Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

656 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.50%—Apple MAC OS XApple MAC OS X Server21/9/200616/6/2026
Integer overflow in the API for the AirPort wireless driver on Apple Mac OS X 10.4.7 might allow physically proximate attackers to cause a denial of service (crash) or execute arbitrary code in third-party wireless software that uses the API via crafted frames.
ModificadaAlta (7.2)1.5%💥 ExploitApple MAC OS XApple MAC OS X Server21/9/200616/6/2026
Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10.4.7 allow physically proximate attackers to execute arbitrary code by injecting crafted frames into a wireless network.
ModificadaAlta (7.2)0.56%—Apple MAC OS XApple MAC OS X Server21/9/200616/6/2026
Heap-based buffer overflow in the AirPort wireless driver on Apple Mac OS X 10.4.7 allows physically proximate attackers to cause a denial of service (crash), gain privileges, and execute arbitrary code via a crafted frame that is not properly handled during scan cache updates.
ModificadaMedia (4.6)0.98%💥 ExploitApple MAC OS XApple MAC OS X Server19/9/200616/6/2026
Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.
ModificadaAlta (7.5)12%—ISC BindCanonical Ubuntu LinuxApple MAC OS XApple MAC OS X Server6/9/200616/6/2026
BIND before 9.2.6-P1 and 9.3.x before 9.3.2-P1 allows remote attackers to cause a denial of service (crash) via certain SIG queries, which cause an assertion failure when multiple RRsets are returned.
ModificadaMedia (4.6)0.49%—Apple XsanApple MAC OS XApple MAC OS X Server21/8/200616/6/2026
Buffer overflow in the Xsan Filesystem driver on Mac OS X 10.4.7 and OS X Server 10.4.7 allows local users with Xsan write access, to execute arbitrary code via unspecified vectors related to "processing a path name."
ModificadaMedia (5.1)55%💥 ExploitApple MAC OS XApple MAC OS X Server5/8/200616/6/2026
The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to execute arbitrary code via crafted file types.
ModificadaMedia (5.1)2.7%—Apple MAC OS XApple MAC OS X Server3/8/200616/6/2026
Unspecified vulnerability in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted GIF image that triggers a memory allocation failure that is not properly handled.
ModificadaMedia (5.1)1.5%—Apple MAC OS XApple MAC OS X Server3/8/200616/6/2026
The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari.
ModificadaAlta (7.5)4.1%—Apple MAC OS XApple MAC OS X Server3/8/200616/6/2026
WebKit in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML document that causes WebKit to access an object that has already been deallocated.
ModificadaMedia (5.1)2.7%—Apple MAC OS XApple MAC OS X Server3/8/200616/6/2026
Integer overflow in ImageIO in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a malformed GIF image.
ModificadaMedia (5.1)3.2%—Apple MAC OS XApple MAC OS X Server3/8/200616/6/2026
Buffer overflow in Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Canon RAW image.
ModificadaBaja (2.1)0.35%—Apple MAC OS XApple MAC OS X Server3/8/200616/6/2026
The dynamic linker (dyld) in Apple Mac OS X 10.3.9 allows local users to obtain sensitive information via unspecified dynamic linker options that affect the use of standard error (stderr) by privileged applications.
ModificadaAlta (7.2)0.41%—Apple MAC OS XApple MAC OS X Server3/8/200616/6/2026
The dynamic linker (dyld) in Apple Mac OS X 10.4.7 allows local users to execute arbitrary code via an "improperly handled condition" that leads to use of "dangerous paths," probably related to an untrusted search path vulnerability.
ModificadaMedia (4)2.0%—Apple MAC OS XApple MAC OS X Server3/8/200616/6/2026
OpenSSH in Apple Mac OS X 10.4.7 allows remote attackers to cause a denial of service or determine account existence by attempting to log in using an invalid user, which causes the server to hang.
ModificadaMedia (5.1)2.7%—Apple MAC OS XApple MAC OS X Server3/8/200616/6/2026
Integer overflow in ImageIO for Apple Mac OS X 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Radiance image.
ModificadaMedia (5)1.9%—Apple MAC OS XApple MAC OS X Server2/8/200616/6/2026
Unspecified vulnerability in AFP Server in Apple Mac OS X 10.3.9 allows remote attackers to determine names of unauthorized files and folders via unknown vectors related to the search results.
ModificadaMedia (5)3.0%—Apple MAC OS XApple MAC OS X Server2/8/200616/6/2026
AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause denial of service (crash) via an invalid AFP request that triggers an unchecked error condition.
ModificadaAlta (10)7.2%—Apple MAC OS XApple MAC OS X Server2/8/200616/6/2026
Stack-based buffer overflow in bootpd in the DHCP component for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to execute arbitrary code via a crafted BOOTP request.
ModificadaMedia (5.1)3.9%—Apple MAC OS XApple MAC OS X Server2/8/200616/6/2026
Unspecified vulnerability in the "compression state handling" in Bom for Apple Mac OS X 10.3.9 and 10.4.7 allows user-assisted attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted Zip archive.
ModificadaBaja (2.1)0.91%—Apple MAC OS XApple MAC OS X Server2/8/200616/6/2026
AFP Server in Apple Mac OS X 10.3.9 and 10.4.7 stores reconnect keys in a world-readable file, which allows local users to obtain the keys and access files and folders of other users.
ModificadaMedia (5)5.3%—Apple MAC OS XApple MAC OS X Server2/8/200616/6/2026
Integer overflow in AFP Server for Apple Mac OS X 10.3.9 and 10.4.7 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via unknown vectors.
ModificadaBaja (2.6)1.3%—Apple MAC OS XApple MAC OS X Server6/7/200616/6/2026
The TIFFFetchAnyArray function in ImageIO in Apple OS X 10.4.7 and earlier allows remote user-assisted attackers to cause a denial of service (application crash) via an invalid tag value in a TIFF image, possibly triggering a null dereference. NOTE: This is a different issue than CVE-2006-1469.
ModificadaMedia (4.6)0.40%—Apple MAC OS XApple MAC OS X Server27/6/200623/9/2026
Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file.
ModificadaAlta (7.5)4.8%—Apple MAC OS XApple MAC OS X Server27/6/200623/9/2026
Stack-based buffer overflow in ImageIO in Apple Mac OS X 10.4 up to 10.4.6 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image.