Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)5.2%—GNU BinutilsCanonical Ubuntu LinuxFedoraproject Fedora9/12/201417/6/2026
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.
ModificadaAlta (7.5)7.5%—Fedoraproject FedoraCanonical Ubuntu LinuxGNU Binutils9/12/201417/6/2026
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
ModificadaMedia (5)5.1%—GNU BinutilsFedoraproject FedoraCanonical Ubuntu Linux9/12/201417/6/2026
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
ModificadaAlta (7.8)2.3%—Manageengine Oputils25/11/201417/6/2026
The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related to "saveFile."
ModificadaMedia (5)1.8%—Powerpc-utils Project Powerpc-utils17/6/201417/6/2026
snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support…
ModificadaMedia (6.9)0.36%—Selinuxproject Policycoreutils8/5/201417/6/2026
seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes the relationship between the setuid system call and the getresuid saved set-user-ID value, which makes it easier for local users to gain privileges by leveraging a program that mistakenly expected…
ModificadaAlta (7.5)99%💥 ExploitApache Commons BeanutilsApache Struts30/4/201417/6/2026
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class…
ModificadaMedia (4.4)0.44%—Openfabrics Ibutils15/4/201416/6/2026
Untrusted search path vulnerability in a certain Red Hat build script for the ibmssh executable in ibutils packages before ibutils-1.5.7-2.el6 in Red Hat Enterprise Linux (RHEL) 6 and ibutils-1.2-11.2.el5 in Red Hat Enterprise Linux (RHEL) 5 allows local users to gain privileges via a Trojan Horse program in…
ModificadaMedia (6.8)4.0%—Elfutils Project Elfutils11/4/201417/6/2026
Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed compressed debug section in an ELF file, which…
ModificadaBaja (3.3)0.35%—Linux-nfs Nfs-utils26/2/201416/6/2026
The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to…
ModificadaAlta (7.5)2.6%—Linux-nfs Nfs-utils15/2/201416/6/2026
The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.
ModificadaBaja (3.6)0.38%—Ecryptfs-utilsEcryptfs Utils15/2/201416/6/2026
The lock-counter implementation in utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 allows local users to overwrite arbitrary files via unspecified vectors.
ModificadaMedia (4.6)0.38%—Ecryptfs-utilsEcryptfs Utils15/2/201416/6/2026
utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations during the recovery process.
ModificadaMedia (4.4)0.35%—Ecryptfs-utilsEcryptfs Utils15/2/201416/6/2026
The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might allow local users to bypass intended access restrictions at a certain time in the new-user creation steps.
ModificadaBaja (2.1)0.38%—Ecryptfs-utilsEcryptfs Utils15/2/201416/6/2026
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly maintain the mtab file during error conditions, which allows local users to cause a denial of service (table corruption) or bypass intended unmounting restrictions via a umount system call.
ModificadaBaja (2.1)0.38%—Ecryptfs-utilsEcryptfs Utils15/2/201416/6/2026
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to remove directories via a umount system call.
ModificadaMedia (4.6)0.37%—Ecryptfs-utilsEcryptfs Utils15/2/201416/6/2026
utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to effectively replace any directory with a new filesystem, and consequently gain privileges, via a mount system call.
ModificadaBaja (3.2)1.0%—Linux-nfs Nfs-utils21/1/201416/6/2026
rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks.
ModificadaMedia (6.3)0.50%—Redhat Enterprise LinuxOpenfabrics Ibutils23/11/201316/6/2026
OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.
ModificadaBaja (3.6)0.46%—Fedoraproject Crypto-utils10/10/201216/6/2026
The nssconfigFound function in genkey.pl in crypto-utils 2.4.1-34 allows local users to overwrite arbitrary files via a symlink attack on the "list" file in the current working directory.
ModificadaMedia (5)3.6%—GNU BinutilsGNU LibibertyCanonical Ubuntu LinuxDebian Linux5/9/201216/6/2026
Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which…
ModificadaBaja (2.1)0.73%💥 ExploitDebian Cifs-utils27/8/201216/6/2026
mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message.
ModificadaBaja (3.3)0.31%—Debian Texlive-extra-utils18/5/201216/6/2026
latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
ModificadaMedia (5)1.3%—Claus DUE Sysutils14/2/201216/6/2026
The System Utilities (sysutils) extension 1.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unspecified vectors related to improper "protection" of the "backup output directory."
ModificadaAlta (10)95%💥 ExploitGNU InetutilsHeimdal Project HeimdalMIT Krb5-applFreebsd+625/12/201116/6/2026
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the…
Orbitaley — Vulnerabilidades