Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

65 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)5.3%—Ethereal Group EtherealGentoo LinuxMandrakesoft Mandrake LinuxRedhat Enterprise Linux+16/12/200416/6/2026
The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.
ModificadaAlta (7.5)1.6%—Avaya CvlanRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Linux Advanced Workstation23/11/200416/6/2026
Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI.
ModificadaMedia (5)1.7%—MozillaSGI PropackRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+318/10/200416/6/2026
Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.
ModificadaAlta (7.5)5.5%—Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+1016/9/200416/6/2026
Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.
ModificadaMedia (4.6)3.0%—Mozilla FirefoxMozillaNetscape NavigatorConectiva Linux+614/9/200416/6/2026
Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.
ModificadaMedia (5)2.1%—Gnome GdkpixbufRedhat GDK PixbufSGI PropackRedhat Enterprise Linux+115/4/200416/6/2026
gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.
ModificadaAlta (7.5)8.2%—Metamail Corporation MetamailSGI PropackRedhat Enterprise LinuxRedhat Linux Advanced Workstation3/3/200416/6/2026
Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
ModificadaAlta (7.5)26%💥 ExploitMetamail Corporation MetamailSGI PropackRedhat Enterprise LinuxRedhat Linux Advanced Workstation3/3/200416/6/2026
Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
ModificadaMedia (4.9)0.38%—GNU GlibcGNU ZebraQuagga Routing Software SuiteSGI Propack+315/12/200316/6/2026
The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
ModificadaAlta (7.5)2.0%—Redhat Enterprise LinuxRedhat Linux Advanced Workstation27/8/200316/6/2026
The C-Media PCI sound driver in Linux before 2.4.21 does not use the get_user function to access userspace, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0700.
ModificadaMedia (5)1.5%—Gnome GDMRedhat KdebaseRedhat Enterprise LinuxRedhat Linux Advanced Workstation27/8/200316/6/2026
The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) when a chosen host expires, a different issue than CVE-2003-0549.
ModificadaMedia (5)1.5%—Gnome GDMRedhat KdebaseRedhat Enterprise LinuxRedhat Linux Advanced Workstation27/8/200316/6/2026
The X Display Manager Control Protocol (XDMCP) support for GDM before 2.4.1.6 allows attackers to cause a denial of service (daemon crash) via a short authorization key name.
ModificadaAlta (7.5)41%💥 ExploitAdobe AcrobatXpdfMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+324/7/200316/6/2026
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
ModificadaMedia (4.9)2.5%—SGI IrixDebian LinuxMandrakesoft Mandrake LinuxMicrosoft Windows 98+731/12/200216/6/2026
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
ModificadaMedia (4.6)0.46%—Safe.pmSUN LinuxSGI IrixRedhat Enterprise Linux+511/12/200216/6/2026
Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and earlier, may allow attackers to break out of safe compartments in (1) Safe::reval or (2) Safe::rdo using a redefined @_ variable, which is not reset between successive calls.