Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.3)0.42%—MageiaGNU ReadlineOpensuseFedoraproject Fedora20/8/201417/6/2026
The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.
ModificadaMedia (6.8)4.7%—OpensuseIpython NotebookMageia7/8/201417/6/2026
IPython Notebook 0.12 through 1.x before 1.2 does not validate the origin of websocket requests, which allows remote attackers to execute arbitrary code by leveraging knowledge of the kernel id and a crafted page.
ModificadaAlta (7.5)2.4%—Ctdb Project CtdbOpensuseMageia6/8/201416/6/2026
ctdb before 2.3 in OpenSUSE 12.3 and 13.1 does not create temporary files securely, which has unspecified impact related to "several temp file vulnerabilities" in (1) tcp/tcp_connect.c, (2) server/eventscript.c, (3) tools/ctdb_diagnostics, (4) config/gdb_backtrace, and (5) include/ctdb_private.h.
ModificadaBaja (2.1)0.42%—Debian LinuxFreedesktop DbusMageia Project MageiaOpensuse19/7/201417/6/2026
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invalid file descriptor.
ModificadaBaja (2.1)0.45%—Freedesktop DbusOpensuseDebian LinuxMageia+119/7/201417/6/2026
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message…
ModificadaMedia (6.8)2.8%—Fedoraproject FedoraMageia Project MageiaCherokee-project Cherokee2/7/201417/6/2026
The cherokee_validator_ldap_check function in validator_ldap.c in Cherokee 1.2.103 and earlier, when LDAP is used, does not properly consider unauthenticated-bind semantics, which allows remote attackers to bypass authentication via an empty password.
ModificadaBaja (3.3)0.36%—Mageia Project MageiaGNU Emacs8/5/201417/6/2026
lisp/net/tramp-sh.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/tramp.##### temporary file.
ModificadaBaja (3.3)0.35%—Mageia Project MageiaGNU Emacs8/5/201417/6/2026
lisp/net/browse-url.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a /tmp/Mosaic.##### temporary file.
ModificadaBaja (3.3)0.34%—GNU EmacsMageia Project Mageia8/5/201417/6/2026
lisp/emacs-lisp/find-gc.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file under /tmp/esrc/.
ModificadaBaja (3.3)0.34%—Mageia Project MageiaGNU Emacs8/5/201417/6/2026
lisp/gnus/gnus-fun.el in GNU Emacs 24.3 and earlier allows local users to overwrite arbitrary files via a symlink attack on the /tmp/gnus.face.ppm temporary file.
Orbitaley — Vulnerabilidades