Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

656 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)2.1%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to obtain sensitive information (memory contents) via a crafted (1) BMP or (2) GIF image, which causes an out-of-bounds read.
ModificadaMedia (4.3)1.5%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
Apple Filing Protocol (AFP) Server in Apple Mac OS X before 10.5.3 does not verify that requested files and directories are inside shared folders, which allows remote attackers to read arbitrary files via unspecified AFP traffic.
ModificadaMedia (4.6)0.37%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
Image Capture in Apple Mac OS X before 10.5 does not properly use temporary files, which allows local users to overwrite arbitrary files, and display images that are being resized by this application.
ModificadaAlta (9.3)6.7%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
Integer overflow in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image that triggers a heap-based buffer overflow.
ModificadaMedia (6.8)4.2%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Terminal content type for a downloadable object, which does not trigger a "potentially unsafe" warning message in (a) the…
ModificadaAlta (9.3)5.8%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
Unspecified vulnerability in the Pixlet codec in Apple Pixlet Video in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file, related to "multiple memory corruption issues."
ModificadaMedia (5)2.8%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message produced upon access to a nonexistent blog.
ModificadaAlta (9.3)5.8%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
Unspecified vulnerability in the Apple Type Services (ATS) server in Apple Mac OS X 10.5 before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via a crafted embedded font in a PDF document, related to memory corruption that occurs during printing.
ModificadaBaja (2.1)0.37%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
The sso_util program in Single Sign-On in Apple Mac OS X before 10.5.3 places passwords on the command line, which allows local users to obtain sensitive information by listing the process.
ModificadaMedia (5)3.5%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
Directory traversal vulnerability in the embedded web server in Image Capture in Apple Mac OS X before 10.5 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.
ModificadaAlta (10)4.7%—Apple MAC OS XApple MAC OS X Server2/6/200816/6/2026
Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, which triggers a heap-based buffer overflow.
ModificadaCrítica (9.8)11%—PHPFedoraproject FedoraCanonical Ubuntu LinuxApple MAC OS X+15/5/200816/6/2026
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
ModificadaAlta (7.5)3.5%—MIT Kerberos 5Apple MAC OS XApple MAC OS X ServerOpensuse+719/3/200816/6/2026
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
ModificadaMedia (6.8)2.1%—Apple MAC OS XApple MAC OS X Server18/3/200816/6/2026
CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set.
ModificadaBaja (2.6)1.7%—Apple MAC OS XApple MAC OS X Server18/3/200816/6/2026
The Printing component in Apple Mac OS X 10.5.2 uses 40-bit RC4 when printing to an encrypted PDF file, which makes it easier for attackers to decrypt the file via brute force methods.
ModificadaMedia (5.8)2.3%—Apple MAC OS XApple MAC OS X Server18/3/200816/6/2026
Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic."
ModificadaMedia (6.8)2.1%—Apple MAC OS XApple MAC OS X Server18/3/200816/6/2026
Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link.
ModificadaBaja (2.6)1.2%—Apple MAC OS XApple MAC OS X Server18/3/200816/6/2026
Preview in Apple Mac OS X 10.5.2 uses 40-bit RC4 when saving a PDF file with encryption, which makes it easier for attackers to decrypt the file via brute force methods.
ModificadaMedia (4.4)0.34%—Apple MAC OS XApple MAC OS X Server18/3/200816/6/2026
notifyd in Apple Mac OS X 10.4.11 does not verify that Mach port death notifications have originated from the kernel, which allows local users to cause a denial of service via spoofed death notifications that prevent other applications from receiving notifications.
ModificadaMedia (4.3)1.6%—Apple MAC OS XApple MAC OS X Server18/3/200816/6/2026
Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-dependent attackers to cause a denial of service (crash) via crafted arguments that trigger a buffer over-read.
ModificadaMedia (5.8)2.9%—Apple MAC OS XApple MAC OS X Server18/3/200816/6/2026
Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object.
ModificadaMedia (5.8)3.1%—Apple MAC OS XApple MAC OS X Server18/3/200816/6/2026
Array index error in pax in Apple Mac OS X 10.5.2 allows context-dependent attackers to execute arbitrary code via an archive with a crafted length value.
ModificadaAlta (7.1)2.6%—Apple MAC OS XApple MAC OS X Server18/3/200816/6/2026
Apple Mac OS X 10.5.2 allows user-assisted attackers to cause a denial of service (crash) via a crafted Universal Disc Format (UDF) disk image, which triggers a NULL pointer dereference.
ModificadaMedia (6.4)4.6%—Apple MAC OS XApple MAC OS X Server18/3/200816/6/2026
Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used.
ModificadaBaja (1.7)0.34%—Apple MAC OS XApple MAC OS X Server18/3/200816/6/2026
The Printing component in Apple Mac OS X 10.5.2 might save authentication credentials to disk when starting a job on an authenticated print queue, which might allow local users to obtain the credentials.