Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 45% | — | Avaya Converged Communications ServerRedhat Fedora CoreTrustix Secure LinuxAvaya Integrated Management+4 | 27/7/2004 | 16/6/2026 | The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows dangerous tags to be processed by web browsers such as Internet Explorer and Safari, which ignore null characters and facilitate the… | |
| Modificada | Media (5) | 3.7% | — | SambaTrustix Secure Linux | 27/7/2004 | 16/6/2026 | Buffer overflow in Samba 2.2.x to 2.2.9, and 3.0.0 to 3.0.4, when the "mangling method = hash" option is enabled in smb.conf, has unknown impact and attack vectors. | |
| Modificada | Media (5.1) | 55% | — | OpenpkgAvaya Converged Communications ServerDebian LinuxHp-ux+2 | 27/7/2004 | 16/6/2026 | The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute arbitrary code by triggering a memory_limit abort during execution of the zend_hash_init function and overwriting a HashTable destructor… | |
| Modificada | Alta (7.5) | 11% | — | Francisco Burzi Php-nukeOscommerce Osc2nukePaul Laudanski Betanc Php-nukeTrustix Secure Linux | 1/6/2004 | 16/6/2026 | PHP-Nuke 7.3, and other products that use the PHP-Nuke codebase such as the Nuke Cops betaNC PHP-Nuke Bundle, OSCNukeLite 3.1, and OSC2Nuke 7x do not properly use the eregi() PHP function with $_SERVER['PHP_SELF'] to identify the calling script, which allows remote attackers to directly access scripts, obtain path… | |
| Modificada | Alta (7.2) | 2.4% | — | Redhat Bigmem KernelRedhat KernelRedhat Kernel DOCRedhat Kernel Source+3 | 3/3/2004 | 16/6/2026 | The do_mremap function for the mremap system call in Linux 2.2 to 2.2.25, 2.4 to 2.4.24, and 2.6 to 2.6.2, does not properly check the return value from the do_munmap function when the maximum number of VMA descriptors is exceeded, which allows local users to gain root privileges, a different vulnerability than… | |
| Modificada | Alta (7.5) | 21% | — | Andrew Tridgell RsyncRedhat RsyncEngardelinux Secure CommunityEngardelinux Secure Linux+1 | 15/12/2003 | 16/6/2026 | Heap-based buffer overflow in rsync before 2.5.7, when running in server mode, allows remote attackers to execute arbitrary code and possibly escape the chroot jail. | |
| Modificada | Baja (2.1) | 0.37% | — | Linux KernelTrustix Secure Linux | 11/12/2002 | 16/6/2026 | The Linux kernel 2.4.20 and earlier, and 2.5.x, when running on x86 systems, allows local users to cause a denial of service (hang) via the emulation mode, which does not properly clear TF and NT EFLAGs. | |
| Modificada | Crítica (9.8) | 15% | — | ImmunixMandrakesoft Mandrake Single Network FirewallOpenbsd OpensshOpenpkg+7 | 15/3/2002 | 16/6/2026 | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | |
| Modificada | Alta (7.5) | 5.3% | — | StunnelEngardelinux Secure LinuxMandrakesoft Mandrake LinuxRedhat Linux | 31/1/2002 | 16/6/2026 | Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code. | |
| Modificada | Baja (2.1) | 0.81% | — | ImmunixUniversity OF Washington PineEngardelinux Secure LinuxMandrakesoft Mandrake Linux+2 | 18/10/2001 | 16/6/2026 | Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack. | |
| Modificada | Alta (7.2) | 0.39% | — | Engardelinux Secure Linux | 18/10/2001 | 16/6/2026 | Guardian Digital WebTool in EnGarde Secure Linux 1.0.1 allows restarted services to inherit some environmental variables, which could allow local users to gain root privileges. | |
| Modificada | Alta (7.5) | 2.0% | — | Caldera Openlinux ServerImmunixMandrakesoft Mandrake Single Network FirewallSquid WEB Proxy+4 | 18/7/2001 | 16/6/2026 | Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning. | |
| Modificada | Alta (10) | 1.8% | — | Engardelinux Secure Linux | 11/7/2001 | 16/6/2026 | The default configuration of sudo in Engarde Secure Linux 1.0.1 allows any user in the admin group to run certain commands that could be leveraged to gain full root access. | |
| Modificada | Baja (2.1) | 0.86% | — | Mandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat LinuxTrustix Secure Linux+1 | 26/3/2001 | 16/6/2026 | When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib. | |
| Modificada | Baja (1.2) | 0.30% | — | ImmunixNational Science Foundation Squid WEB ProxyMandrakesoft Mandrake LinuxRedhat Linux+1 | 12/3/2001 | 16/6/2026 | squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations. | |
| Modificada | Baja (1.2) | 0.37% | — | ImmunixMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Linux+1 | 12/3/2001 | 16/6/2026 | sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack. | |
| Modificada | Alta (10) | 79% | — | Caldera Openlinux EbuilderCaldera OpenlinuxCaldera Openlinux EdesktopCaldera Openlinux Eserver+2 | 19/12/2000 | 23/9/2026 | Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. | |
| Modificada | Alta (7.2) | 1.1% | — | Redhat LinuxTrustix Secure Linux | 11/12/2000 | 16/6/2026 | dump in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which allows local users to obtain root privileges by modifying the RSH variable to point to a Trojan horse program. | |
| Modificada | Alta (10) | 16% | — | Caldera Openlinux EbuilderImmunixConectiva LinuxSGI Irix+12 | 14/11/2000 | 16/6/2026 | Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. | |
| Modificada | Alta (7.2) | 0.41% | — | Debian LinuxMandrakesoft Mandrake LinuxRedhat LinuxSlackware Linux+1 | 14/11/2000 | 16/6/2026 | Kernel logging daemon (klogd) in Linux does not properly cleanse user-injected format strings, which allows local users to gain root privileges by triggering malformed kernel messages. | |
| Modificada | Media (4.6) | 0.32% | — | Trustix Secure Linux | 20/10/2000 | 16/6/2026 | Trustix installs the httpsd program for Apache-SSL with world-writeable permissions, which allows local users to replace it with a Trojan horse. | |
| Modificada | Alta (10) | 26% | — | Conectiva LinuxDebian LinuxRedhat LinuxSuse Linux+1 | 16/7/2000 | 16/6/2026 | rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, which allows remote attackers to gain root privileges. |