Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
598 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.7% | — | GNU Mailutils | 26/5/2005 | 16/6/2026 | The imap4d server for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows authenticated remote users to cause a denial of service (CPU consumption) via a large range value in the FETCH command. | |
| Modificada | Baja (2.1) | 0.36% | — | GNU Sharutils | 2/5/2005 | 16/6/2026 | unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file. | |
| Modificada | Baja (3.7) | 0.28% | — | GNU Coreutils | 2/5/2005 | 16/6/2026 | Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files. | |
| Modificada | Alta (10) | 11% | — | Nfs-utilsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop | 10/1/2005 | 16/6/2026 | rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request. | |
| Modificada | Media (5) | 2.4% | — | Nfs-utilsDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+2 | 10/1/2005 | 16/6/2026 | statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated. | |
| Modificada | Media (4.6) | 0.65% | — | GNU Sharutils | 31/12/2004 | 16/6/2026 | Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument. | |
| Modificada | Alta (7.5) | 2.5% | — | GNU InetutilsAI | 31/12/2004 | 16/6/2026 | Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function. | |
| Modificada | Alta (7.5) | 3.0% | — | GNU Sharutils | 31/12/2004 | 16/6/2026 | Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar. | |
| Modificada | Alta (7.2) | 0.42% | — | GNU Mailutils | 31/12/2004 | 16/6/2026 | Unknown vulnerability in the dotlock implementation in mailutils before 1:0.5-4 on Debian GNU/Linux allows attackers to gain privileges. | |
| Modificada | Alta (7.2) | 0.56% | — | Debian Bsdmainutils | 20/10/2004 | 16/6/2026 | The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file. | |
| Modificada | Media (5) | 1.7% | — | Nfs-utils | 14/6/2004 | 16/6/2026 | rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name. | |
| Modificada | Media (5) | 11% | 💥 Exploit | GNU FileutilsWashington University Wu-ftpd | 17/11/2003 | 16/6/2026 | An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd. | |
| Modificada | Baja (2.1) | 1.1% | 💥 Exploit | GNU FileutilsWashington University Wu-ftpd | 17/11/2003 | 16/6/2026 | ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls, such as wu-ftpd. | |
| Modificada | Crítica (9.8) | 16% | — | Linux-nfs Nfs-utils | 18/8/2003 | 16/6/2026 | Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines. | |
| Modificada | Baja (1.2) | 0.30% | — | Mhc-utils | 7/3/2003 | 16/6/2026 | adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name. | |
| Modificada | Alta (10) | 4.1% | — | Sourcecraft Networking Utils | 31/12/2002 | 16/6/2026 | The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument. | |
| Modificada | Baja (1.2) | 0.34% | — | GNU Fileutils | 26/7/2002 | 16/6/2026 | Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".."… | |
| Modificada | Alta (7.2) | 0.62% | — | GNU Sharutils | 29/5/2002 | 16/6/2026 | uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, which could allow attackers to overwrite files or execute commands. | |
| Modificada | Media (4.6) | 0.41% | — | Redhat Docbook StylesheetsRedhat Docbook Utils | 29/5/2002 | 16/6/2026 | The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier. | |
| Modificada | Media (4.6) | 0.33% | — | Kdeutils | 14/12/2001 | 16/6/2026 | klprfax_filter in KDE2 KDEUtils allows local users to overwrite arbitrary files via a symlink attack on the klprfax.filter temporary file. | |
| Modificada | Alta (7.2) | 0.90% | 💥 Exploit | GNU FindutilsSlackware Linux | 31/8/2001 | 16/6/2026 | GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory. | |
| Modificada | Alta (7.5) | 2.0% | — | ImmunixIputilsRedhat Linux | 18/10/2000 | 16/6/2026 | ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to bugs that otherwise would occur at lower privileges. | |
| Modificada | Media (4.6) | 0.41% | — | ImmunixIputilsRedhat Linux | 18/10/2000 | 16/6/2026 | Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow local users to gain privileges. |