Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
472 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.37% | — | Linux-pam | 24/1/2011 | 16/6/2026 | The pam_env module in Linux-PAM (aka pam) 1.1.2 and earlier reads the .pam_environment file in a user's home directory, which might allow local users to run programs with an unintended environment by executing a program that relies on the pam_env PAM check. | |
| Modificada | Media (4.9) | 0.36% | — | Linux-pam | 24/1/2011 | 16/6/2026 | The check_acl function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not verify that a certain ACL file is a regular file, which might allow local users to cause a denial of service (resource consumption) via a special file. | |
| Modificada | Media (4.9) | 0.37% | — | Linux-pam | 24/1/2011 | 16/6/2026 | The pam_sm_close_session function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) 1.1.2 and earlier does not properly handle a failure to determine a certain target uid, which might allow local users to delete unintended files by executing a program that relies on the pam_xauth PAM check. | |
| Modificada | Media (6.9) | 0.41% | — | Linux-pam | 24/1/2011 | 16/6/2026 | pam_namespace.c in the pam_namespace module in Linux-PAM (aka pam) before 1.1.3 uses the environment of the invoking application or service during execution of the namespace.init script, which might allow local users to gain privileges by running a setuid program that relies on the pam_namespace PAM check, as… | |
| Modificada | Media (4.7) | 0.35% | — | Linux-pam | 24/1/2011 | 16/6/2026 | The (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) before 1.1.2 use root privileges during read access to files and directories that belong to arbitrary user accounts, which might allow local users to obtain sensitive information by leveraging this filesystem activity, as demonstrated by a symlink attack… | |
| Modificada | Baja (1.9) | 0.35% | — | Linux-pam | 24/1/2011 | 16/6/2026 | The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not check the return value of the setfsuid system call, which might allow local users to obtain sensitive information by leveraging an unintended uid, as demonstrated by a symlink attack on the… | |
| Modificada | Media (4.7) | 0.34% | — | Linux-pam | 24/1/2011 | 16/6/2026 | The privilege-dropping implementation in the (1) pam_env and (2) pam_mail modules in Linux-PAM (aka pam) 1.1.2 does not perform the required setfsgid and setgroups system calls, which might allow local users to obtain sensitive information by leveraging unintended group permissions, as demonstrated by a symlink attack… | |
| Modificada | Baja (3.3) | 0.36% | — | Linux-pam | 24/1/2011 | 16/6/2026 | The run_coprocess function in pam_xauth.c in the pam_xauth module in Linux-PAM (aka pam) before 1.1.2 does not check the return values of the setuid, setgid, and setgroups system calls, which might allow local users to read arbitrary files by executing a program that relies on the pam_xauth PAM check. | |
| Modificada | Alta (9.3) | 8.5% | 💥 Exploit | Georg Greve Spamassassin Milter Plugin | 27/3/2010 | 16/6/2026 | The mlfi_envrcpt function in spamass-milter.cpp in SpamAssassin Milter Plugin 0.3.1, when using the expand option, allows remote attackers to execute arbitrary system commands via shell metacharacters in the RCPT TO field of an email message. | |
| Modificada | Media (4.3) | 5.8% | 💥 Exploit | Peter's Math Anti-spam FOR Wordpress | 11/9/2009 | 16/6/2026 | Peter's Math Anti-Spam Spinoff plugin for WordPress generates audio CAPTCHA clips by concatenating static audio files without any additional distortion, which allows remote attackers to bypass CAPTCHA protection by reading certain bytes from the generated clip. | |
| Modificada | Media (5) | 2.9% | — | Eyrie Pam-krb5 | 28/5/2009 | 16/6/2026 | pam_krb5 2.2.14 through 2.3.4, as used in Red Hat Enterprise Linux (RHEL) 5, generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. | |
| Modificada | Media (4.6) | 0.35% | — | Linux-pam | 16/4/2009 | 16/6/2026 | Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified. | |
