Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

46 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)5.8%—Xfree86 Project X11r6Netbsd20/10/200316/6/2026
Multiple integer overflows in the font libraries for XFree86 4.3.0 allow local or remote attackers to cause a denial of service or execute arbitrary code via heap-based and stack-based buffer overflow attacks.
ModificadaBaja (3.6)0.38%—Xfree86 Project Xfree86 X Server24/7/200316/6/2026
dexconf in XFree86 Xserver 4.1.0-2 creates the /dev/dri directory with insecure permissions (666), which allows local users to replace or create files in the root file system.
ModificadaAlta (7.3)3.4%—Xfree86 Project X11r63/3/200316/6/2026
The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal, e.g. when the user views a file containing the malicious sequence, which could allow the attacker to execute…
ModificadaAlta (7.2)0.37%—Xfree86 Project X11r63/3/200316/6/2026
Untrusted search path vulnerability in libX11.so in xfree86, when used in setuid or setgid programs, allows local users to gain root privileges via a modified LD_PRELOAD environment variable that points to a malicious module.
ModificadaBaja (2.1)0.42%—Xfree86 Project X11r63/3/200316/6/2026
The DEC UDK processing feature in the xterm terminal emulator in XFree86 4.2.99.4 and earlier allows attackers to cause a denial of service via a certain character escape sequence that causes the terminal to enter a tight loop.
ModificadaAlta (10)2.0%—Xfree86 Project X11r63/3/200316/6/2026
xdm, with the authComplain variable set to false, allows arbitrary attackers to connect to the X server if the xdm auth directory does not exist.
ModificadaAlta (7.5)24%💥 ExploitXfree86 Project X11r6SGI IrixHp-uxSUN Solaris+111/12/200216/6/2026
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a certain XFS query.
ModificadaAlta (7.2)0.45%—Xfree86 Project X11r622/9/200116/6/2026
Buffer overflow in fbglyph.c in XFree86 before 4.2.0, related to glyph clipping for large origins, allows attackers to cause a denial of service and possibly gain privileges via a large number of characters, possibly through the web page search form of KDE Konqueror or from an xterm command with a long title.
ModificadaAlta (7.2)0.44%—Xfree86 Project X11r617/7/200116/6/2026
xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters.
ModificadaAlta (7.2)0.77%💥 ExploitXfree86 Project X11r611/7/200116/6/2026
Buffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable.
ModificadaAlta (7.5)2.8%💥 ExploitXfree86 Project X11r64/7/200116/6/2026
XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.
ModificadaMedia (4.6)0.97%💥 ExploitXfree86 Project Xlib19/12/200023/9/2026
Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY environment variable or a -display command line parameter.
ModificadaMedia (4.6)0.34%—Xfree86 Project Xfce11/12/200016/6/2026
The default configuration of XFCE 3.5.1 bypasses the Xauthority access control mechanism with an "xhost + localhost" command in the xinitrc program, which allows local users to sniff X Windows traffic and gain privileges.
ModificadaMedia (5)3.3%💥 ExploitGnome GDMOpen Group XXfree86 Project X11r619/6/200016/6/2026
libICE in XFree86 allows remote attackers to cause a denial of service by specifying a large value which is not properly checked by the SKIP_STRING macro.
ModificadaMedia (5)1.7%—Open Group XXfree86 Project X11r619/6/200016/6/2026
libX11 X library allows remote attackers to cause a denial of service via a resource mask of 0, which causes libX11 to go into an infinite loop.
ModificadaMedia (5)2.5%💥 ExploitMichael Jennings EtermPuttyRxvtXfree86 Project X11r61/6/200016/6/2026
xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized.
ModificadaMedia (5)3.0%💥 ExploitXfree86 Project X11r618/5/200016/6/2026
XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000.
ModificadaAlta (7.2)0.54%—Xfree86 Project X11r616/4/200016/6/2026
Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.
ModificadaMedia (4.6)0.71%💥 ExploitXfree86 Project X11r6NetbsdRedhat LinuxSlackware Linux+121/3/199916/6/2026
XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
ModificadaAlta (7.2)0.80%💥 ExploitXfree86 Project Xfree863/5/199816/6/2026
SGI IRIX buffer overflow in xterm and Xaw allows root access.
ModificadaAlta (10)4.3%—Xfree86 Project X11r6SGI IrixSUN SolarisSunos1/11/199516/6/2026
Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.
Orbitaley — Vulnerabilidades