Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

72 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)45%—Avaya Converged Communications ServerRedhat Fedora CoreTrustix Secure LinuxAvaya Integrated Management+427/7/200416/6/2026
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the…
ModificadaMedia (5)3.7%—SambaTrustix Secure Linux27/7/200416/6/2026
Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors.
ModificadaMedia (5.1)55%—OpenpkgAvaya Converged Communications ServerDebian LinuxHp-ux+227/7/200416/6/2026
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor…
ModificadaAlta (7.5)11%—Francisco Burzi Php-nukeOscommerce Osc2nukePaul Laudanski Betanc Php-nukeTrustix Secure Linux1/6/200416/6/2026
PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path…
ModificadaAlta (7.2)2.4%—Redhat Bigmem KernelRedhat KernelRedhat Kernel DOCRedhat Kernel Source+33/3/200416/6/2026
The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than…
ModificadaAlta (7.5)21%—Andrew Tridgell RsyncRedhat RsyncEngardelinux Secure CommunityEngardelinux Secure Linux+115/12/200316/6/2026
Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail.
ModificadaBaja (2.1)0.37%—Linux KernelTrustix Secure Linux11/12/200216/6/2026
The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs.
ModificadaCrítica (9.8)15%—ImmunixMandrakesoft Mandrake Single Network FirewallOpenbsd OpensshOpenpkg+715/3/200216/6/2026
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
ModificadaAlta (7.5)5.3%—StunnelEngardelinux Secure LinuxMandrakesoft Mandrake LinuxRedhat Linux31/1/200216/6/2026
Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code.
ModificadaBaja (2.1)0.81%—ImmunixUniversity OF Washington PineEngardelinux Secure LinuxMandrakesoft Mandrake Linux+218/10/200116/6/2026
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.
ModificadaAlta (7.2)0.39%—Engardelinux Secure Linux18/10/200116/6/2026
Guardian Digital WebTool in EnGarde Secure Linux 1.0.1 allows restarted services to inherit some environmental variables, which could allow local users to gain root privileges.
ModificadaAlta (7.5)2.0%—Caldera Openlinux ServerImmunixMandrakesoft Mandrake Single Network FirewallSquid WEB Proxy+418/7/200116/6/2026
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
ModificadaAlta (10)1.8%—Engardelinux Secure Linux11/7/200116/6/2026
The default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to gain full root access.
ModificadaBaja (2.1)0.86%—Mandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat LinuxTrustix Secure Linux+126/3/200116/6/2026
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
ModificadaBaja (1.2)0.30%—ImmunixNational Science Foundation Squid WEB ProxyMandrakesoft Mandrake LinuxRedhat Linux+112/3/200116/6/2026
squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.
ModificadaBaja (1.2)0.37%—ImmunixMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Linux+112/3/200116/6/2026
sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.
ModificadaAlta (10)79%—Caldera Openlinux EbuilderCaldera OpenlinuxCaldera Openlinux EdesktopCaldera Openlinux Eserver+219/12/200023/9/2026
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands.
ModificadaAlta (7.2)1.1%—Redhat LinuxTrustix Secure Linux11/12/200016/6/2026
dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program.
ModificadaAlta (10)16%—Caldera Openlinux EbuilderImmunixConectiva LinuxSGI Irix+1214/11/200016/6/2026
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen.
ModificadaAlta (7.2)0.41%—Debian LinuxMandrakesoft Mandrake LinuxRedhat LinuxSlackware Linux+114/11/200016/6/2026
Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages.
ModificadaMedia (4.6)0.32%—Trustix Secure Linux20/10/200016/6/2026
Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse.
ModificadaAlta (10)26%—Conectiva LinuxDebian LinuxRedhat LinuxSuse Linux+116/7/200016/6/2026
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges.