Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
695 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 2.7% | — | Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express | 11/5/2007 | 16/6/2026 | Múltiples vulnerabilidades secuencias de comandos en sitios cruzados (XSS) en el Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107 y 6.6.2.2, posiblemente involucrando al Novell Groupwise Mobile Server y al Nokia Intellisync Wireless Email Express, permiten a atacantes remotos inyectar secuencias de comandos web o… | |
| Modificada | Media (6.4) | 1.5% | — | Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express | 11/5/2007 | 16/6/2026 | Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107 y 6.6.2.2, posiblemente involucrando al Novell Groupwise Mobile Server y al Nokia Intellisync Wireless Email Express, permite a atacantes remotos obtener nombres de usuario y otra información sensible mediante una petición directa al (1) usrmgr/userList.asp o (2) al… | |
| Modificada | Alta (7.5) | 1.8% | — | Nokia Groupwise Mobile ServerNokia Intellisync Mobile SuiteNokia Intellisync Wireless Email Express | 11/5/2007 | 16/6/2026 | El usrmgr/userList.asp en el Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107 y 6.6.2.2, posiblemente involucrando al Novell Groupwise Mobile Server y al Nokia Intellisync Wireless Email Express, permite a atacantes remotos modificar detalles de la cuenta del usuario y causar una denegación de servicio… | |
| Modificada | Alta (7.5) | 3.6% | — | Andrew Tridgell Rsync | 28/4/2006 | 16/6/2026 | Integer overflow in the receive_xattr function in the extended attributes patch (xattr.c) for rsync before 2.6.8 might allow attackers to execute arbitrary code via crafted extended attributes that trigger a buffer overflow. | |
| Modificada | Media (5) | 1.9% | — | Smart Technologies Synchroneyes | 6/4/2006 | 16/6/2026 | SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service (memory consumption) via a certain packet to the Teacher discovery port that causes SynchronEyes to connect to the attacker's machine and read a value that is used as a parameter to malloc. | |
| Modificada | Alta (7.8) | 2.2% | — | Smart Technologies Synchroneyes | 6/4/2006 | 16/6/2026 | An unspecified "logical programming mistake" in SMART SynchronEyes Student and Teacher 6.0, and possibly earlier versions, allows remote attackers to cause a denial of service via a large packet to the Teacher discovery port (UDP port 5496), which causes a thread to terminate and prevents communications on that port. | |
| Modificada | Alta (7.2) | 1.3% | 💥 Exploit | Isync Mrouter | 22/1/2005 | 16/6/2026 | Buffer overflow in the (1) -v and (2) -a switches in mRouter in iSync 1.5 in Mac OS X 10.3.7 and earlier allows local users to execute arbitrary code. | |
| Modificada | Media (6.4) | 2.3% | — | Andrew Tridgell Rsync | 20/10/2004 | 16/6/2026 | Vulnerabilidad de atravesamiento de directorios en la función sanitize_path en util.c de rsync 2.6.2 y anteriores, cuando chroot está desactivado, permite a atacantes leer o escribir ciertos ficheros. | |
| Modificada | Media (5) | 3.4% | — | Andrew Tridgell Rsync | 7/7/2004 | 16/6/2026 | rsync anteriores a 2.6.1 no limpia adecuadamente rutas cuando ejecuta un demonio de lectura y escritura sin usar chroot, lo que permite a atacantes remotos escribir ficheros fuera de la ruta del módulo. | |
| Modificada | Media (4.6) | 1.00% | 💥 Exploit | RsyncAI | 9/2/2004 | 16/6/2026 | Buffer overflow in the open_socket_out function in socket.c for rsync 2.5.7 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long RSYNC_PROXY environment variable. NOTE: since rsync is not setuid, this issue does not provide any additional privileges beyond… | |
| Modificada | Alta (7.5) | 21% | — | Andrew Tridgell RsyncRedhat RsyncEngardelinux Secure CommunityEngardelinux Secure Linux+1 | 15/12/2003 | 16/6/2026 | Desbordamiento de búfer en el montón en rsync anteriores a 2.5.7, cuando se ejecuta en modo servidor, permite a atacantes remotos ejecutar código arbitrario y posiblemente escapar del confinamiento chroot. | |
| Modificada | Baja (2.1) | 0.53% | — | Samba RsyncRedhat Linux | 15/3/2002 | 16/6/2026 | rsync no llama adecuadamente a 'setgroups' antes de establecer los permisos, lo cual podría proveer de ciertos privilegios de grupo a usuarios locales, los cuales podrían leer ciertos ficheros que de otro modo les estarían vetados. | |
| Modificada | Alta (10) | 34% | 💥 Exploit | Andrew Tridgell Rsync | 27/2/2002 | 16/6/2026 | Errores de mezclado de números con y sin signo en las funciones I/O de rsync, versiones 2.4.6, 2.3.2 y otras versiones, permite que atacantes remotos provoquen una denegación de servicio y ejecuten código arbitrario en el cliente o servidor rsync. | |
| Modificada | Media (5) | 1.1% | — | Starfish Truesync Desktop | 31/8/2001 | 16/6/2026 | Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses a small keyspace for device keys and does not impose a delay when an incorrect key is entered, which allows attackers to more quickly guess the key via a brute force attack. | |
| Modificada | Media (5) | 1.1% | — | Starfish Truesync Desktop | 31/8/2001 | 16/6/2026 | Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA does not encrypt sensitive files and relies solely on its password feature to restrict access, which allows an attacker to read the files using a different application. | |
| Modificada | Alta (7.5) | 0.71% | — | Starfish Truesync Desktop | 31/8/2001 | 16/6/2026 | Starfish Truesync Desktop 2.0b as used on the REX 5000 PDA uses weak encryption to store the user password in a registry key, which allows attackers who have access to the registry key to decrypt the password and gain privileges. | |
| Modificada | Alta (10) | 6.0% | 💥 Exploit | Atrius Trivalie SN Time Sync | 1/6/2000 | 16/6/2026 | Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long string. | |
| Modificada | Media (5) | 1.4% | — | Handspring Visor Network Hotsync | 5/1/2000 | 16/6/2026 | Network HotSync program in Handspring Visor does not have authentication, which allows remote attackers to retrieve email and files. | |
| Modificada | Alta (7.5) | 1.8% | — | Palm Pilot Hotsync Manager | 4/11/1999 | 16/6/2026 | Palm Pilot HotSync Manager 3.0.4 in Windows 98 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 14238 while the manager is in network mode. | |
| Modificada | Baja (2.1) | 0.32% | — | Andrew Tridgell Rsync | 7/4/1999 | 16/6/2026 | The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred. |