Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.9)0.37%—Redhat PolicycoreutilsRedhat Enterprise LinuxRedhat Fedora24/2/201116/6/2026
The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterprise Linux (RHEL) 6 and earlier, and Fedora 14 and earlier, mounts a new directory on top of /tmp without assigning root ownership and the sticky bit to this new…
ModificadaMedia (5)3.0%—Skbuff Iputils28/7/201016/6/2026
Unspecified vulnerability in ping.c in iputils 20020927, 20070202, 20071127, and 20100214 on Mandriva Linux allows remote attackers to cause a denial of service (hang) via a crafted echo response.
ModificadaAlta (7.5)0.97%💥 ExploitManageengine Oputils23/3/201016/6/2026
SQL injection vulnerability in Login.do in ManageEngine OpUtils 5.0 allows remote attackers to execute arbitrary SQL commands via the isHttpPort parameter.
ModificadaMedia (4.4)0.38%—Canonical Ubuntu LinuxGNU CoreutilsFedoraproject Fedora11/12/200916/6/2026
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
ModificadaMedia (6.9)0.38%—Redhat Cluster ProjectRedhat CmanRedhat RgmanagerFedoraproject Fedora+130/3/200916/6/2026
Red Hat Cluster Project 2.x allows local users to modify or overwrite arbitrary files via symlink attacks on files in /tmp, involving unspecified components in Resource Group Manager (aka rgmanager) before 2.03.09-1, gfs2-utils before 2.03.09-1, and CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9.
ModificadaAlta (7.5)1.6%—Nfs-utils20/1/200916/6/2026
Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions, possibly a related issue to CVE-2008-1376.
ModificadaMedia (6.8)2.2%—Freedesktop Xdg-utils7/1/200916/6/2026
Interaction error in xdg-open allows remote attackers to execute arbitrary code by sending a file with a dangerous MIME type but using a safe type that Firefox sends to xdg-open, which causes xdg-open to process the dangerous file type through automatic type detection, as demonstrated by overwriting the .desktop file.
ModificadaAlta (7.2)0.39%—Ecryptfs Utils21/11/200816/6/2026
The (1) ecryptfs-setup-private, (2) ecryptfs-setup-confidential, and (3) ecryptfs-setup-pam-wrapped.sh scripts in ecryptfs-utils 45 through 61 in eCryptfs place cleartext passwords on command lines, which allows local users to obtain sensitive information by listing the process.
ModificadaAlta (7.5)2.3%—Nfs-utils14/10/200816/6/2026
The good_client function in nfs-utils 1.0.9, and possibly other versions before 1.1.3, invokes the hosts_ctl function with the wrong order of arguments, which causes TCP Wrappers to ignore netgroups and allows remote attackers to bypass intended access restrictions.
ModificadaAlta (7.5)2.6%—Redhat NFS Utils1/8/200816/6/2026
A certain Red Hat build script for nfs-utils before 1.0.9-35z.el5_2 on Red Hat Enterprise Linux (RHEL) 5 omits TCP wrappers support, which might allow remote attackers to bypass intended access restrictions.
ModificadaMedia (4.4)0.31%—GNU Coreutils28/7/200816/6/2026
The default configuration of su in /etc/pam.d/su in GNU coreutils 5.2.1 allows local users to gain the privileges of a (1) locked or (2) expired account by entering the account name on the command line, related to improper use of the pam_succeed_if.so module.
ModificadaCrítica (9.8)4.3%—Bluez-libsBluez-utilsFedoraproject Fedora7/7/200816/6/2026
src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive…
ModificadaMedia (4.3)1.0%—Manageengine Oputils20/6/200816/6/2026
Cross-site scripting (XSS) vulnerability in MainLayout.do in ManageEngine OpUtils 5.0 allows remote attackers to inject arbitrary web script or HTML via the hostName parameter, when viewing an SNMP graph. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (6.8)3.2%—Gentoo Xdg-utils4/2/200816/6/2026
Xdg-utils 1.0.2 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a URL argument to (1) xdg-open or (2) xdg-email.
ModificadaAlta (7.2)0.44%—Kernel Util-linuxLoop-aes-utils Project Loop-aes-utilsFedoraproject FedoraCanonical Ubuntu Linux+14/10/200716/6/2026
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
ModificadaMedia (6)2.2%—GNU Findutils4/6/200716/6/2026
Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.
ModificadaAlta (7.3)14%💥 ExploitGNU Binutils15/5/200616/6/2026
Buffer overflow in getsym in tekhex.c in libbfd in Free Software Foundation GNU Binutils before 20060423, as used by GNU strings, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a file with a crafted Tektronix Hex Format (TekHex) record in…
ModificadaAlta (7.6)2.3%—GNU BinutilsCanonical Ubuntu Linux31/12/200516/6/2026
Buffer overflow in reset_vars in config/tc-crx.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050714 allows user-assisted attackers to have an unknown impact via a crafted .s file.
ModificadaAlta (7.5)12%💥 ExploitGNU BinutilsCanonical Ubuntu Linux31/12/200516/6/2026
Stack-based buffer overflow in the as_bad function in messages.c in the GNU as (gas) assembler in Free Software Foundation GNU Binutils before 20050721 allows attackers to execute arbitrary code via a .c file with crafted inline assembly code.
ModificadaAlta (7.2)2.8%💥 ExploitPwdutils5/11/200516/6/2026
chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.
ModificadaAlta (7.5)15%💥 ExploitGNU Mailutils13/9/200516/6/2026
Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command.
ModificadaAlta (7.5)1.1%—GNU Mailutils2/6/200516/6/2026
The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "\" (backslash) character, which is used as an escape character and makes the module vulnerable to SQL injection attacks.
ModificadaAlta (7.5)9.8%💥 ExploitGNU Mailutils26/5/200516/6/2026
Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands.
ModificadaAlta (7.5)6.7%💥 ExploitGNU Mailutils26/5/200516/6/2026
Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a crafted e-mail.
ModificadaAlta (7.5)3.3%—GNU Mailutils26/5/200516/6/2026
Integer overflow in the fetch_io function of the imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a partial message request with a large value in the END parameter, which leads to a heap-based buffer overflow.
Orbitaley — Vulnerabilidades