Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
–

695 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.7%—Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express11/5/200716/6/2026
Múltiples vulnerabilidades secuencias de comandos en sitios cruzados (XSS) en el Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107 y 6.6.2.2, posiblemente involucrando al Novell Groupwise Mobile Server y al Nokia Intellisync Wireless Email Express, permiten a atacantes remotos inyectar secuencias de comandos web o…
ModificadaMedia (6.4)1.5%—Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express11/5/200716/6/2026
Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107 y 6.6.2.2, posiblemente involucrando al Novell Groupwise Mobile Server y al Nokia Intellisync Wireless Email Express, permite a atacantes remotos obtener nombres de usuario y otra información sensible mediante una petición directa al (1) usrmgr/userList.asp o (2) al…
ModificadaAlta (7.5)1.8%—Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express11/5/200716/6/2026
El usrmgr/userList.asp en el Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107 y 6.6.2.2, posiblemente involucrando al Novell Groupwise Mobile Server y al Nokia Intellisync Wireless Email Express, permite a atacantes remotos modificar detalles de la cuenta del usuario y causar una denegación de servicio…
ModificadaAlta (7.5)3.6%—Andrew Tridgell Rsync28/4/200616/6/2026
Integer overflow in the receive_xattr function in the extended attributes patch (xattr.c) for rsync before 2.6.8 might allow attackers to execute arbitrary code via crafted extended attributes that trigger a buffer overflow.
ModificadaMedia (5)1.9%—Smart Technologies Synchroneyes6/4/200616/6/2026
SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service (memory consumption) via a certain packet to the Teacher discovery port that causes SynchronEyes to connect to the attacker's machine and read a value that is used as a parameter to malloc.
ModificadaAlta (7.8)2.2%—Smart Technologies Synchroneyes6/4/200616/6/2026
An unspecified "logical programming mistake" in SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service via a large packet to the Teacher discovery port (UDP port 5496), which causes a thread to terminate and prevents communications on that port.
ModificadaAlta (7.2)1.3%💥 ExploitIsync Mrouter22/1/200516/6/2026
Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code.
ModificadaMedia (6.4)2.3%—Andrew Tridgell Rsync20/10/200416/6/2026
Vulnerabilidad de atravesamiento de directorios en la función sanitize_path en util.c de rsync 2.6.2 y anteriores, cuando chroot está desactivado, permite a atacantes leer o escribir ciertos ficheros.
ModificadaMedia (5)3.4%—Andrew Tridgell Rsync7/7/200416/6/2026
rsync anteriores a 2.6.1 no limpia adecuadamente rutas cuando ejecuta un demonio de lectura y escritura sin usar chroot, lo que permite a atacantes remotos escribir ficheros fuera de la ruta del módulo.
ModificadaMedia (4.6)1.00%💥 ExploitRsyncAI9/2/200416/6/2026
Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond…
ModificadaAlta (7.5)21%—Andrew Tridgell RsyncRedhat RsyncEngardelinux Secure CommunityEngardelinux Secure Linux+115/12/200316/6/2026
Desbordamiento de búfer en el montón en rsync anteriores a 2.5.7, cuando se ejecuta en modo servidor, permite a atacantes remotos ejecutar código arbitrario y posiblemente escapar del confinamiento chroot.
ModificadaBaja (2.1)0.53%—Samba RsyncRedhat Linux15/3/200216/6/2026
rsync no llama adecuadamente a 'setgroups' antes de establecer los permisos, lo cual podría proveer de ciertos privilegios de grupo a usuarios locales, los cuales podrían leer ciertos ficheros que de otro modo les estarían vetados.
ModificadaAlta (10)34%💥 ExploitAndrew Tridgell Rsync27/2/200216/6/2026
Errores de mezclado de números con y sin signo en las funciones I/O de rsync, versiones 2.4.6, 2.3.2 y otras versiones, permite que atacantes remotos provoquen una denegación de servicio y ejecuten código arbitrario en el cliente o servidor rsync.
ModificadaMedia (5)1.1%—Starfish Truesync Desktop31/8/200116/6/2026
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack.
ModificadaMedia (5)1.1%—Starfish Truesync Desktop31/8/200116/6/2026
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to restrict access, which allows an attacker to read the files using a different application.
ModificadaAlta (7.5)0.71%—Starfish Truesync Desktop31/8/200116/6/2026
Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the password and gain privileges.
ModificadaAlta (10)6.0%💥 ExploitAtrius Trivalie SN Time Sync1/6/200016/6/2026
Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long string.
ModificadaMedia (5)1.4%—Handspring Visor Network Hotsync5/1/200016/6/2026
Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files.
ModificadaAlta (7.5)1.8%—Palm Pilot Hotsync Manager4/11/199916/6/2026
Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode.
ModificadaBaja (2.1)0.32%—Andrew Tridgell Rsync7/4/199916/6/2026
The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.