Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

519 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.65%—Suse Linux21/9/200516/6/2026
Buffer overflow in liby2util in Yet another Setup Tool (YaST) for SuSE Linux 9.3 allows local users to execute arbitrary code via a long Loc entry.
ModificadaBaja (2.1)0.46%—Novell Open Enterprise ServerNovell Linux DesktopSuse Linux5/8/200516/6/2026
traps.c in the Linux kernel 2.6.x and 2.4.x executes stack segment faults on an exception stack, which allows local users to cause a denial of service (oops and stack fault exception).
ModificadaBaja (2.1)0.46%—Novell Open Enterprise ServerNovell Linux DesktopSuse Linux5/8/200516/6/2026
Linux kernel 2.6 and 2.4 on the IA64 architecture allows local users to cause a denial of service (kernel crash) via ptrace and the restore_sigcontext function.
ModificadaAlta (10)2.3%—Suse Linux17/6/200516/6/2026
The send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, which can prevent pinentry from being found and causes S/MIME signing to fail.
ModificadaAlta (7.2)0.41%—Novell Linux DesktopSuse Linux9/6/200516/6/2026
Buffer overflow in ptrace in the Linux Kernel for 64-bit architectures allows local users to write bytes into kernel memory.
ModificadaAlta (7.5)4.4%—GraphicsmagickImagemagickSGI PropackDebian Linux+22/5/200516/6/2026
Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers.
ModificadaAlta (7.5)2.8%—Wietse Venema PostfixRedhat Enterprise LinuxRedhat Enterprise Linux DesktopSuse Linux2/5/200516/6/2026
Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.
ModificadaBaja (2.1)0.41%—Conectiva LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+12/5/200516/6/2026
Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT.
ModificadaMedia (6.8)2.3%—HtdigMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Fedora Core+127/4/200516/6/2026
Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
ModificadaAlta (7.5)3.0%—Ascii PtexCstex CstetexEasy Software Products CupsGnome Gpdf+1827/4/200516/6/2026
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
ModificadaMedia (5)1.7%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."
ModificadaMedia (5)1.7%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.
ModificadaMedia (5)1.7%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."
ModificadaMedia (5)1.4%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."
ModificadaAlta (7.5)1.6%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
ModificadaMedia (5)1.9%—PHPSGI PropackConectiva LinuxApple MAC OS X+314/4/200516/6/2026
exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.
ModificadaBaja (2.1)0.36%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopSuse Linux14/4/200516/6/2026
Unknown vulnerability in the system call filtering code in the audit subsystem for Red Hat Enterprise Linux 3 allows local users to cause a denial of service (system crash) via unknown vectors.
ModificadaMedia (5)1.7%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.
ModificadaAlta (7.5)1.6%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
ModificadaAlta (7.5)1.8%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
ModificadaMedia (6.2)2.9%💥 ExploitAvaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+1614/4/200516/6/2026
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
ModificadaMedia (5)2.5%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
ModificadaAlta (7.5)3.1%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaAlta (7.2)0.85%💥 ExploitConectiva LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+427/3/200516/6/2026
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
ModificadaMedia (5)4.0%—Redhat Enterprise LinuxSuse LinuxTrustix Secure LinuxUbuntu Linux15/3/200516/6/2026
Unknown vulnerability in the PPP driver for the Linux kernel 2.6.8.1 allows remote attackers to cause a denial of service (kernel crash) via a pppd client.
Orbitaley — Vulnerabilidades