Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 23% | 💥 Exploit | Apple MAC OS XApple MAC OS X Server | 19/12/2007 | 16/6/2026 | Software Update in Apple Mac OS X 10.5.1 allows remote attackers to execute arbitrary commands via a man-in-the-middle (MITM) attack between the client and the server, using a modified distribution definition file with the "allow-external-scripts" option. | |
| Modificada | Alta (7.2) | 0.40% | — | Apple MAC OS XApple MAC OS X Server | 19/12/2007 | 16/6/2026 | Unspecified vulnerability in Spin Tracer in Apple Mac OS X 10.5.1 allows local users to execute arbitrary code via unspecified output files, involving an "insecure file operation." | |
| Modificada | Alta (7.8) | 9.1% | 💥 Exploit | Apple MAC OS XApple MAC OS X Server | 7/12/2007 | 16/6/2026 | The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows remote attackers to cause a denial of service (divide-by-zero error and daemon crash) via a crafted load balancing packet to UDP port 4112. | |
| Modificada | Alta (10) | 2.6% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | The Application Firewall in Apple Mac OS X 10.5 does not prevent a root process from accepting incoming connections, even when "Block incoming connections" has been set for its associated executable, which might allow remote attackers or local root processes to bypass intended access restrictions. | |
| Modificada | Alta (9.3) | 2.2% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | The Application Firewall in Apple Mac OS X 10.5, when "Block all incoming connections" is enabled, does not prevent root processes or mDNSResponder from accepting connections, which might allow remote attackers or local root processes to bypass intended access restrictions. | |
| Modificada | Baja (2.1) | 0.34% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | WebKit on Apple Mac OS X 10.4 through 10.4.10 does not create temporary files securely when Safari is previewing a PDF file, which allows local users to read the contents of that file. | |
| Modificada | Alta (7.5) | 2.1% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Unspecified vulnerability in WebKit on Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to use Safari as an indirect proxy and send attacker-controlled data to arbitrary TCP ports via unknown vectors. | |
| Modificada | Alta (10) | 2.1% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | The NSURL component in Apple Mac OS X 10.4 through 10.4.10 performs case-sensitive comparisons that allow attackers to bypass intended restrictions for local file system URLs. | |
| Modificada | Alta (7.1) | 2.1% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | AppleRAID in Apple Mac OS X 10.3.9 and 10.4 through 10.4.10 allows attackers to cause a denial of service (crash) via a crafted striped disk image, which triggers a NULL pointer dereference when it is mounted. | |
| Modificada | Alta (10) | 7.3% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Double free vulnerability in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (system shutdown) or execute arbitrary code via crafted IPV6 packets. | |
| Modificada | Media (4.3) | 1.1% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Race condition in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain information for forms from other sites via unknown vectors related to "page transitions" in Safari. | |
| Modificada | Alta (7.2) | 0.34% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | The kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to gain privileges by executing setuid or setgid programs in which the stdio, stderr, or stdout file descriptors are "in an unexpected state." | |
| Modificada | Media (5) | 1.8% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | The Networking component in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to obtain all addresses for a host, including link-local addresses, via a Node Information Query. | |
| Modificada | Alta (9.3) | 1.7% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | The remote_cmds component in Apple Mac OS X 10.4 through 10.4.10 contains a symbolic link from the tftpboot private directory to the root directory, which allows tftpd users to escape the private directory and access arbitrary files. | |
| Modificada | Media (4.3) | 1.5% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Safari in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to access local content via file:// URLs. | |
| Modificada | Alta (7.2) | 0.49% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Integer overflow in the Networking component in Apple Mac OS X 10.4 through 10.4.10 allows local users to execute arbitrary code via a crafted AppleTalk Session Protocol (ASP) message on an AppleTalk socket, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.2) | 0.39% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | The SecurityAgent component in Mac OS X 10.4 through 10.4.10 allows attackers with physical access to bypass the authentication dialog of the screen saver and send keystrokes to a process, related to "handling of keyboard focus between secure text fields." | |
| Modificada | Alta (7.2) | 0.37% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Integer signedness error in the ttioctl function in bsd/kern/tty.c in the xnu kernel in Apple Mac OS X 10.4 through 10.4.10 allows local users to cause a denial of service (system shutdown) or gain privileges via a crafted TIOCSETD ioctl request. | |
| Modificada | Media (6.8) | 3.0% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Unspecified vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via unknown vectors related to browser history, which triggers memory corruption. | |
| Modificada | Alta (9) | 4.0% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Double free vulnerability in the NFS component in Apple Mac OS X 10.4 through 10.4.10 allows remote authenticated users to execute arbitrary code via a crafted AUTH_UNIX RPC packet. | |
| Modificada | Media (4.3) | 1.5% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2007 | 16/6/2026 | Unspecified "input validation" vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10 allows remote attackers to modify form field values via unknown vectors related to file uploads. | |
| Modificada | Media (6.4) | 2.5% | — | Pcre Perl-compatible Regular Expression LibraryApple MAC OS XApple MAC OS X Server | 7/11/2007 | 16/6/2026 | Perl-Compatible Regular Expression (PCRE) library before 7.3 backtracks too far when matching certain input bytes against some regex patterns in non-UTF-8 mode, which allows context-dependent attackers to obtain sensitive information or cause a denial of service (crash), as demonstrated by the "\X?\d" and "\P{L}?\d"… | |
| Modificada | Media (5) | 1.4% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2007 | 16/6/2026 | CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks. | |
| Modificada | Media (5.8) | 6.9% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2007 | 16/6/2026 | Heap-based buffer overflow in the UPnP IGD (Internet Gateway Device Standardized Device Control Protocol) implementation in mDNSResponder on Apple Mac OS X 10.4.10 before 20070731 allows network-adjacent remote attackers to execute arbitrary code via a crafted packet. | |
| Modificada | Crítica (9.8) | 70% | 💥 Exploit | TcpdumpCanonical Ubuntu LinuxDebian LinuxSlackware+3 | 16/7/2007 | 16/6/2026 | Integer overflow in print-bgp.c in the BGP dissector in tcpdump 3.9.6 and earlier allows remote attackers to execute arbitrary code via crafted TLVs in a BGP packet, related to an unchecked return value. |