| Modificada | Alta (7.5) | 1.4% | — | Typo3 ND Antispam | 10/4/2009 | 16/6/2026 | Unspecified vulnerability in nepa-design.de Spam Protection (nd_antispam) extension 1.0.3 for TYPO3 allows remote attackers to modify configuration via unknown vectors. | |
| Modificada | Media (5) | 1.3% | — | Andrew J.korty PAM SSH | 8/4/2009 | 16/6/2026 | pam_ssh 1.92 and possibly other versions, as used when PAM is compiled with USE=ssh, generates different error messages depending on whether the username is valid or invalid, which makes it easier for remote attackers to enumerate usernames. | |
| Modificada | Media (6.6) | 1.9% | — | Linux-pam | 12/3/2009 | 16/6/2026 | Integer signedness error in the _pam_StrTok function in libpam/pam_misc.c in Linux-PAM (aka pam) 1.0.3 and earlier, when a configuration file contains non-ASCII usernames, might allow remote attackers to cause a denial of service, and might allow remote authenticated users to obtain login access with a different… | |
| Modificada | Media (4.6) | 0.38% | — | Eyrie Pam-krb5 | 13/2/2009 | 16/6/2026 | Russ Allbery pam-krb5 before 3.13, as used by libpam-heimdal, su in Solaris 10, and other software, does not properly handle calls to pam_setcred when running setuid, which allows local users to overwrite and change the ownership of arbitrary files by setting the KRB5CCNAME environment variable, and then launching a… | |
| Modificada | Media (6.2) | 0.69% | 💥 Exploit | Eyrie Pam-krb5 | 13/2/2009 | 16/6/2026 | Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries for setuid use, which allows local users to gain privileges by pointing an environment variable to a modified Kerberos configuration file, and then launching a PAM-based setuid application. | |
| Modificada | Media (6.5) | 2.0% | 💥 Exploit | Barracuda Networks Barracuda Spam Firewall | 19/12/2008 | 16/6/2026 | SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 allows remote authenticated administrators to execute arbitrary SQL commands via a pattern_x parameter in a search_count_equals action, as demonstrated by the pattern_0 parameter. | |
| Modificada | Baja (3.5) | 1.5% | — | Barracuda Networks Barracuda IM FirewallBarracuda Networks Barracuda Load BalancerBarracuda Networks Barracuda Message ArchiverBarracuda Networks Barracuda Spam Firewall+1 | 19/12/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.cgi in Barracuda Spam Firewall (BSF) before 3.5.12.007, Message Archiver before 1.2.1.002, Web Filter before 3.3.0.052, IM Firewall before 3.1.01.017, and Load Balancer before 2.3.024 allow remote attackers to inject arbitrary web script or HTML via (1) the… | |
| Modificada | Media (6.9) | 0.29% | — | Bkleineidam Libpam Mount | 18/11/2008 | 16/6/2026 | passwdehd in libpam-mount 0.43 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/passwdehd.##### temporary file. | |
| Modificada | Media (5) | 7.3% | 💥 Exploit | THE Spanner Spambam PluginWordpress Spambam Plugin | 20/10/2008 | 16/6/2026 | The SpamBam plugin for WordPress allows remote attackers to bypass restrictions and add blog comments by using server-supplied values to calculate a shared key. | |
| Modificada | Media (6.9) | 0.32% | — | PAM Mount | 11/9/2008 | 16/6/2026 | pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount. | |
| Modificada | Media (4.3) | 1.1% | — | Commtouch Enterprise Anti-spam Gateway | 9/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in UPM/English/login/login.asp in Commtouch Enterprise Anti-Spam Gateway 4 and 5 allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter. | |
| Modificada | Media (6.4) | 1.4% | — | Spamdyke | 19/6/2008 | 16/6/2026 | The smtp_filter function in spamdyke before 3.1.8 does not filter RCPT commands after encountering the first DATA command, which allows remote attackers to use the server as an open mail relay by sending RCPT commands with invalid recipients, followed by a DATA command, followed by arbitrary RCPT commands and a second… | |
| Modificada | Media (4.6) | 0.32% | — | Libpam-pgsql | 3/6/2008 | 16/6/2026 | pam_sm_authenticate in pam_pgsql.c in libpam-pgsql 0.6.3 does not properly consider operator precedence when evaluating the success of a pam_get_pass function call, which allows local users to gain privileges via a SIGINT signal when this function is executing, as demonstrated by a CTRL-C sequence at a sudo password… |