Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2647▼ 688 respecto a la semana anterior
Críticas / altas1257▼ 290 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 277 respecto a la semana anterior
–

656 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.1)2.3%—ApplescriptApple MAC OS XApple MAC OS X Server4/5/200516/6/2026
The AppleScript Editor in Mac OS X 10.3.9 does not properly display script code for an applescript: URI, which can result in code that is different than the actual code that would be run, which could allow remote attackers to trick users into executing malicious code via certain URI characters such as NULL, control…
ModificadaMedia (4.9)0.35%—Apple MAC OS XApple MAC OS X Server4/5/200516/6/2026
AppKit in Mac OS X 10.3.9 allows attackers to cause a denial of service (Cocoa application crash) via a malformed TIFF image that causes the NXSeek to use an incorrect offset, leading to an unhandled exception.
ModificadaAlta (7.2)1.0%—Apple MAC OS XApple MAC OS X Server3/5/200516/6/2026
Stack-based buffer overflow in the VPN daemon (vpnd) for Mac OS X before 10.3.9 allows local users to execute arbitrary code via a long -i (Server_id) argument.
ModificadaBaja (3.6)0.38%—Apple MAC OS XApple MAC OS X Server3/5/200516/6/2026
Mac OS X 10.3.x and earlier uses insecure permissions for a pseudo terminal tty (pty) that is managed by a non-setuid program, which allows local users to read or modify sessions of other users.
ModificadaBaja (2.1)0.51%—Apple MAC OS XApple MAC OS X ServerOpendarwin Darwin Kernel2/5/200516/6/2026
Integer signedness error in the parse_machfile function in the mach-o loader (mach_loader.c) for the Darwin Kernel as used in Mac OS X 10.3.7, and other versions before 10.3.9, allows local users to cause a denial of service (CPU consumption) via a crafted mach-o header.
ModificadaMedia (5)2.7%—Apple MAC OS XApple MAC OS X Server2/5/200516/6/2026
Mail in Mac OS X 10.3.7, when generating a Message-ID header, generates a GUUID that includes information that identifies the Ethernet hardware being used, which allows remote attackers to link mail messages to a particular machine.
ModificadaAlta (7.5)3.4%—Apple MAC OS XApple MAC OS X Server2/5/200516/6/2026
ColorSync on Mac OS X 10.3.7 and 10.3.8 allows attackers to execute arbitrary code via malformed ICC color profiles that modify the heap.
ModificadaAlta (7.2)0.36%—Apple MAC OS XApple MAC OS X Server2/5/200516/6/2026
The "at" commands on Mac OS X 10.3.7 and earlier do not properly drop privileges, which allows local users to (1) delete arbitrary files via atrm, (2) execute arbitrary programs via the -f argument to batch, or (3) read arbitrary files via the -f argument to batch, which generates a job file that is readable by the…
ModificadaBaja (2.1)0.94%💥 ExploitApple MAC OS XApple MAC OS X Server2/5/200516/6/2026
The Finder in Mac OS X and earlier allows local users to overwrite arbitrary files and gain privileges by creating a hard link from the .DS_Store file to an arbitrary file.
ModificadaMedia (5)1.9%—PHPSGI PropackConectiva LinuxApple MAC OS X+314/4/200516/6/2026
exif.c in PHP before 4.3.11 allows remote attackers to cause a denial of service (memory consumption and crash) via an EXIF header with a large IFD nesting level, which causes significant stack recursion.
ModificadaAlta (7.2)1.1%💥 ExploitApple MAC OS XApple MAC OS X Server21/3/200516/6/2026
Stack-based buffer overflow in the Core Foundation Library in Mac OS X 10.3.5 and 10.3.6, and possibly earlier versions, allows local users to execute arbitrary code via a long CF_CHARSET_PATH environment variable.
ModificadaBaja (2.1)0.31%—Apple MAC OS XApple MAC OS X Server21/3/200516/6/2026
AFP Server in Mac OS X before 10.3.8 uses insecure permissions for "Drop Boxes," which allows local users to read the contents of a Drop Box.
ModificadaMedia (4.6)0.56%💥 ExploitApple MAC OS XApple MAC OS X Server21/3/200516/6/2026
The Bluetooth Setup Assistant for Mac OS X before 10.3.8 can be launched without a keyboard or Bluetooth device, which allows local users to bypass access restrictions and gain privileges.
ModificadaMedia (5)0.71%—Easy Software Products CupsApple MAC OS XApple MAC OS X Server27/1/200516/6/2026
ServerAdmin in Mac OS X 10.2.8 through 10.3.5 uses the same example self-signed certificate on each system, which allows remote attackers to decrypt sessions.
ModificadaBaja (2.1)0.45%—Easy Software Products CupsApple MAC OS XApple MAC OS X Server27/1/200516/6/2026
CUPS 1.1.20 and earlier records authentication information for a device URI in the error_log file, which allows local users to obtain user names and passwords.
ModificadaMedia (5)1.1%—Apple MAC OS XApple MAC OS X Server27/1/200516/6/2026
Postfix on Mac OS X 10.3.x through 10.3.5, with SMTPD AUTH enabled, does not properly clear the username between authentication attempts, which allows users with the longest username to prevent other valid users from being able to authenticate.
ModificadaAlta (10)4.9%—Easy Software Products CupsApple MAC OS XApple MAC OS X Server27/1/200516/6/2026
Heap-based buffer overflow in Apple QuickTime on Mac OS 10.2.8 through 10.3.5 may allow remote attackers to execute arbitrary code via a certain BMP image.
ModificadaMedia (5)0.85%—Easy Software Products CupsApple MAC OS XApple MAC OS X Server27/1/200516/6/2026
NetInfo Manager on Mac OS X 10.3.x through 10.3.5, after an initial root login, reports the root account as being disabled, even when it has not.
ModificadaMedia (5)0.97%—Apple QuicktimeApple MAC OS XApple MAC OS X Server27/1/200516/6/2026
AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box.
ModificadaAlta (7.5)1.1%—Apple QuicktimeApple MAC OS XApple MAC OS X Server27/1/200516/6/2026
AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets.
ModificadaMedia (5)5.4%—LibtiffPdflib PDF LibraryWxgtk2Apple MAC OS X+927/1/200516/6/2026
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
ModificadaMedia (5)1.3%—Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server10/1/200516/6/2026
Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte.
ModificadaAlta (7.2)0.43%—Apple MAC OS XApple MAC OS X Server31/12/200416/6/2026
The CFPlugIn in Core Foundation framework in Mac OS X allows user supplied libraries to be loaded, which could allow local users to gain privileges.
ModificadaMedia (5)1.8%—Apple MAC OS X Server31/12/200416/6/2026
Buffer overflow in the GUI admin service in Mac OS X Server 10.3 allows remote attackers to cause a denial of service (crash and restart) via a large amount of data to TCP port 660.
ModificadaMedia (5)3.6%—Apple MAC OS X Server31/12/200416/6/2026
QuickTime Streaming Server in Mac OS X Server 10.2.8, 10.3.4, and 10.3.5 allows remote attackers to cause a denial of service (application deadlock) via a certain sequence of operations.