Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
432 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.8% | — | Gnome Dhcdbd | 16/6/2006 | 16/6/2026 | Unspecified vulnerability in NetworkManager daemon for DHCP (dhcdbd) allows remote attackers to cause a denial of service (crash) via certain invalid DHCP responses that trigger memory corruption. | |
| Modificada | Baja (3.7) | 0.36% | — | Gnome GDM | 9/6/2006 | 16/6/2026 | GNOME GDM 2.8, 2.12, 2.14, and 2.15, when the "face browser" feature is enabled, allows local users to access the "Configure Login Manager" functionality using their own password instead of the root password, which can be leveraged to gain additional privileges. | |
| Modificada | Baja (2.6) | 2.1% | — | Gnome Evolution | 2/6/2006 | 16/6/2026 | Evolution 2.2.x and 2.3.x in GNOME 2.7 and 2.8, when "load images if sender in addressbook" is enabled, allows remote attackers to cause a denial of service (persistent crash) via a crafted "From" header that triggers an assert error in camel-internet-address.c when a null pointer is used. | |
| Modificada | Baja (3.7) | 0.27% | — | Gnome GDM | 25/4/2006 | 16/6/2026 | Race condition in daemon/slave.c in gdm before 2.14.1 allows local users to gain privileges via a symlink attack when gdm performs chown and chgrp operations on the .ICEauthority file. | |
| Modificada | Baja (3.7) | 0.34% | — | Gnome Screensaver | 21/3/2006 | 16/6/2026 | gnome screensaver before 2.14, when running on an X server with AllowDeactivateGrabs and AllowClosedownGrabs enabled, allows attackers with physical access to cause the screensaver to crash and access the session via the Ctl+Alt+Keypad-Multiply keyboard sequence, which removes the grab from gnome. | |
| Modificada | Alta (7.6) | 2.2% | — | Gnome GpdfLibextractorXpdfDebian Linux | 15/3/2006 | 16/6/2026 | Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user-assisted attack vectors, possibly involving errors in (1) gmem.c, (2) SplashXPathScanner.cc, (3) JBIG2Stream.cc, (4)… | |
| Modificada | Media (4.3) | 1.4% | — | Gnome Dwarf Http Server | 13/3/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Dwarf HTTP Server 1.3.2 allows remote attackers to inject arbitrary web script or HTML via unspecified error messages. | |
| Modificada | Alta (7.8) | 2.3% | — | Gnome Dwarf Http Server | 13/3/2006 | 16/6/2026 | Dwarf HTTP Server 1.3.2 allows remote attackers to obtain the source code of JSP files via (1) dot, (2) space, (3) slash, or (4) NULL characters in the filename extension of an HTTP request. | |
| Modificada | Media (5) | 2.0% | — | Gnome Evolution | 10/3/2006 | 16/6/2026 | GNOME Evolution 2.4.2.1 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) via a text e-mail with a large number of URLs, possibly due to unknown problems in gtkhtml. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Gnome Evolution | 2/2/2006 | 16/6/2026 | The cairo library (libcairo), as used in GNOME Evolution and possibly other products, allows remote attackers to cause a denial of service (persistent client crash) via an attached text file that contains "Content-Disposition: inline" in the header, and a very long line in the body, which causes the client to… | |
| Modificada | Alta (7.5) | 4.5% | — | Gnome GdkpixbufGnome GTK | 18/11/2005 | 16/6/2026 | Integer overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary code via an XPM file with large height, width, and colour values, a different vulnerability than CVE-2005-3186. | |
| Modificada | Alta (7.5) | 4.7% | — | Gnome GdkpixbufGtk+ | 18/11/2005 | 16/6/2026 | Integer overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a number of colors that causes insufficient memory to be allocated, which leads to a heap-based buffer overflow. | |
| Modificada | Alta (7.8) | 3.7% | — | Gnome GdkpixbufGnome GTK | 18/11/2005 | 16/6/2026 | io-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a crafted XPM image with a large number of colors. | |
| Modificada | Alta (7.5) | 3.6% | — | Gnome Libgda2 | 25/10/2005 | 16/6/2026 | Multiple format string vulnerabilities in the GNOME Data Access library for GNOME2 (libgda2) 1.2.1 and earlier allow attackers to execute arbitrary code. | |
| Modificada | Baja (2.1) | 0.89% | 💥 Exploit | Gnome Libvte4Gnome Libzvt2 | 5/10/2005 | 16/6/2026 | gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY environment variable. NOTE: the severity of this issue has been disputed. | |
| Modificada | Media (4.6) | 0.33% | — | Brent ELY Gnome Workstation Command Center | 16/9/2005 | 16/6/2026 | The perform_file_save function in GNOME Workstation Command Center (gwcc) 0.9.6 and earlier allows local users to create and overwrite arbitrary files via a symlink attack on the gwcc_out.txt temporary file. | |
| Modificada | Alta (7.5) | 4.4% | — | Gnome Evolution | 12/8/2005 | 16/6/2026 | Multiple format string vulnerabilities in Evolution 1.5 through 2.3.6.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) full vCard data, (2) contact data from remote LDAP servers, or (3) task list data from remote servers. | |
| Modificada | Alta (7.5) | 4.4% | — | Gnome Evolution | 12/8/2005 | 16/6/2026 | Format string vulnerability in Evolution 1.4 through 2.3.6.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via the calendar entries such as task lists, which are not properly handled when the user selects the Calendars tab. | |
| Modificada | Alta (7.5) | 3.5% | — | Gnome Networkmanager | 1/8/2005 | 16/6/2026 | Format string vulnerability in the nm_info_handler function in Network Manager may allow remote attackers to execute arbitrary code via format string specifiers in a Wireless Access Point identifier, which is not properly handled in a syslog call. | |
| Modificada | Baja (2.6) | 7.7% | 💥 Exploit | Gnome Gedit | 20/5/2005 | 16/6/2026 | Format string vulnerability in gedit 2.10.2 may allow attackers to cause a denial of service (application crash) via a bin file with format string specifiers in the filename. NOTE: while this issue is triggered on the command line by the gedit user, it has been reported that web browsers and email clients could be… | |
| Modificada | Media (5) | 4.4% | — | Gnome GTK | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in gftp before 2.0.18 for GTK+ allows remote malicious FTP servers to read arbitrary files via .. (dot dot) sequences in filenames returned from a LIST command. | |
| Modificada | Alta (7.5) | 3.5% | — | Gnome GTK | 2/5/2005 | 16/6/2026 | Double free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image. | |
| Modificada | Media (5) | 1.6% | — | Gnome EpiphanyMozilla CaminoMozillaOmnigroup Omniweb+1 | 2/5/2005 | 16/6/2026 | The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks. | |
| Modificada | Alta (7.5) | 3.0% | — | Ascii PtexCstex CstetexEasy Software Products CupsGnome Gpdf+18 | 27/4/2005 | 16/6/2026 | The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities. | |
| Modificada | Alta (10) | 6.2% | — | Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+12 | 27/1/2005 | 16/6/2026 | Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888. |