Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
656 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.37% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Integer signedness error in the ttioctl function in bsd/kern/tty.c in the xnu kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to cause a denial of service (system shutdown) or gain privileges via a crafted TIOCSETD ioctl request. | |
| Modificada | Media (6.8) | 3.0% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Unspecified vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via unknown vectors related to browser history, which triggers memory corruption. | |
| Modificada | Media (4.3) | 1.5% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Unspecified "input validation" vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to modify form field values via unknown vectors related to file uploads. | |
| Modificada | Alta (7.2) | 0.39% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen saver and send keystrokes to a process, related to "handling of keyboard focus between secure text fields." | |
| Modificada | Alta (10) | 2.1% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that allow attackers to bypass intended restrictions for local file system URLs. | |
| Modificada | Alta (7.1) | 2.1% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | AppleRAID in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows attackers to cause a denial of service (crash) via a crafted striped disk image, which triggers a NULL pointer dereference when it is mounted. | |
| Modificada | Alta (9.3) | 1.7% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | The remote_cmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, which allows tftpd users to escape the private directory and access arbitrary files. | |
| Modificada | Alta (7.2) | 0.34% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | The kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to gain privileges by executing setuid or setgid programs in which the stdio, stderr, or stdout file descriptors are "in an unexpected state." | |
| Modificada | Alta (7.2) | 0.49% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Integer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk Session Protocol (ASP) message on an AppleTalk socket, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (10) | 7.3% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets. | |
| Modificada | Media (6.4) | 2.5% | — | Pcre Perl-compatible Regular Expression LibraryApple MAC OS XApple MAC OS X Server | 7/11/2007 | 16/6/2026 | Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d"… | |
| Modificada | Media (5) | 1.4% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2007 | 16/6/2026 | CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks. | |
| Modificada | Media (5.8) | 6.9% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2007 | 16/6/2026 | Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac OS X 10.4.10 before 20070731 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet. | |
| Modificada | Crítica (9.8) | 70% | 💥 Exploit | TcpdumpCanonical Ubuntu LinuxDebian LinuxSlackware+3 | 16/7/2007 | 16/6/2026 | Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value. | |
| Modificada | Media (5) | 12% | — | Apple MAC OS X ServerApache Http Server | 27/6/2007 | 16/6/2026 | cache_util.c in the mod_cache module in Apache HTTP Server (httpd), when caching is enabled and a threaded Multi-Processing Module (MPM) is used, allows remote attackers to cause a denial of service (child processing handler crash) via a request with the (1) s-maxage, (2) max-age, (3) min-fresh, or (4) max-stale… | |
| Modificada | Media (4.3) | 7.1% | 💥 Exploit | Apple MAC OS XApple MAC OS X Server | 25/6/2007 | 16/6/2026 | CRLF injection vulnerability in WebCore in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1, allows remote attackers to inject arbitrary HTTP headers via LF characters in an XMLHttpRequest request, which are not filtered when serializing headers via the setRequestHeader function. NOTE: this issue can… | |
| Modificada | Alta (9.3) | 7.3% | — | Apple MAC OS XApple MAC OS X Server | 25/6/2007 | 16/6/2026 | WebKit in Apple Mac OS X 10.3.9, 10.4.9 and later, and iPhone before 1.0.1 performs an "invalid type conversion", which allows remote attackers to execute arbitrary code via unspecified frame sets that trigger memory corruption. | |
| Modificada | Baja (2.1) | 0.32% | — | Apple MAC OS XApple MAC OS X Server | 24/5/2007 | 16/6/2026 | A cleanup script in crontabs in Apple Mac OS X 10.3.9 and 10.4.9 might delete filesystems that have been mounted in /tmp, which might allow local users to cause a denial of service, related to the find command. | |
| Modificada | Alta (7.2) | 0.93% | 💥 Exploit | Apple MAC OS XApple MAC OS X Server | 24/5/2007 | 16/6/2026 | Format string vulnerability in the VPN daemon (vpnd) in Apple Mac OS X 10.3.9 and 10.4.9 allows local users to execute arbitrary code via the -i parameter. | |
| Modificada | Alta (7.2) | 0.72% | 💥 Exploit | Apple MAC OS XApple MAC OS X Server | 24/5/2007 | 16/6/2026 | The PPP daemon (pppd) in Apple Mac OS X 10.4.8 checks ownership of the stdin file descriptor to determine if the invoker has sufficient privileges, which allows local users to load arbitrary plugins and gain root privileges by bypassing this check. | |
| Modificada | Alta (9.3) | 4.0% | — | Apple MAC OS XApple MAC OS X Server | 24/5/2007 | 16/6/2026 | Integer overflow in CoreGraphics in Apple Mac OS X 10.4 up to 10.4.9 allows remote user-assisted attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted PDF file. | |
| Modificada | Alta (7.1) | 0.81% | — | Apple MAC OS X Server | 2/5/2007 | 16/6/2026 | The Apple Security Update 2007-004 uses an incorrect configuration file for FTPServer in Apple Mac OS X Server 10.4.9, which might allow remote authenticated users to access additional directories. | |
| Modificada | Alta (9.3) | 3.6% | — | Apple MAC OS XApple MAC OS X Server | 24/4/2007 | 16/6/2026 | Use-after-free vulnerability in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving crafted web pages that trigger certain error conditions that are not properly reported in certain… | |
| Modificada | Alta (7.2) | 0.38% | — | Apple MAC OS XApple MAC OS X Server | 24/4/2007 | 16/6/2026 | SMB in Apple Mac OS X 10.3.9 through 10.4.9 does not properly clean the environment when executing commands, which allows local users to gain privileges by setting unspecified environment variables. | |
| Modificada | Alta (9.3) | 5.4% | — | Apple MAC OS XApple MAC OS X Server | 24/4/2007 | 16/6/2026 | Integer overflow in the RPC library in Libinfo in Apple Mac OS X 10.3.9 through 10.4.9 allows remote attackers to execute arbitrary code via crafted requests to portmap. |