Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

432 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)9.5%—Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+1227/1/200516/6/2026
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
ModificadaCrítica (9.8)3.2%—Gnome EvolutionDebian Linux24/1/200516/6/2026
Integer overflow in camel-lock-helper in Evolution 2.0.2 and earlier allows local users or remote malicious POP3 servers to execute arbitrary code via a length value of -1, which leads to a zero byte memory allocation and a buffer overflow.
ModificadaMedia (5)5.9%—Gnome GdkpixbufGnome GTK20/10/200416/6/2026
Integer overflow in the ICO image decoder for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted ICO file.
ModificadaAlta (7.5)9.2%—Gnome GdkpixbufGnome GTK20/10/200416/6/2026
Integer overflow in pixbuf_create_from_xpm (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, allows remote attackers to execute arbitrary code via certain n_col and cpp values that enable a heap-based buffer overflow. NOTE: this identifier is ONLY for gtk+. It was…
ModificadaMedia (5)5.9%—Gnome GdkpixbufGnome GTK20/10/200416/6/2026
The BMP image processor for (1) gdk-pixbuf before 0.22 and (2) gtk2 before 2.2.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted BMP file.
ModificadaAlta (7.5)9.4%—Gnome GdkpixbufGnome GTK20/10/200416/6/2026
Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a…
ModificadaMedia (5)2.1%—Gnome GdkpixbufRedhat GDK PixbufSGI PropackRedhat Enterprise Linux+115/4/200416/6/2026
gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.
ModificadaBaja (2.1)0.36%—Gnome GDM17/11/200316/6/2026
GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not limit the number or duration of commands and uses a blocking socket connection, which allows attackers to cause a denial of service (resource exhaustion) by sending commands and not reading the results.
ModificadaBaja (2.1)0.42%—Gnome GDM17/11/200316/6/2026
GDM 2.4.4.x before 2.4.4.4, and 2.4.1.x before 2.4.1.7, does not restrict the size of input, which allows attackers to cause a denial of service (memory consumption).
ModificadaMedia (5)2.6%—Gnome Gtkhtml17/9/200316/6/2026
gtkhtml before 1.1.10, as used in Evolution, allows remote attackers to cause a denial of service (crash) via a malformed message that causes a null pointer dereference.
ModificadaMedia (5)1.5%—Gnome GDMRedhat KdebaseRedhat Enterprise LinuxRedhat Linux Advanced Workstation27/8/200316/6/2026
The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.
ModificadaBaja (2.1)0.37%—Gnome GDMRedhat Kdebase27/8/200316/6/2026
GDM before 2.4.1.6, when using the "examine session errors" feature, allows local users to read arbitrary files via a symlink attack on the ~/.xsession-errors file.
ModificadaMedia (5)1.5%—Gnome GDMRedhat KdebaseRedhat Enterprise LinuxRedhat Linux Advanced Workstation27/8/200316/6/2026
The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.
ModificadaAlta (10)16%💥 ExploitGnome Batalla Naval30/6/200316/6/2026
Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.
ModificadaMedia (5)1.7%—Gnome Gtkhtml5/5/200316/6/2026
GtkHTML, as included in Evolution before 1.2.4, allows remote attackers to cause a denial of service (crash) via certain malformed messages.
ModificadaMedia (4.6)1.7%💥 ExploitGnome EOG2/4/200316/6/2026
Format string vulnerability in Eye Of Gnome (EOG) allows attackers to execute arbitrary code via format string specifiers in a command line argument for the file to display.
ModificadaAlta (7.5)2.0%—Gnome-lokkit31/3/200316/6/2026
The iptables ruleset in Gnome-lokkit in Red Hat Linux 8.0 does not include any rules in the FORWARD chain, which could allow attackers to bypass intended access restrictions if packet forwarding is enabled.
ModificadaMedia (6.8)2.1%—Nalin Dahyabhai VTEGnome-terminal3/3/200316/6/2026
VTE, as used by default in gnome-terminal terminal emulator 2.2 and as an option in gnome-terminal 2.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious…
ModificadaMedia (4.6)1.1%💥 ExploitGnome BonoboMandrakesoft Mandrake LinuxRedhat LinuxSlackware Linux31/12/200216/6/2026
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long command line arguments.
ModificadaAlta (7.5)6.1%—Gnome Libgtop Daemon28/11/200116/6/2026
Buffer overflow in the permitted function of GNOME gtop daemon (libgtop_daemon) in libgtop 1.0.13 and earlier may allow remote attackers to execute arbitrary code via long authentication data.
ModificadaAlta (7.5)2.8%—Gnome Libgtop Daemon27/11/200116/6/2026
Format string vulnerability in the permitted function of GNOME libgtop_daemon in libgtop 1.0.12 and earlier allows remote attackers to execute arbitrary code via an argument that contains format specifiers that are passed into the (1) syslog_message and (2) syslog_io_message functions.
ModificadaAlta (7.2)1.0%💥 ExploitGnome GTK12/2/200116/6/2026
GTK+ library allows local users to specify arbitrary modules via the GTK_MODULES environmental variable, which could allow local users to gain privileges if GTK+ is used by a setuid/setgid program.
ModificadaAlta (7.2)0.40%—Gnome Gnorpm19/12/200023/9/2026
GnoRPM before 0.95 allows local users to modify arbitrary files via a symlink attack.
ModificadaMedia (6.2)0.69%💥 ExploitGnome Esound14/11/200016/6/2026
Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change the permissions of arbitrary files and directories, and gain additional privileges, via a symlink attack.
ModificadaAlta (7.5)1.4%—Alan COX Gnome-lokkit20/10/200016/6/2026
Gnome Lokkit firewall package before 0.41 does not properly restrict access to some ports, even if a user does not make any services available.