Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

598 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.7%—GNU Mailutils26/5/200516/6/2026
The imap4d server for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows authenticated remote users to cause a denial of service (CPU consumption) via a large range value in the FETCH command.
ModificadaBaja (2.1)0.36%—GNU Sharutils2/5/200516/6/2026
unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
ModificadaBaja (3.7)0.28%—GNU Coreutils2/5/200516/6/2026
Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.
ModificadaAlta (10)11%—Nfs-utilsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop10/1/200516/6/2026
rquotad in nfs-utils (rquota_server.c) before 1.0.6-r6 on 64-bit architectures does not properly perform an integer conversion, which leads to a stack-based buffer overflow and allows remote attackers to execute arbitrary code via a crafted NFS request.
ModificadaMedia (5)2.4%—Nfs-utilsDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+210/1/200516/6/2026
statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
ModificadaMedia (4.6)0.65%—GNU Sharutils31/12/200416/6/2026
Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.
ModificadaAlta (7.5)2.5%—GNU InetutilsAI31/12/200416/6/2026
Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function.
ModificadaAlta (7.5)3.0%—GNU Sharutils31/12/200416/6/2026
Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.
ModificadaAlta (7.2)0.42%—GNU Mailutils31/12/200416/6/2026
Unknown vulnerability in the dotlock implementation in mailutils before 1:0.5-4 on Debian GNU/Linux allows attackers to gain privileges.
ModificadaAlta (7.2)0.56%—Debian Bsdmainutils20/10/200416/6/2026
The calendar program in bsdmainutils 6.0 through 6.0.14 does not drop root privileges when executed with the -a flag, which allows attackers to execute arbitrary commands via a calendar event file.
ModificadaMedia (5)1.7%—Nfs-utils14/6/200416/6/2026
rpc.mountd in nfs-utils after 1.0.3 and before 1.0.6 allows attackers to cause a denial of service (crash) via an NFS mount of a directory from a client whose reverse DNS lookup name is different from the forward lookup name.
ModificadaMedia (5)11%💥 ExploitGNU FileutilsWashington University Wu-ftpd17/11/200316/6/2026
An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or execute arbitrary code via a large -w value, which could be remotely exploited via applications that use ls, such as wu-ftpd.
ModificadaBaja (2.1)1.1%💥 ExploitGNU FileutilsWashington University Wu-ftpd17/11/200316/6/2026
ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, which can be remotely exploited via applications that use ls, such as wu-ftpd.
ModificadaCrítica (9.8)16%—Linux-nfs Nfs-utils18/8/200316/6/2026
Off-by-one error in the xlog function of mountd in the Linux NFS utils package (nfs-utils) before 1.0.4 allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain RPC requests to mountd that do not contain newlines.
ModificadaBaja (1.2)0.30%—Mhc-utils7/3/200316/6/2026
adb2mhc in the mhc-utils package before 0.25+20010625-7.1 allows local users to overwrite arbitrary files via a symlink attack on a default temporary directory with a predictable name.
ModificadaAlta (10)4.1%—Sourcecraft Networking Utils31/12/200216/6/2026
The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument.
ModificadaBaja (1.2)0.34%—GNU Fileutils26/7/200216/6/2026
Race condition in the recursive (1) directory deletion and (2) directory move in GNU File Utilities (fileutils) 4.1 and earlier allows local users to delete directories as the user running fileutils by moving a low-level directory to a higher level as it is being deleted, which causes fileutils to chdir to a ".."…
ModificadaAlta (7.2)0.62%—GNU Sharutils29/5/200216/6/2026
uudecode, as available in the sharutils package before 4.2.1, does not check whether the filename of the uudecoded file is a pipe or symbolic link, which could allow attackers to overwrite files or execute commands.
ModificadaMedia (4.6)0.41%—Redhat Docbook StylesheetsRedhat Docbook Utils29/5/200216/6/2026
The default stylesheet for DocBook on Red Hat Linux 6.2 through 7.2 is installed with an insecure option enabled, which could allow users to overwrite files outside of the current directory from an untrusted document by using a full pathname as an element identifier.
ModificadaMedia (4.6)0.33%—Kdeutils14/12/200116/6/2026
klprfax_filter in KDE2 KDEUtils allows local users to overwrite arbitrary files via a symlink attack on the klprfax.filter temporary file.
ModificadaAlta (7.2)0.90%💥 ExploitGNU FindutilsSlackware Linux31/8/200116/6/2026
GNU locate in findutils 4.1 on Slackware 7.1 and 8.0 allows local users to gain privileges via an old formatted filename database (locatedb) that contains an entry with an out-of-range offset, which causes locate to write to arbitrary process memory.
ModificadaAlta (7.5)2.0%—ImmunixIputilsRedhat Linux18/10/200016/6/2026
ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, does not drop privileges after acquiring a raw socket, which increases ping's exposure to bugs that otherwise would occur at lower privileges.
ModificadaMedia (4.6)0.41%—ImmunixIputilsRedhat Linux18/10/200016/6/2026
Buffer overflows in the (1) outpack or (2) buf variables of ping in iputils before 20001010, as distributed on Red Hat Linux 6.2 through 7J and other operating systems, may allow local users to gain privileges.
Orbitaley — Vulnerabilidades