Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
656 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 2.1% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to obtain sensitive information (memory contents) via a crafted (1) BMP or (2) GIF image, which causes an out-of-bounds read. | |
| Modificada | Media (4.3) | 1.5% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Apple Filing Protocol (AFP) Server in Apple Mac OS X before 10.5.3 does not verify that requested files and directories are inside shared folders, which allows remote attackers to read arbitrary files via unspecified AFP traffic. | |
| Modificada | Media (4.6) | 0.37% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Image Capture in Apple Mac OS X before 10.5 does not properly use temporary files, which allows local users to overwrite arbitrary files, and display images that are being resized by this application. | |
| Modificada | Alta (9.3) | 6.7% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Integer overflow in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image that triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 4.2% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Terminal content type for a downloadable object, which does not trigger a "potentially unsafe" warning message in (a) the… | |
| Modificada | Alta (9.3) | 5.8% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Unspecified vulnerability in the Pixlet codec in Apple Pixlet Video in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file, related to "multiple memory corruption issues." | |
| Modificada | Media (5) | 2.8% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message produced upon access to a nonexistent blog. | |
| Modificada | Alta (9.3) | 5.8% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Unspecified vulnerability in the Apple Type Services (ATS) server in Apple Mac OS X 10.5 before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via a crafted embedded font in a PDF document, related to memory corruption that occurs during printing. | |
| Modificada | Baja (2.1) | 0.37% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | The sso_util program in Single Sign-On in Apple Mac OS X before 10.5.3 places passwords on the command line, which allows local users to obtain sensitive information by listing the process. | |
| Modificada | Media (5) | 3.5% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Directory traversal vulnerability in the embedded web server in Image Capture in Apple Mac OS X before 10.5 allows remote attackers to read arbitrary files via directory traversal sequences in the URI. | |
| Modificada | Alta (10) | 4.7% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, which triggers a heap-based buffer overflow. | |
| Modificada | Crítica (9.8) | 11% | — | PHPFedoraproject FedoraCanonical Ubuntu LinuxApple MAC OS X+1 | 5/5/2008 | 16/6/2026 | The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI. | |
| Modificada | Alta (7.5) | 3.5% | — | MIT Kerberos 5Apple MAC OS XApple MAC OS X ServerOpensuse+7 | 19/3/2008 | 16/6/2026 | The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values." | |
| Modificada | Media (6.8) | 2.1% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | CoreServices in Apple Mac OS X 10.4.11 treats .ief as a safe file type, which allows remote attackers to force Safari users into opening an .ief file in AppleWorks, even when the "Open 'Safe' files" preference is set. | |
| Modificada | Baja (2.6) | 1.7% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | The Printing component in Apple Mac OS X 10.5.2 uses 40-bit RC4 when printing to an encrypted PDF file, which makes it easier for attackers to decrypt the file via brute force methods. | |
| Modificada | Media (5.8) | 2.3% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | Race condition in NSXML in Foundation for Apple Mac OS X 10.4.11 allows context-dependent attackers to execute arbitrary code via a crafted XML file, related to "error handling logic." | |
| Modificada | Media (6.8) | 2.1% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | Help Viewer in Apple Mac OS X 10.4.11 and 10.5.2 allows remote attackers to execute arbitrary Applescript via a help:topic_list URL that injects HTML or JavaScript into a topic list page, as demonstrated using a help:runscript link. | |
| Modificada | Baja (2.6) | 1.2% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | Preview in Apple Mac OS X 10.5.2 uses 40-bit RC4 when saving a PDF file with encryption, which makes it easier for attackers to decrypt the file via brute force methods. | |
| Modificada | Media (4.4) | 0.34% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | notifyd in Apple Mac OS X 10.4.11 does not verify that Mach port death notifications have originated from the kernel, which allows local users to cause a denial of service via spoofed death notifications that prevent other applications from receiving notifications. | |
| Modificada | Media (4.3) | 1.6% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-dependent attackers to cause a denial of service (crash) via crafted arguments that trigger a buffer over-read. | |
| Modificada | Media (5.8) | 2.9% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | Race condition in the NSURLConnection cache management functionality in Foundation for Apple Mac OS X 10.4.11 allows remote attackers to execute arbitrary code via unspecified manipulations that cause messages to be sent to a deallocated object. | |
| Modificada | Media (5.8) | 3.1% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | Array index error in pax in Apple Mac OS X 10.5.2 allows context-dependent attackers to execute arbitrary code via an archive with a crafted length value. | |
| Modificada | Alta (7.1) | 2.6% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | Apple Mac OS X 10.5.2 allows user-assisted attackers to cause a denial of service (crash) via a crafted Universal Disc Format (UDF) disk image, which triggers a NULL pointer dereference. | |
| Modificada | Media (6.4) | 4.6% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | Foundation in Apple Mac OS X 10.4.11 might allow context-dependent attackers to execute arbitrary code via a malformed selector name to the NSSelectorFromString API, which causes an "unexpected selector" to be used. | |
| Modificada | Baja (1.7) | 0.34% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | The Printing component in Apple Mac OS X 10.5.2 might save authentication credentials to disk when starting a job on an authenticated print queue, which might allow local users to obtain the credentials. |