Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.4) | 2.6% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+4 | 10/1/2005 | 16/6/2026 | The smb_recv_trans2 function call in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 does not properly handle the re-assembly of fragmented packets correctly, which could allow remote samba servers to (1) read arbitrary kernel information or (2) raise a counter value to an arbitrary number by sending the… | |
| Modificada | Baja (2.1) | 0.45% | — | Easy Software Products CupsRedhat Fedora Core | 10/1/2005 | 16/6/2026 | lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message. | |
| Modificada | Baja (2.1) | 0.81% | 💥 Exploit | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+4 | 10/1/2005 | 16/6/2026 | The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality. | |
| Modificada | Media (6.4) | 4.2% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+4 | 10/1/2005 | 16/6/2026 | Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to the smb_proc_read function, (2) returning a data offset from… | |
| Modificada | Alta (7.2) | 0.51% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+4 | 10/1/2005 | 16/6/2026 | The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code. | |
| Modificada | Alta (7.2) | 0.56% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+4 | 10/1/2005 | 16/6/2026 | The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and… | |
| Modificada | Alta (10) | 8.7% | — | LesstifX.org X11r6Xfree86 Project X11r6Gentoo Linux+2 | 10/1/2005 | 16/6/2026 | Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive… | |
| Modificada | Alta (10) | 5.8% | — | Carnegie Mellon University Cyrus Imap ServerOpenpkgConectiva LinuxRedhat Fedora Core+2 | 10/1/2005 | 16/6/2026 | The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p") that cause an index increment error that leads to an out-of-bounds memory corruption. | |
| Modificada | Alta (7.2) | 0.51% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+4 | 10/1/2005 | 16/6/2026 | The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code. | |
| Modificada | Media (5) | 9.0% | 💥 Exploit | Easy Software Products CupsRedhat Fedora Core | 10/1/2005 | 16/6/2026 | lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to passwd.new, which causes subsequent invocations of lppasswd to fail. | |
| Modificada | Alta (10) | 5.2% | — | Carnegie Mellon University Cyrus Imap ServerRedhat Fedora CoreUbuntu Linux | 10/1/2005 | 16/6/2026 | Buffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the imapmagicplus option enabled, may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2004-1011. | |
| Modificada | Baja (2.1) | 0.45% | — | KDEMandrakesoft Mandrake LinuxRedhat Fedora Core | 10/1/2005 | 16/6/2026 | KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames… | |
| Modificada | Media (6.5) | 6.3% | 💥 Exploit | Easy Software Products CupsRedhat Fedora Core | 10/1/2005 | 16/6/2026 | Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attackers to execute arbitrary code via a crafted HPGL file. | |
| Modificada | Alta (10) | 5.8% | — | Carnegie Mellon University Cyrus Imap ServerOpenpkgConectiva LinuxRedhat Fedora Core+2 | 10/1/2005 | 16/6/2026 | Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with the imapmagicplus option enabled, allows remote attackers to execute arbitrary code via a long (1) PROXY or (2) LOGIN command, a different vulnerability than CVE-2004-1015. | |
| Modificada | Alta (10) | 5.2% | — | Carnegie Mellon University Cyrus Imap ServerRedhat Fedora CoreUbuntu Linux | 10/1/2005 | 16/6/2026 | Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username. | |
| Modificada | Alta (10) | 13% | — | SambaRedhat Fedora CoreSuse LinuxTrustix Secure Linux | 10/1/2005 | 16/6/2026 | Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a Samba request with a large number of security descriptors that triggers a heap-based buffer overflow. | |
| Modificada | Baja (2.1) | 0.45% | — | Easy Software Products CupsRedhat Fedora Core | 10/1/2005 | 16/6/2026 | lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors. | |
| Modificada | Alta (7.5) | 4.9% | — | Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+12 | 31/12/2004 | 16/6/2026 | Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file. | |
| Modificada | Alta (10) | 8.0% | — | Mozilla FirefoxMozillaMozilla ThunderbirdNetscape Navigator+6 | 31/12/2004 | 16/6/2026 | Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows. | |
| Modificada | Media (5.1) | 3.4% | — | Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+12 | 31/12/2004 | 16/6/2026 | Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817. | |
| Modificada | Alta (7.5) | 8.3% | — | LibtiffPdflib PDF LibraryWxgtk2Apple MAC OS X+9 | 23/12/2004 | 16/6/2026 | Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files. | |
| Modificada | Baja (2.1) | 0.96% | 💥 Exploit | Linux KernelRedhat Fedora CoreRedhat Linux | 15/12/2004 | 16/6/2026 | Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow. | |
| Modificada | Baja (2.1) | 1.0% | 💥 Exploit | Linux KernelRedhat Fedora CoreRedhat Linux | 15/12/2004 | 16/6/2026 | Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function. | |
| Modificada | Alta (7.2) | 0.49% | — | Redhat Fedora CoreRedhat LinuxRedhat Kernel | 6/12/2004 | 16/6/2026 | Integer overflow in the ubsec_keysetup function for Linux Broadcom 5820 cryptonet driver allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a negative add_dsa_buf_bytes variable, which leads to a buffer overflow. | |
| Modificada | Baja (2.1) | 0.77% | 💥 Exploit | Linux KernelRedhat Fedora CoreTrustix Secure Linux | 23/11/2004 | 16/6/2026 | Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory. |