Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

86 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)3.0%—Ascii PtexCstex CstetexEasy Software Products CupsGnome Gpdf+1827/4/200516/6/2026
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
ModificadaAlta (7.5)3.0%—KDE QuantaConectiva LinuxGentoo LinuxKDE+222/4/200516/6/2026
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
ModificadaMedia (6.2)2.9%—Avaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+1614/4/200516/6/2026
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
ModificadaAlta (7.2)0.85%—Conectiva LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+427/3/200516/6/2026
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
ModificadaBaja (2.1)2.1%—Conectiva LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+19/3/200516/6/2026
Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.
ModificadaMedia (5.1)3.2%—SylpheedSylpheed-clawsAltlinux ALT LinuxGentoo Linux+37/3/200516/6/2026
Buffer overflow in Sylpheed before 1.0.3 and other versions before 1.9.5 allows remote attackers to execute arbitrary code via an e-mail message with certain headers containing non-ASCII characters that are not properly handled when the user replies to the message.
ModificadaMedia (5.6)0.51%—FreebsdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+45/3/200516/6/2026
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack…
ModificadaAlta (7.5)4.5%—LesstifSGI PropackX.org X11r6Xfree86 Project X11r6+72/3/200516/6/2026
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
ModificadaAlta (10)22%—Xmlsoft LibxmlXmlsoft Libxml2Xmlstarlet Command Line XML ToolkitRedhat Fedora Core+21/3/200516/6/2026
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the…
ModificadaAlta (7.5)1.9%—Suse IptablesDebian LinuxLinux KernelRedhat Fedora Core1/3/200516/6/2026
Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.
ModificadaMedia (5)3.2%—FreeradiusRedhat Enterprise LinuxRedhat Fedora Core9/2/200516/6/2026
FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.
ModificadaMedia (5)3.3%—FreeradiusRedhat Enterprise LinuxRedhat Fedora Core9/2/200516/6/2026
Memory leak in FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (memory exhaustion) via a series of Access-Request packets with (1) Ascend-Send-Secret, (2) Ascend-Recv-Secret, or (3) Tunnel-Password attributes.
ModificadaBaja (2.1)0.39%—Netatalk Open Source Apple File Share Protocol SuiteMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Fedora Core9/2/200516/6/2026
The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
ModificadaBaja (2.1)1.3%—Larry Wall PerlSGI PropackIBM AIXRedhat Enterprise Linux+57/2/200516/6/2026
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
ModificadaAlta (10)9.5%—Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+1227/1/200516/6/2026
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
ModificadaAlta (10)6.2%—Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+1227/1/200516/6/2026
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
ModificadaAlta (10)10%—MozillaMozilla ThunderbirdConectiva LinuxRedhat Enterprise Linux+527/1/200516/6/2026
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3…
ModificadaMedia (5)5.4%—LibtiffPdflib PDF LibraryWxgtk2Apple MAC OS X+927/1/200516/6/2026
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
ModificadaAlta (10)14%—SambaConectiva LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+327/1/200516/6/2026
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.
ModificadaMedia (5)4.9%—SambaSGI SambaConectiva LinuxGentoo Linux+427/1/200516/6/2026
The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.
ModificadaAlta (10)9.7%—MozillaMozilla ThunderbirdConectiva LinuxRedhat Enterprise Linux+527/1/200516/6/2026
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.
ModificadaMedia (5)16%—OpenpkgSquidGentoo LinuxRedhat Fedora Core+227/1/200516/6/2026
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.
ModificadaMedia (4.6)1.2%—GNU EnscriptSGI PropackRedhat Fedora CoreSuse Linux21/1/200516/6/2026
The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
ModificadaAlta (10)6.0%—Carnegie Mellon University Cyrus Imap ServerOpenpkgConectiva LinuxRedhat Fedora Core+210/1/200516/6/2026
The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and earlier allows remote authenticated users to execute arbitrary code via a certain command ("body[p") that is treated as a different command ("body.peek") and causes an index increment error that leads to an out-of-bounds memory corruption.
ModificadaMedia (5)9.0%—Easy Software Products CupsRedhat Fedora Core10/1/200516/6/2026
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail.