Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 5.4% | — | Apple MAC OS XApple MAC OS X Server | 16/9/2008 | 16/6/2026 | Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.4.11 and 10.5 through 10.5.4 allows remote attackers to execute arbitrary code via a document containing a crafted font, related to "PostScript font names." | |
| Modificada | Media (4.6) | 0.34% | — | Apple MAC OS XApple MAC OS X Server | 4/8/2008 | 16/6/2026 | The Repair Permissions tool in Disk Utility in Apple Mac OS X 10.4.11 adds the setuid bit to the emacs executable file, which allows local users to gain privileges by executing commands within emacs. | |
| Modificada | Alta (7.6) | 3.0% | — | Apple MAC OS XApple MAC OS X Server | 1/7/2008 | 16/6/2026 | Launch Services in Apple Mac OS X before 10.5, when Open Safe Files is enabled, allows remote attackers to execute arbitrary code via a symlink attack, probably related to a race condition and automatic execution of a downloaded file. | |
| Modificada | Media (4.4) | 0.32% | — | Apple MAC OS XApple MAC OS X Server | 1/7/2008 | 16/6/2026 | Dock in Apple Mac OS X 10.5 before 10.5.4, when Exposé hot corners is enabled, allows physically proximate attackers to gain access to a locked session in (1) sleep mode or (2) screen saver mode via unspecified vectors. | |
| Modificada | Media (6.8) | 2.6% | — | Apple MAC OS XApple MAC OS X Server | 1/7/2008 | 16/6/2026 | Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.4 allows user-assisted remote attackers to execute arbitrary code via a (1) .xht or (2) .xhtm file, which does not trigger a "potentially unsafe" warning message in (a) the Download Validation feature in Mac OS X 10.4 or (b) the Quarantine… | |
| Modificada | Media (6.8) | 2.5% | — | Apple MAC OS XApple MAC OS X Server | 1/7/2008 | 16/6/2026 | Format string vulnerability in c++filt in Apple Mac OS X 10.5 before 10.5.4 allows user-assisted attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted string in (1) C++ or (2) Java source code. | |
| Modificada | Media (4.6) | 0.32% | — | Apple MAC OS XApple MAC OS X Server | 1/7/2008 | 16/6/2026 | Apple Mac OS X before 10.5 uses weak permissions for the User Template directory, which allows local users to gain privileges by inserting a Trojan horse file into this directory. | |
| Modificada | Media (4.6) | 0.32% | — | Apple MAC OS XApple MAC OS X Server | 1/7/2008 | 16/6/2026 | Unspecified vulnerability in Alias Manager in Apple Mac OS X 10.5.1 and earlier on Intel platforms allows local users to gain privileges or cause a denial of service (memory corruption and application crash) by resolving an alias that contains crafted AFP volume mount information. | |
| Modificada | Alta (9.3) | 4.6% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Unspecified vulnerability in AppKit in Apple Mac OS X before 10.5 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted document file, as demonstrated by opening the document with TextEdit. | |
| Modificada | Media (4.3) | 3.2% | — | Apple MAC OS XApple MAC OS X ServerRedhat Enterprise Linux | 2/6/2008 | 16/6/2026 | The International Components for Unicode (ICU) library in Apple Mac OS X before 10.5.3, Red Hat Enterprise Linux 5, and other operating systems omits some invalid character sequences during conversion of some character encodings, which might allow remote attackers to conduct cross-site scripting (XSS) attacks. | |
| Modificada | Alta (9.3) | 5.9% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | CoreGraphics in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document, related to an uninitialized variable. | |
| Modificada | Alta (7.1) | 2.1% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | The BMP and GIF image decoding engine in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to obtain sensitive information (memory contents) via a crafted (1) BMP or (2) GIF image, which causes an out-of-bounds read. | |
| Modificada | Media (4.3) | 1.5% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Apple Filing Protocol (AFP) Server in Apple Mac OS X before 10.5.3 does not verify that requested files and directories are inside shared folders, which allows remote attackers to read arbitrary files via unspecified AFP traffic. | |
| Modificada | Media (4.6) | 0.37% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Image Capture in Apple Mac OS X before 10.5 does not properly use temporary files, which allows local users to overwrite arbitrary files, and display images that are being resized by this application. | |
| Modificada | Alta (9.3) | 6.7% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Integer overflow in ImageIO in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image that triggers a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 4.2% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via an (1) Automator, (2) Help, (3) Safari, or (4) Terminal content type for a downloadable object, which does not trigger a "potentially unsafe" warning message in (a) the… | |
| Modificada | Alta (9.3) | 5.8% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Unspecified vulnerability in the Pixlet codec in Apple Pixlet Video in Apple Mac OS X before 10.5.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file, related to "multiple memory corruption issues." | |
| Modificada | Media (5) | 2.8% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Wiki Server in Apple Mac OS X 10.5 before 10.5.3 allows remote attackers to obtain sensitive information (user names) by reading the error message produced upon access to a nonexistent blog. | |
| Modificada | Alta (9.3) | 5.8% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Unspecified vulnerability in the Apple Type Services (ATS) server in Apple Mac OS X 10.5 before 10.5.3 allows user-assisted remote attackers to execute arbitrary code via a crafted embedded font in a PDF document, related to memory corruption that occurs during printing. | |
| Modificada | Baja (2.1) | 0.37% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | The sso_util program in Single Sign-On in Apple Mac OS X before 10.5.3 places passwords on the command line, which allows local users to obtain sensitive information by listing the process. | |
| Modificada | Media (5) | 3.5% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Directory traversal vulnerability in the embedded web server in Image Capture in Apple Mac OS X before 10.5 allows remote attackers to read arbitrary files via directory traversal sequences in the URI. | |
| Modificada | Alta (10) | 4.7% | — | Apple MAC OS XApple MAC OS X Server | 2/6/2008 | 16/6/2026 | Integer overflow in the CFDataReplaceBytes function in the CFData API in CoreFoundation in Apple Mac OS X before 10.5.3 allows context-dependent attackers to execute arbitrary code or cause a denial of service (crash) via an invalid length argument, which triggers a heap-based buffer overflow. | |
| Modificada | Crítica (9.8) | 11% | — | PHPFedoraproject FedoraCanonical Ubuntu LinuxApple MAC OS X+1 | 5/5/2008 | 16/6/2026 | The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI. | |
| Modificada | Alta (7.5) | 3.5% | — | MIT Kerberos 5Apple MAC OS XApple MAC OS X ServerOpensuse+7 | 19/3/2008 | 16/6/2026 | The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values." | |
| Modificada | Media (5.8) | 3.1% | — | Apple MAC OS XApple MAC OS X Server | 18/3/2008 | 16/6/2026 | Array index error in pax in Apple Mac OS X 10.5.2 allows context-dependent attackers to execute arbitrary code via an archive with a crafted length value. |