (7.2)0.36%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
The kernel in Apple Mac OS X 10.5 through 10.5.4 does not properly flush cached credentials during recycling (aka purging) of a vnode, which might allow local users to bypass the intended read or write permissions of a file.
ModificadaAlta (9.3)3.4%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted JPEG image with an embedded ICC profile.
ModificadaAlta (9.3)3.4%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
ImageIO in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a crafted TIFF image.
ModificadaMedia (5)1.5%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Finder in Apple Mac OS X 10.5 through 10.5.4 does not properly update permission data in the Get Info window after a lock operation that modifies Sharing & Permissions in a filesystem, which might allow local users to leverage weak permissions that were not intended by an administrator.
ModificadaMedia (4.9)0.34%—Apple MAC OS X Server16/9/200816/6/2026
slapconfig in Directory Services in Apple Mac OS X 10.5 through 10.5.4 allows local users to select a readable output file into which the server password will be written by an OpenLDAP system administrator, related to the mkfifo function, aka an "insecure file operation issue."
ModificadaBaja (1.9)0.33%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Directory Services in Apple Mac OS X 10.5 through 10.5.4, when Active Directory is used, allows attackers to enumerate user names via wildcard characters in the Login Window.
ModificadaMedia (4.9)0.34%—Apple MAC OS XApple MAC OS X Server16/9/200816/6/2026
Network Preferences in Apple Mac OS X 10.4.11 stores PPP passwords in cleartext in a world-readable file, which allows local users to obtain sensitive information by reading this file.