Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

135 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)64%💥 ExploitArchive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+1927/1/200516/6/2026
McAfee Anti-Virus Engine DATS drivers before 4398 released on Oct 13th 2004 and DATS Driver before 4397 October 6th 2004 allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target…
ModificadaAlta (7.5)21%💥 ExploitArchive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+1927/1/200516/6/2026
Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file…
ModificadaMedia (5)5.4%—LibtiffPdflib PDF LibraryWxgtk2Apple MAC OS X+927/1/200516/6/2026
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
ModificadaAlta (7.5)15%💥 ExploitArchive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+1927/1/200516/6/2026
RAV antivirus allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
ModificadaAlta (7.5)15%💥 ExploitArchive ZIPBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus Gateway+1927/1/200516/6/2026
Eset Anti-Virus before 1.020 (16th September 2004) allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
ModificadaAlta (10)5.2%—MplayerXineXine-libMandrakesoft Mandrake Linux10/1/200516/6/2026
Heap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote attackers to execute arbitrary code via long PNA_TAG values, a different vulnerability than CVE-2004-1188.
ModificadaAlta (7.5)2.7%—KDE KonquerorMandrakesoft Mandrake LinuxRedhat Fedora Core10/1/200516/6/2026
Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection"…
ModificadaAlta (7.5)1.6%—Roaring Penguin MimedefangMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerSuse Linux10/1/200516/6/2026
MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an e-mail attachment with a virus that contains an empty boundary string in the Content-Type header.
ModificadaAlta (7.5)19%💥 ExploitBroadcom Brightstor Arcserve BackupBroadcom Etrust AntivirusBroadcom Etrust Antivirus GatewayBroadcom Etrust EZ Antivirus+1810/1/200516/6/2026
Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
ModificadaMedia (5)2.4%—Nfs-utilsDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+210/1/200516/6/2026
statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
ModificadaAlta (10)2.0%—MplayerXineXine-libMandrakesoft Mandrake Linux10/1/200516/6/2026
The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREAMBLE_SIZE, which causes a read operation with a negative length that leads to a buffer overflow via (1) RMF_TAG, (2) DATA_TAG, (3)…
ModificadaBaja (2.1)0.45%—KDEMandrakesoft Mandrake LinuxRedhat Fedora Core10/1/200516/6/2026
KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames…
ModificadaMedia (5)1.5%—Mandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server31/12/200416/6/2026
libuser 0.51.7 allows attackers to cause a denial of service (crash or disk consumption) via unknown attack vectors, related to read failures and other bugs.
ModificadaMedia (5.1)3.4%—Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+1231/12/200416/6/2026
Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.
ModificadaBaja (2.1)0.36%—Mandrakesoft Mandrake Multi Network FirewallMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server31/12/200416/6/2026
Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.
ModificadaBaja (2.1)0.34%—Mandrakesoft Mandrake Multi Network FirewallMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server31/12/200416/6/2026
Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of failed read attempts from the password buffer.
ModificadaAlta (7.5)4.9%—Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+1231/12/200416/6/2026
Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.
ModificadaAlta (7.2)0.43%—Mandrakesoft Mandrake Multi Network FirewallSpeedtouch USB DriverGentoo LinuxMandrakesoft Mandrake Linux+123/12/200416/6/2026
Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.
ModificadaAlta (7.5)3.8%—Mpg123Mandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server23/12/200416/6/2026
Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) mp2 file.
ModificadaAlta (7.5)8.3%—LibtiffPdflib PDF LibraryWxgtk2Apple MAC OS X+923/12/200416/6/2026
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
ModificadaAlta (7.5)6.3%—Avaya Call Management System ServerAvaya CvlanAvaya Integrated ManagementAvaya Interactive Response+1521/12/200416/6/2026
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
ModificadaMedia (5)5.3%—Ethereal Group EtherealGentoo LinuxMandrakesoft Mandrake LinuxRedhat Enterprise Linux+16/12/200416/6/2026
The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.
ModificadaMedia (5)5.3%—Ethereal Group EtherealGentoo LinuxMandrakesoft Mandrake LinuxRedhat Enterprise Linux+16/12/200416/6/2026
The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a denial of service (process crash) via a handle without a policy name, which causes a null dereference.
ModificadaAlta (7.2)0.39%—Mandrakesoft Mandrake Multi Network FirewallSuse Email ServerSuse Linux Connectivity ServerSuse Linux Database Server+96/12/200416/6/2026
Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.
ModificadaBaja (2.1)0.44%—Mandrakesoft Mandrake Multi Network FirewallGentoo LinuxLinux KernelMandrakesoft Mandrake Linux+26/12/200416/6/2026
Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.
Orbitaley — Vulnerabilidades