Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
519 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.4% | — | Ethereal Group EtherealSGI PropackConectiva LinuxAltlinux ALT Linux+5 | 15/12/2004 | 16/6/2026 | Ethereal 0.9.0 through 0.10.7 allows remote attackers to cause a denial of service (CPU consumption) via a certain malformed SMB packet. | |
| Modificada | Media (5) | 4.1% | — | Ethereal Group EtherealSGI PropackConectiva LinuxAltlinux ALT Linux+5 | 15/12/2004 | 16/6/2026 | Multiple vulnerabilities in Konqueror in KDE 3.3.1 and earlier (1) allow access to restricted Java classes via JavaScript and (2) do not properly restrict access to certain Java classes from the Java applet, which allows remote attackers to bypass sandbox restrictions and read or write arbitrary files. | |
| Modificada | Media (5) | 2.4% | — | Ethereal Group EtherealSGI PropackConectiva LinuxAltlinux ALT Linux+5 | 15/12/2004 | 16/6/2026 | Unknown vulnerability in the DICOM dissector in Ethereal 0.10.4 through 0.10.7 allows remote attackers to cause a denial of service (application crash). | |
| Modificada | Media (5) | 2.8% | — | Conectiva LinuxGentoo LinuxLinux KernelSuse Linux | 6/12/2004 | 16/6/2026 | The tcp_find_option function of the netfilter subsystem in Linux kernel 2.6, when using iptables and TCP options rules, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a large option length that produces a negative integer after a casting operation to the char type. | |
| Modificada | Baja (2.1) | 0.80% | 💥 Exploit | Mandrakesoft Mandrake Multi Network FirewallConectiva LinuxGentoo LinuxLinux Kernel+5 | 6/12/2004 | 16/6/2026 | Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4. | |
| Modificada | Alta (7.2) | 0.39% | — | Mandrakesoft Mandrake Multi Network FirewallSuse Email ServerSuse Linux Connectivity ServerSuse Linux Database Server+9 | 6/12/2004 | 16/6/2026 | Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool. | |
| Modificada | Alta (7.5) | 8.1% | — | X.org X11r6Xfree86 Project X11r6OpenbsdSuse Linux | 20/10/2004 | 16/6/2026 | Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file. | |
| Modificada | Alta (7.5) | 7.2% | — | X.org X11r6Xfree86 Project X11r6OpenbsdSuse Linux | 20/10/2004 | 16/6/2026 | Multiple integer overflows in (1) the xpmParseColors function in parse.c, (2) XpmCreateImageFromXpmImage, (3) CreateXImage, (4) ParsePixels, and (5) ParseAndPutPixels for libXpm before 6.8.1 may allow remote attackers to execute arbitrary code via a malformed XPM image file. | |
| Modificada | Alta (7.5) | 1.9% | — | KDE KonquerorGentoo LinuxKDEMandrakesoft Mandrake Linux+1 | 20/10/2004 | 16/6/2026 | Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. | |
| Modificada | Alta (7.5) | 3.9% | — | Cyrus SaslOpenpkgSuse CvsupConectiva Linux+4 | 7/10/2004 | 16/6/2026 | Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (7.5) | 10% | — | KDE KonquerorMicrosoft IEMicrosoft Internet ExplorerMozilla Firefox+1 | 16/9/2004 | 16/6/2026 | Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. | |
| Modificada | Alta (7.5) | 5.5% | — | Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+10 | 16/9/2004 | 16/6/2026 | Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files. | |
| Modificada | Media (4.6) | 3.0% | — | Mozilla FirefoxMozillaNetscape NavigatorConectiva Linux+6 | 14/9/2004 | 16/6/2026 | Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain. | |
| Modificada | Media (5) | 5.5% | — | SambaSGI SambaConectiva LinuxMandrakesoft Mandrake Linux+1 | 13/9/2004 | 16/6/2026 | Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop. | |
| Modificada | Alta (10) | 45% | — | Infoblox DNS ONE ApplianceISC DhcpdSuse Email ServerSuse Linux Admin-cd FOR Firewall+7 | 6/8/2004 | 16/6/2026 | Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which… | |
| Modificada | Baja (2.1) | 0.47% | — | Mandrakesoft Mandrake Multi Network FirewallSuse Email ServerSuse Linux Admin-cd FOR FirewallSuse Linux Connectivity Server+13 | 6/8/2004 | 16/6/2026 | The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources. | |
| Modificada | Alta (7.2) | 0.42% | — | Avaya Converged Communications ServerAvaya Modular Messaging Message Storage ServerGentoo LinuxLinux Kernel+14 | 6/8/2004 | 16/6/2026 | Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool. | |
| Modificada | Baja (2.1) | 0.87% | 💥 Exploit | Avaya Converged Communications ServerAvaya Modular Messaging Message Storage ServerGentoo LinuxLinux Kernel+14 | 6/8/2004 | 16/6/2026 | Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program. | |
| Modificada | Baja (2.1) | 0.41% | — | Mandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Fedora CoreSuse Linux | 6/8/2004 | 16/6/2026 | Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service. | |
| Modificada | Alta (10) | 17% | — | Infoblox DNS ONE ApplianceISC DhcpdSuse Email ServerSuse Linux Admin-cd FOR Firewall+7 | 6/8/2004 | 16/6/2026 | The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and… | |
| Modificada | Alta (10) | 3.6% | — | Suse Linux | 6/5/2004 | 16/6/2026 | The Live CD in SUSE LINUX 9.1 Personal edition is configured without a password for root, which allows remote attackers to gain privileges via SSH. | |
| Modificada | Baja (2.1) | 0.76% | 💥 Exploit | Suse Linux | 17/2/2004 | 16/6/2026 | The SuSEconfig.gnome-filesystem script for YaST in SuSE 9.0 allows local users to overwrite arbitrary files via a symlink attack on files within the tmp.SuSEconfig.gnome-filesystem.$RANDOM temporary directory. | |
| Modificada | Baja (2.1) | 0.36% | — | Redhat Enterprise LinuxSuse Linux | 31/12/2003 | 16/6/2026 | Unspecified vulnerability in xscreensaver 4.12, and possibly other versions, allows attackers to cause xscreensaver to crash via unspecified vectors "while verifying the user-password." | |
| Modificada | Media (6.4) | 2.5% | — | Suse Linux Openexchange ServerSuse Office ServerSuse Linux | 31/12/2003 | 16/6/2026 | susehelp in SuSE Linux 8.1, Enterprise Server 8, Office Server, and Openexchange Server 4 does not properly filter shell metacharacters, which allows remote attackers to execute arbitrary commands via CGI queries. | |
| Modificada | Media (4.6) | 0.70% | 💥 Exploit | Suse Linux | 17/11/2003 | 16/6/2026 | SuSEconfig.susewm in the susewm package on SuSE Linux 8.2Pro allows local users to overwrite arbitrary files via a symlink attack on the susewm.$$ temporary file. |