Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
34 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.44% | — | Kernel Util-linuxLoop-aes-utils Project Loop-aes-utilsFedoraproject FedoraCanonical Ubuntu Linux+1 | 4/10/2007 | 16/6/2026 | mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs. | |
| Modificada | Media (4.1) | 0.35% | — | Andries Brouwer Util-linux | 4/3/2007 | 16/6/2026 | login in util-linux-2.12a skips pam_acct_mgmt and chauth_tok when authentication is skipped, such as when a Kerberos krlogin session has been established, which might allow users to bypass intended access policies that would be enforced by pam_acct_mgmt and chauth_tok. | |
| Modificada | Alta (7.2) | 0.43% | — | Andries Brouwer Util-linux | 13/9/2005 | 16/6/2026 | umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages such as loop-aes-utils, allows local users with unmount permissions to gain privileges via the -r (remount) option, which causes the file system to be remounted with just the read-only flag, which effectively clears the nosuid, nodev, and… | |
| Modificada | Media (5) | 3.3% | — | Andries Brouwer Util-linux | 3/3/2004 | 16/6/2026 | The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data. | |
| Modificada | Media (5) | 1.6% | — | Andries Brouwer Util-linux | 3/3/2003 | 16/6/2026 | A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed. | |
| Modificada | Alta (7.2) | 0.43% | — | Andries Brouwer Util-linux | 1/4/2002 | 16/6/2026 | vipw in the util-linux package before 2.10 causes /etc/shadow to be world-readable in some cases, which would make it easier for local users to perform brute force password guessing. | |
| Modificada | Media (5.5) | 0.43% | — | Kernel Util-linuxAvaya CvlanAvaya Integrated Management SuitAvaya Interactive Response+3 | 31/12/2001 | 16/6/2026 | script command in the util-linux package before 2.11n allows local users to overwrite arbitrary files by setting a hardlink from the typescript log file to any file on the system, then having root execute the script command. | |
| Modificada | Alta (7.2) | 0.43% | — | Andries Brouwer Util-linux | 8/10/2001 | 16/6/2026 | The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials of one user to a different user, when used in certain PAM modules such as pam_limits. | |
| Modificada | Alta (10) | 54% | — | TCP WrappersAIWuftpdAIIrciiAISendmailAI+2 | 1/1/1999 | 16/6/2026 | A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such as (1) TCP Wrappers 7.6, (2) util-linux 2.9g, (3) wuarchive ftpd (wuftpd) 2.2 and 2.1f, (4) IRC client (ircII) ircII 2.2.9, (5) OpenSSH 3.4p1, or (6) Sendmail 8.12.6. |