Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
656 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.50% | — | Apple MAC OS XApple MAC OS X Server | 21/9/2006 | 16/6/2026 | Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow physically proximate attackers to cause a denial of service (crash) or execute arbitrary code in third-party wireless software that uses the API via crafted frames. | |
| Modificada | Alta (7.2) | 1.5% | 💥 Exploit | Apple MAC OS XApple MAC OS X Server | 21/9/2006 | 16/6/2026 | Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10.4.7 allow physically proximate attackers to execute arbitrary code by injecting crafted frames into a wireless network. | |
| Modificada | Alta (7.2) | 0.56% | — | Apple MAC OS XApple MAC OS X Server | 21/9/2006 | 16/6/2026 | Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically proximate attackers to cause a denial of service (crash), gain privileges, and execute arbitrary code via a crafted frame that is not properly handled during scan cache updates. | |
| Modificada | Media (4.6) | 0.98% | 💥 Exploit | Apple MAC OS XApple MAC OS X Server | 19/9/2006 | 16/6/2026 | Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument. | |
| Modificada | Alta (7.5) | 12% | — | ISC BindCanonical Ubuntu LinuxApple MAC OS XApple MAC OS X Server | 6/9/2006 | 16/6/2026 | BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned. | |
| Modificada | Media (4.6) | 0.49% | — | Apple XsanApple MAC OS XApple MAC OS X Server | 21/8/2006 | 16/6/2026 | Buffer overflow in the Xsan Filesystem driver on Mac OS X 10.4.7 and OS X Server 10.4.7 allows local users with Xsan write access, to execute arbitrary code via unspecified vectors related to "processing a path name." | |
| Modificada | Media (5.1) | 55% | 💥 Exploit | Apple MAC OS XApple MAC OS X Server | 5/8/2006 | 16/6/2026 | The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to execute arbitrary code via crafted file types. | |
| Modificada | Media (5.1) | 2.7% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2006 | 16/6/2026 | Unspecified vulnerability in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image that triggers a memory allocation failure that is not properly handled. | |
| Modificada | Media (5.1) | 1.5% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2006 | 16/6/2026 | The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari. | |
| Modificada | Alta (7.5) | 4.1% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2006 | 16/6/2026 | WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML document that causes WebKit to access an object that has already been deallocated. | |
| Modificada | Media (5.1) | 2.7% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2006 | 16/6/2026 | Integer overflow in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed GIF image. | |
| Modificada | Media (5.1) | 3.2% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2006 | 16/6/2026 | Buffer overflow in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Canon RAW image. | |
| Modificada | Baja (2.1) | 0.35% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2006 | 16/6/2026 | The dynamic linker (dyld) in Apple Mac OS X 10.3.9 allows local users to obtain sensitive information via unspecified dynamic linker options that affect the use of standard error (stderr) by privileged applications. | |
| Modificada | Alta (7.2) | 0.41% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2006 | 16/6/2026 | The dynamic linker (dyld) in Apple Mac OS X 10.4.7 allows local users to execute arbitrary code via an "improperly handled condition" that leads to use of "dangerous paths," probably related to an untrusted search path vulnerability. | |
| Modificada | Media (4) | 2.0% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2006 | 16/6/2026 | OpenSSH in Apple Mac OS X 10.4.7 allows remote attackers to cause a denial of service or determine account existence by attempting to log in using an invalid user, which causes the server to hang. | |
| Modificada | Media (5.1) | 2.7% | — | Apple MAC OS XApple MAC OS X Server | 3/8/2006 | 16/6/2026 | Integer overflow in ImageIO for Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Radiance image. | |
| Modificada | Media (5) | 1.9% | — | Apple MAC OS XApple MAC OS X Server | 2/8/2006 | 16/6/2026 | Unspecified vulnerability in AFP Server in Apple Mac OS X 10.3.9 allows remote attackers to determine names of unauthorized files and folders via unknown vectors related to the search results. | |
| Modificada | Media (5) | 3.0% | — | Apple MAC OS XApple MAC OS X Server | 2/8/2006 | 16/6/2026 | AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (crash) via an invalid AFP request that triggers an unchecked error condition. | |
| Modificada | Alta (10) | 7.2% | — | Apple MAC OS XApple MAC OS X Server | 2/8/2006 | 16/6/2026 | Stack-based buffer overflow in bootpd in the DHCP component for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to execute arbitrary code via a crafted BOOTP request. | |
| Modificada | Media (5.1) | 3.9% | — | Apple MAC OS XApple MAC OS X Server | 2/8/2006 | 16/6/2026 | Unspecified vulnerability in the "compression state handling" in Bom for Apple Mac OS X 10.3.9 and 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Zip archive. | |
| Modificada | Baja (2.1) | 0.91% | — | Apple MAC OS XApple MAC OS X Server | 2/8/2006 | 16/6/2026 | AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys in a world-readable file, which allows local users to obtain the keys and access files and folders of other users. | |
| Modificada | Media (5) | 5.3% | — | Apple MAC OS XApple MAC OS X Server | 2/8/2006 | 16/6/2026 | Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors. | |
| Modificada | Baja (2.6) | 1.3% | — | Apple MAC OS XApple MAC OS X Server | 6/7/2006 | 16/6/2026 | The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to cause a denial of service (application crash) via an invalid tag value in a TIFF image, possibly triggering a null dereference. NOTE: This is a different issue than CVE-2006-1469. | |
| Modificada | Media (4.6) | 0.40% | — | Apple MAC OS XApple MAC OS X Server | 27/6/2006 | 23/9/2026 | Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file. | |
| Modificada | Alta (7.5) | 4.8% | — | Apple MAC OS XApple MAC OS X Server | 27/6/2006 | 23/9/2026 | Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image. |