Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | Apple MAC OS XApple MAC OS X Server | 1/7/2014 | 17/6/2026 | Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandboxed application for sending a message. | |
| Modificada | Media (6.8) | 2.2% | — | Apple MAC OS XApple MAC OS X Server | 1/7/2014 | 17/6/2026 | The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archive. | |
| Modificada | Media (4.3) | 1.9% | — | Apple Iphone OSApple MAC OS XApple MAC OS X ServerApple Tvos | 23/4/2014 | 17/6/2026 | CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during… | |
| Modificada | Media (5) | 53% | — | Apache Http ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+11 | 15/4/2014 | 16/6/2026 | The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such." | |
| Modificada | Media (4.6) | 0.48% | — | Apple MAC OS XApple MAC OS X ServerPostgresql | 31/3/2014 | 17/6/2026 | The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster. | |
| Modificada | Media (6.8) | 2.2% | — | Apple SafariApple WebkitApple MAC OS XApple MAC OS X Server | 27/2/2014 | 17/6/2026 | WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269. | |
| Modificada | Media (6.8) | 2.2% | — | Apple SafariApple WebkitApple MAC OS XApple MAC OS X Server | 27/2/2014 | 17/6/2026 | WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1270. | |
| Modificada | Media (6.8) | 1.9% | — | Apple SafariApple WebkitApple MAC OS XApple MAC OS X Server | 27/2/2014 | 17/6/2026 | WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1269 and CVE-2014-1270. | |
| Modificada | Media (4.6) | 0.34% | — | Apple MAC OS XApple MAC OS X Server | 27/2/2014 | 17/6/2026 | The systemsetup program in the Date and Time subsystem in Apple OS X before 10.9.2 allows local users to bypass intended access restrictions by changing the current time on the system clock. | |
| Modificada | Media (6.8) | 1.8% | — | Apple MAC OS XApple MAC OS X Server | 27/2/2014 | 17/6/2026 | Buffer overflow in File Bookmark in Apple OS X before 10.9.2 allows attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted filename. | |
| Modificada | Alta (7.5) | 1.3% | — | Apple MAC OS XApple MAC OS X Server | 27/2/2014 | 17/6/2026 | Buffer overflow in Apple Type Services (ATS) in Apple OS X before 10.9.2 allows attackers to bypass the App Sandbox protection mechanism via crafted Mach messages. | |
| Modificada | Media (6.8) | 0.55% | — | Apple OS X Server | 24/10/2013 | 16/6/2026 | The RADIUS service in Server App in Apple OS X Server before 3.0 selects a fallback X.509 certificate in unspecified circumstances, which might allow man-in-the-middle attackers to hijack RADIUS sessions by leveraging knowledge of the private key that matches this fallback certificate. | |
| Modificada | Media (4.3) | 2.0% | — | Apple OS X Server | 19/9/2013 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Wiki Server in Apple Mac OS X Server before 2.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 2.9% | — | Apple MAC OS XApple MAC OS X Server | 5/6/2013 | 16/6/2026 | CoreMedia Playback in Apple Mac OS X before 10.8.4 does not properly initialize memory during the processing of text tracks, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file. | |
| Modificada | Media (4.9) | 1.2% | — | Apple MAC OS XApple MAC OS X Server | 5/6/2013 | 16/6/2026 | SMB in Apple Mac OS X before 10.8.4, when file sharing is enabled, allows remote authenticated users to create or modify files outside of a shared directory via unspecified vectors. | |
| Modificada | Alta (9.3) | 14% | 💥 Exploit | Apple MAC OS XApple MAC OS X Server | 5/6/2013 | 16/6/2026 | Directory Service in Apple Mac OS X through 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted message. | |
| Modificada | Baja (1.7) | 0.34% | — | Apple MAC OS XApple MAC OS X Server | 5/6/2013 | 16/6/2026 | The Private Browsing feature in CFNetwork in Apple Mac OS X before 10.8.4 does not prevent storage of permanent cookies upon exit from Safari, which might allow physically proximate attackers to bypass cookie-based authentication by leveraging an unattended workstation. | |
| Modificada | Media (6.8) | 2.8% | — | Apple MAC OS XApple MAC OS X Server | 5/6/2013 | 16/6/2026 | Buffer overflow in QuickDraw Manager in Apple Mac OS X before 10.8.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PICT image. | |
| Modificada | Media (6.8) | 1.2% | — | Apple MAC OS XApple MAC OS X Server | 15/3/2013 | 16/6/2026 | Software Update in Apple Mac OS X through 10.7.5 does not prevent plugin loading within the marketing-text WebView, which allows man-in-the-middle attackers to execute plugin code by modifying the client-server data stream. | |
| Modificada | Media (6.8) | 1.8% | — | Apple MAC OS XApple MAC OS X Server | 15/3/2013 | 16/6/2026 | Use-after-free vulnerability in PDFKit in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted ink annotations in a PDF document. | |
| Modificada | Media (4.3) | 1.5% | — | Apple MAC OS XApple MAC OS X Server | 15/3/2013 | 16/6/2026 | CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which allows remote attackers to bypass a Java plug-in disabled setting, and trigger the launch of Java Web Start applications, via a crafted web site. | |
| Modificada | Media (6.4) | 1.7% | — | Apple MAC OS XApple MAC OS X Server | 15/3/2013 | 16/6/2026 | The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI. | |
| Modificada | Media (6.5) | 3.1% | — | PostgresqlOpensuseApple MAC OS X ServerCanonical Ubuntu Linux+5 | 3/10/2012 | 16/6/2026 | The xml_parse function in the libxml2 support in the core server component in PostgreSQL 8.3 before 8.3.20, 8.4 before 8.4.13, 9.0 before 9.0.9, and 9.1 before 9.1.5 allows remote authenticated users to determine the existence of arbitrary files or URLs, and possibly obtain file or URL content that triggers a parsing… | |
| Modificada | Media (4.6) | 0.40% | — | Apple MAC OS XApple MAC OS X Server | 20/9/2012 | 16/6/2026 | Apple Mac OS X before 10.7.5 does not properly handle the bNbrPorts field of a USB hub descriptor, which allows physically proximate attackers to execute arbitrary code or cause a denial of service (memory corruption and system crash) by attaching a USB device. | |
| Modificada | Media (6.8) | 2.9% | — | Apple MAC OS XApple MAC OS X ServerApple Iphone OS | 20/9/2012 | 16/6/2026 | The Sorenson codec in QuickTime in Apple Mac OS X before 10.7.5, and in CoreMedia in iOS before 6, accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding. |