Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

135 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.80%💥 ExploitMandrakesoft Mandrake Multi Network FirewallConectiva LinuxGentoo LinuxLinux Kernel+56/12/200416/6/2026
Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.
ModificadaMedia (5)18%💥 ExploitEthereal Group EtherealGentoo LinuxMandrakesoft Mandrake LinuxRedhat Enterprise Linux+16/12/200416/6/2026
The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.
ModificadaBaja (2.1)0.36%—UserminWebminMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server20/10/200416/6/2026
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.
ModificadaAlta (7.5)1.9%—KDE KonquerorGentoo LinuxKDEMandrakesoft Mandrake Linux+120/10/200416/6/2026
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
ModificadaAlta (7.5)5.0%—ROB Flynn GaimGentoo LinuxMandrakesoft Mandrake Linux28/9/200416/6/2026
Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.
ModificadaAlta (7.5)5.5%—Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+1016/9/200416/6/2026
Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.
ModificadaMedia (5)17%—Apache Http ServerHP Secure WEB Server FOR Tru64Gentoo LinuxHp-ux+816/9/200416/6/2026
The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
ModificadaMedia (5)5.5%—SambaSGI SambaConectiva LinuxMandrakesoft Mandrake Linux+113/9/200416/6/2026
Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.
ModificadaAlta (10)17%—Infoblox DNS ONE ApplianceISC DhcpdSuse Email ServerSuse Linux Admin-cd FOR Firewall+76/8/200416/6/2026
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and…
ModificadaAlta (10)45%—Infoblox DNS ONE ApplianceISC DhcpdSuse Email ServerSuse Linux Admin-cd FOR Firewall+76/8/200416/6/2026
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which…
ModificadaBaja (2.1)0.47%—Mandrakesoft Mandrake Multi Network FirewallSuse Email ServerSuse Linux Admin-cd FOR FirewallSuse Linux Connectivity Server+136/8/200416/6/2026
The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources.
ModificadaMedia (4.6)0.37%—GNU KsymoopsMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server6/8/200416/6/2026
ksymoops-gznm script in Mandrake Linux 9.1 through 10.0, and Corporate Server 2.1, allows local users to delete arbitrary files via a symlink attack on files in /tmp.
ModificadaBaja (2.1)0.41%—Mandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Fedora CoreSuse Linux6/8/200416/6/2026
Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service.
ModificadaMedia (4.6)0.48%—XpcdMandrakesoft Mandrake Linux7/7/200416/6/2026
Buffer overflow in xpcd-svga in xpcd before 2.08, and possibly other versions, may allow local users to execute arbitrary code.
ModificadaAlta (10)27%💥 ExploitMplayerGentoo LinuxMandrakesoft Mandrake Linux4/5/200416/6/2026
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.
ModificadaMedia (5)1.7%—SUN SolarisSunosDebian LinuxMandrakesoft Mandrake Linux+116/2/200416/6/2026
Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).
ModificadaMedia (5)1.4%—IrssiMandrakesoft Mandrake Linux5/1/200416/6/2026
The format_send_to_gui function in formats.c for irssi before 0.8.9 allows remote IRC users to cause a denial of service (crash).
ModificadaBaja (1.2)0.65%💥 ExploitMandrakesoft Mandrake Multi Network FirewallLinux KernelMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server27/8/200316/6/2026
A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash).
ModificadaAlta (7.5)41%💥 ExploitAdobe AcrobatXpdfMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+324/7/200316/6/2026
Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink.
ModificadaAlta (10)3.5%—MIT Kerberos FTP ClientRedhat LinuxMandrakesoft Mandrake Multi Network FirewallMandrakesoft Mandrake Linux19/2/200316/6/2026
Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.
ModificadaMedia (4.6)1.1%💥 ExploitGnome BonoboMandrakesoft Mandrake LinuxRedhat LinuxSlackware Linux31/12/200216/6/2026
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long command line arguments.
ModificadaMedia (5.5)0.38%—Mandrakesoft Mandrake Linux31/12/200216/6/2026
The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-readable permissions, which could allow local users to read other user's files.
ModificadaBaja (1.2)0.29%—JmcceMandrakesoft Mandrake Linux31/12/200216/6/2026
jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack.
ModificadaMedia (4.9)2.5%—SGI IrixDebian LinuxMandrakesoft Mandrake LinuxMicrosoft Windows 98+731/12/200216/6/2026
The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network.
ModificadaAlta (7.5)8.0%—HP Secure OSMandrakesoft Mandrake LinuxRedhat Linux28/10/200216/6/2026
dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts.
Orbitaley — Vulnerabilidades