Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 5.2% | — | GNU BinutilsCanonical Ubuntu LinuxFedoraproject Fedora | 9/12/2014 | 17/6/2026 | The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable. | |
| Modificada | Alta (7.5) | 7.5% | — | Fedoraproject FedoraCanonical Ubuntu LinuxGNU Binutils | 9/12/2014 | 17/6/2026 | The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file. | |
| Modificada | Media (5) | 5.1% | — | GNU BinutilsFedoraproject FedoraCanonical Ubuntu Linux | 9/12/2014 | 17/6/2026 | The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record. | |
| Modificada | Alta (7.8) | 2.3% | — | Manageengine Oputils | 25/11/2014 | 17/6/2026 | The ConfigSaveServlet servlet in ManageEngine OpUtils before build 71024 allows remote attackers to "disclose" files via a crafted filename, related to "saveFile." | |
| Modificada | Media (5) | 1.8% | — | Powerpc-utils Project Powerpc-utils | 17/6/2014 | 17/6/2026 | snap in powerpc-utils 1.2.20 produces an archive with fstab and yaboot.conf files potentially containing cleartext passwords, and lacks a warning about reviewing this archive to detect included passwords, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support… | |
| Modificada | Media (6.9) | 0.36% | — | Selinuxproject Policycoreutils | 8/5/2014 | 17/6/2026 | seunshare in policycoreutils 2.2.5 is owned by root with 4755 permissions, and executes programs in a way that changes the relationship between the setuid system call and the getresuid saved set-user-ID value, which makes it easier for local users to gain privileges by leveraging a program that mistakenly expected… | |
| Modificada | Alta (7.5) | 99% | 💥 Exploit | Apache Commons BeanutilsApache Struts | 30/4/2014 | 17/6/2026 | Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in other products requiring commons-beanutils through 1.9.2, does not suppress the class property, which allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class… | |
| Modificada | Media (4.4) | 0.44% | — | Openfabrics Ibutils | 15/4/2014 | 16/6/2026 | Untrusted search path vulnerability in a certain Red Hat build script for the ibmssh executable in ibutils packages before ibutils-1.5.7-2.el6 in Red Hat Enterprise Linux (RHEL) 6 and ibutils-1.2-11.2.el5 in Red Hat Enterprise Linux (RHEL) 5 allows local users to gain privileges via a Trojan Horse program in… | |
| Modificada | Media (6.8) | 4.0% | — | Elfutils Project Elfutils | 11/4/2014 | 17/6/2026 | Integer overflow in the check_section function in dwarf_begin_elf.c in the libdw library, as used in elfutils 0.153 and possibly through 0.158 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed compressed debug section in an ELF file, which… | |
| Modificada | Baja (3.3) | 0.35% | — | Linux-nfs Nfs-utils | 26/2/2014 | 16/6/2026 | The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to… | |
| Modificada | Alta (7.5) | 2.6% | — | Linux-nfs Nfs-utils | 15/2/2014 | 16/6/2026 | The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records. | |
| Modificada | Baja (3.6) | 0.38% | — | Ecryptfs-utilsEcryptfs Utils | 15/2/2014 | 16/6/2026 | The lock-counter implementation in utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 allows local users to overwrite arbitrary files via unspecified vectors. | |
| Modificada | Media (4.6) | 0.38% | — | Ecryptfs-utilsEcryptfs Utils | 15/2/2014 | 16/6/2026 | utils/ecryptfs-recover-private in ecryptfs-utils before 90 does not establish a subdirectory with safe permissions, which might allow local users to bypass intended access restrictions via standard filesystem operations during the recovery process. | |
| Modificada | Media (4.4) | 0.35% | — | Ecryptfs-utilsEcryptfs Utils | 15/2/2014 | 16/6/2026 | The encrypted private-directory setup process in utils/ecryptfs-setup-private in ecryptfs-utils before 90 does not properly ensure that the passphrase file is created, which might allow local users to bypass intended access restrictions at a certain time in the new-user creation steps. | |
| Modificada | Baja (2.1) | 0.38% | — | Ecryptfs-utilsEcryptfs Utils | 15/2/2014 | 16/6/2026 | utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly maintain the mtab file during error conditions, which allows local users to cause a denial of service (table corruption) or bypass intended unmounting restrictions via a umount system call. | |
| Modificada | Baja (2.1) | 0.38% | — | Ecryptfs-utilsEcryptfs Utils | 15/2/2014 | 16/6/2026 | utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to remove directories via a umount system call. | |
| Modificada | Media (4.6) | 0.37% | — | Ecryptfs-utilsEcryptfs Utils | 15/2/2014 | 16/6/2026 | utils/mount.ecryptfs_private.c in ecryptfs-utils before 90 does not properly check mountpoint permissions, which allows local users to effectively replace any directory with a new filesystem, and consequently gain privileges, via a mount system call. | |
| Modificada | Baja (3.2) | 1.0% | — | Linux-nfs Nfs-utils | 21/1/2014 | 16/6/2026 | rpc-gssd in nfs-utils before 1.2.8 performs reverse DNS resolution for server names during GSSAPI authentication, which might allow remote attackers to read otherwise-restricted files via DNS spoofing attacks. | |
| Modificada | Media (6.3) | 0.50% | — | Redhat Enterprise LinuxOpenfabrics Ibutils | 23/11/2013 | 16/6/2026 | OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/. | |
| Modificada | Baja (3.6) | 0.46% | — | Fedoraproject Crypto-utils | 10/10/2012 | 16/6/2026 | The nssconfigFound function in genkey.pl in crypto-utils 2.4.1-34 allows local users to overwrite arbitrary files via a symlink attack on the "list" file in the current working directory. | |
| Modificada | Media (5) | 3.6% | — | GNU BinutilsGNU LibibertyCanonical Ubuntu LinuxDebian Linux | 5/9/2012 | 16/6/2026 | Multiple integer overflows in the (1) _objalloc_alloc function in objalloc.c and (2) objalloc_alloc macro in include/objalloc.h in GNU libiberty, as used by binutils 2.22, allow remote attackers to cause a denial of service (crash) via vectors related to the "addition of CHUNK_HEADER_SIZE to the length," which… | |
| Modificada | Baja (2.1) | 0.73% | 💥 Exploit | Debian Cifs-utils | 27/8/2012 | 16/6/2026 | mount.cifs in cifs-utils 2.6 allows local users to determine the existence of arbitrary files or directories via the file path in the second argument, which reveals their existence in an error message. | |
| Modificada | Baja (3.3) | 0.31% | — | Debian Texlive-extra-utils | 18/5/2012 | 16/6/2026 | latex2man in texlive-extra-utils 2011.20120322, and possibly other versions or packages, when used with the H or T option, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. | |
| Modificada | Media (5) | 1.3% | — | Claus DUE Sysutils | 14/2/2012 | 16/6/2026 | The System Utilities (sysutils) extension 1.0.3 and earlier for TYPO3 allows remote attackers to obtain sensitive information via unspecified vectors related to improper "protection" of the "backup output directory." | |
| Modificada | Alta (10) | 95% | 💥 Exploit | GNU InetutilsHeimdal Project HeimdalMIT Krb5-applFreebsd+6 | 25/12/2011 | 16/6/2026 | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the… |