Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 646 respecto a la semana anterior
Críticas / altas1266▼ 292 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

593 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.68%💥 ExploitFreebsd12/2/200116/6/2026
Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental variables that affect the behavior of telnetd.
ModificadaBaja (2.1)0.33%—Freebsd12/2/200116/6/2026
procfs in FreeBSD and possibly other operating systems allows local users to cause a denial of service by calling mmap on the process' own mem file, which causes the kernel to hang.
ModificadaMedia (5)1.7%—Freebsd9/1/200116/6/2026
telnetd in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service by specifying an arbitrary large file in the TERMCAP environmental variable, which consumes resources as the server processes the file.
ModificadaAlta (7.5)1.6%—Freebsd9/1/200116/6/2026
ppp utility in FreeBSD 4.1.1 and earlier does not properly restrict access as specified by the "nat deny_incoming" command, which allows remote attackers to connect to the target system.
ModificadaAlta (7.2)0.69%—ImmunixFreebsdRedhat LinuxInvisible-island Ncurses19/12/200023/9/2026
Buffer overflow in ncurses library allows local users to execute arbitrary commands via long environmental information such as TERM or TERMINFO_DIRS.
ModificadaAlta (7.2)1.7%💥 ExploitFreebsdNetbsdOpenbsd19/12/200023/9/2026
Format string vulnerability in pw_error function in BSD libutil library allows local users to gain root privileges via a malformed password in commands such as chpass or passwd.
ModificadaAlta (7.5)5.5%💥 ExploitFreebsd19/12/200023/9/2026
FreeBSD 4.1.1 and earlier, and possibly other BSD-based OSes, uses an insufficient random number generator to generate initial TCP sequence numbers (ISN), which allows remote attackers to spoof TCP connections.
ModificadaMedia (5)2.4%—Freebsd19/12/200023/9/2026
fingerd in FreeBSD 4.1.1 allows remote attackers to read arbitrary files by specifying the target file name instead of a regular user name.
ModificadaAlta (7.2)0.40%—Freebsd11/12/200016/6/2026
Buffer overflow in catopen() function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to gain root privileges via a long environmental variable.
ModificadaMedia (5)1.7%—Freebsd11/12/200016/6/2026
The getnameinfo function in FreeBSD 4.1.1 and earlier, and possibly other operating systems, allows a remote attacker to cause a denial of service via a long DNS hostname.
ModificadaAlta (7.2)0.35%—Freebsd11/12/200016/6/2026
The catopen function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.
ModificadaAlta (7.2)0.88%💥 ExploitFreebsd11/12/200023/9/2026
Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" function.
ModificadaAlta (7.2)0.35%—Freebsd11/12/200023/9/2026
The setlocale function in FreeBSD 5.0 and earlier, and possibly other OSes, allows local users to read arbitrary files via the LANG environmental variable.
ModificadaAlta (7.2)0.40%—Freebsd14/11/200016/6/2026
Multiple buffer overflows in eject on FreeBSD and possibly other OSes allows local users to gain root privileges.
ModificadaAlta (7.2)0.39%—Freebsd20/10/200016/6/2026
Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.
ModificadaAlta (7.2)0.46%—Freebsd20/10/200016/6/2026
Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.
ModificadaBaja (2.1)0.33%—Freebsd20/10/200016/6/2026
FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.
ModificadaAlta (7.2)0.36%—Freebsd16/9/200016/6/2026
Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program.
ModificadaMedia (4.6)0.51%—Freebsd5/7/200016/6/2026
libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory.
ModificadaMedia (5)9.9%💥 ExploitCaldera Openlinux DesktopCaldera Openlinux EbuilderCaldera Openlinux EdesktopCaldera Openlinux Eserver+24/7/200016/6/2026
BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.
ModificadaAlta (10)5.9%💥 ExploitDebian LinuxFreebsd2/7/200016/6/2026
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.
ModificadaMedia (5)1.4%—OpensslFreebsd12/6/200016/6/2026
OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken.
ModificadaAlta (7.5)1.8%—Freebsd7/6/200016/6/2026
A FreeBSD patch for SSH on 2000-01-14 configures ssh to listen on port 722 as well as port 22, which might allow remote attackers to access SSH through port 722 even if port 22 is otherwise filtered.
ModificadaBaja (2.1)0.34%—FreebsdNetbsd29/5/200016/6/2026
The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.
ModificadaAlta (7.2)0.73%💥 ExploitFreebsdMandrakesoft Mandrake Linux17/5/200016/6/2026
xsoldier program allows local users to gain root access via a long argument.
Orbitaley — Vulnerabilidades