Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
–

667 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.35%—Apple MAC OS XApple MAC OS X Server1/11/200516/6/2026
Keychain Access in Mac OS X 10.4.2 and earlier keeps a password visible even if a keychain times out while the password is being viewed, which could allow attackers with physical access to obtain the password.
ModificadaBaja (2.1)0.37%—Apple MAC OS XApple MAC OS X Server1/11/200516/6/2026
Unspecified vulnerability in the Finder Get Info window for Mac OS X 10.4 up to 10.4.2 causes Finder to misrepresent file and group ownership information. NOTE: it is not clear whether this issue satisfies the CVE definition of a vulnerability.
ModificadaBaja (2.1)0.35%—Apple MAC OS XApple MAC OS X Server1/11/200516/6/2026
An unspecified kernel interface in Mac OS X 10.4.2 and earlier does not properly clear memory before reusing it, which could allow attackers to obtain sensitive information, a different vulnerability than CVE-2005-1126 and CVE-2005-1406.
ModificadaMedia (4.6)0.36%—Apple MAC OS XApple MAC OS X Server26/10/200516/6/2026
SecurityAgent in Apple Mac OS X 10.4.2, under certain circumstances, can cause the "Switch User..." button to appear even though the "Enable fast user switching" setting is disabled, which can allow attackers with physical access to gain access to the desktop and bypass the "Require password to wake this computer from…
ModificadaAlta (7.5)4.7%—Apple QuicktimeApple MAC OS XApple MAC OS X Server26/10/200516/6/2026
The Java extensions for QuickTime 6.52 and earlier in Apple Mac OS X 10.3.9 allow untrusted applets to call arbitrary functions in system libraries, which allows remote attackers to execute arbitrary code.
ModificadaMedia (5)1.5%—Apple MAC OS XApple MAC OS X Server26/10/200516/6/2026
Mail.app in Mail for Apple Mac OS X 10.3.9, when using Kerberos 5 for SMTP authentication, can include uninitialized memory in a message, which might allow remote attackers to obtain sensitive information.
ModificadaMedia (5)1.1%—Apple SafariApple MAC OS XApple MAC OS X Server26/10/200516/6/2026
Safari after 2.0 in Apple Mac OS X 10.3.9 allows remote attackers to bypass domain restrictions via crafted web archives that cause Safari to render them as if they came from a different site.
ModificadaAlta (7.2)0.33%—Apple MAC OS XApple MAC OS X ServerPerry Kiehtreiber Securityd26/10/200516/6/2026
Authorization Services en securityd para Apple Mac OS X 10.3.9 permite a usuarios locales obtener privilegios garantizándose a sí mismos determinados derechos que deben de ser restringidos a administradores.
ModificadaMedia (5)1.4%—Apple MAC OS XApple MAC OS X Server26/10/200516/6/2026
Mail.app in Mail for Apple Mac OS X 10.3.9 and 10.4.2 includes message contents when using auto-reply rules, which could cause Mail.app to include decrypted message contents for encrypted messages.
ModificadaMedia (5.1)4.1%—Apple MAC OS XApple MAC OS X Server25/10/200516/6/2026
Buffer overflow in QuickDraw Manager for Apple OS X 10.3.9 and 10.4.2, as used by applications such as Safari, Mail, and Finder, allows remote attackers to execute arbitrary code via a crafted PICT file.
ModificadaAlta (7.5)4.8%—Apple MAC OS XApple MAC OS X Server25/10/200516/6/2026
Buffer overflow in ImageIO for Apple Mac OS X 10.4.2, as used by applications such as WebCore and Safari, allows remote attackers to execute arbitrary code via a crafted GIF file.
ModificadaBaja (2.1)0.34%—Apple MAC OS XApple MAC OS X Server25/10/200516/6/2026
The malloc function in the libSystem library in Apple Mac OS X 10.3.9 and 10.4.2 allows local users to overwrite arbitrary files by setting the MallocLogFile environment variable to the target file before running a setuid application.
ModificadaBaja (2.1)0.39%—Apple MAC OS XApple MAC OS X Server19/8/200516/6/2026
Unknown vulnerability in loginwindow in Mac OS X 10.4.2 and earlier, when Fast User Switching is enabled, allows attackers to log into other accounts if they know the passwords to at least two accounts.
ModificadaMedia (5.1)3.3%—Apple MAC OS XApple MAC OS X Server19/8/200516/6/2026
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2, as used in applications such as TextEdit, allows external user-assisted attackers to execute arbitrary code via a crafted Microsoft Word file.
ModificadaAlta (10)1.9%—Apple MAC OS XApple MAC OS X Server19/8/200516/6/2026
Unknown vulnerability in Mac OS X 10.4.2 and earlier, when using Kerberos authentication with LDAP, allows attackers to gain access to a root Terminal window.
ModificadaAlta (7.5)6.2%—Apple MAC OS X Server19/8/200516/6/2026
Buffer overflow in Directory Services in Mac OS X 10.3.9 and 10.4.2 allows remote attackers to execute arbitrary code during authentication.
ModificadaMedia (4.6)0.39%—Apple MAC OS XApple MAC OS X Server19/8/200516/6/2026
AppKit for Mac OS X 10.3.9 and 10.4.2 allows attackers with physical access to create local accounts by forcing a particular error to occur at the login window.
ModificadaMedia (4.6)0.69%💥 ExploitApple MAC OS XApple MAC OS X Server19/8/200516/6/2026
dsidentity in Directory Services in Mac OS X 10.4.2 allows local users to add or remove user accounts.
ModificadaAlta (7.6)4.2%—Apple MAC OS XApple MAC OS X Server19/8/200516/6/2026
Buffer overflow in AppKit for Mac OS X 10.3.9 and 10.4.2 allows external user-assisted attackers to execute arbitrary code via a crafted Rich Text Format (RTF) file.
ModificadaMedia (5)1.3%—Apple MAC OS XApple MAC OS X Server19/8/200516/6/2026
Algorithmic complexity vulnerability in CoreFoundation in Mac OS X 10.3.9 and 10.4.2 allows attackers to cause a denial of service (CPU consumption) via crafted Gregorian dates.
ModificadaMedia (4.6)0.39%—Apple MAC OS X Server19/8/200516/6/2026
The Server Admin tool in servermgr_ipfilter for Mac OS X 10.4 to 10.4.2, when using multiple subnets and Address Groups, does not always properly write firewall rules to the Active Rules when certain conditions occur, which could result in firewall policies that are less restrictive than intended by the administrator.
ModificadaAlta (7.2)0.40%—Apple MAC OS XApple MAC OS X Server19/8/200516/6/2026
The System Profiler in Mac OS X 10.4.2 labels a Bluetooth device with "Requires Authentication: No" even when the user has selected the "Require pairing for security" option, which could confuse users about which setting is valid.
ModificadaCrítica (9.8)11%—MIT Kerberos 5Apple MAC OS XApple MAC OS X ServerDebian Linux18/7/200516/6/2026
Vulnerabilidad de doble liberación de memoria en la función krb5_recvauth en MIT Kerberos 5 (krb5) 1.4.1 y anteriores permite que atacantes remotos ejecuten código arbitrario mediante ciertas condiciones de error.
ModificadaAlta (7.2)0.38%—Apple MAC OS XApple MAC OS X Server16/6/200516/6/2026
Unknown vulnerability in the CoreGraphics Window Server for Mac OS X 10.4.x up to 10.4.1 allows local users to inject arbitrary commands into root sessions.
ModificadaAlta (7.5)1.3%—Apple MAC OS XApple MAC OS X Server13/6/200516/6/2026
Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.