Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2773▼ 2 respecto a la semana anterior
Críticas / altas1273▼ 205 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 185 respecto a la semana anterior
1112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.39% | — | Freebsd | 12/4/2005 | 16/6/2026 | Multiple symlink vulnerabilities in portupgrade before 20041226_2 in FreeBSD allow local users to (1) overwrite arbitrary files and possibly replace packages to execute arbitrary code via pkg_fetch, (2) overwrite arbitrary files via temporary files when portupgrade upgrades a port or package, or (3) create arbitrary… | |
| Modificada | Media (5.6) | 0.51% | — | FreebsdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+4 | 5/3/2005 | 16/6/2026 | Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack… | |
| Modificada | Alta (10) | 3.1% | — | Freebsd Fetch | 1/3/2005 | 16/6/2026 | Integer overflow in fetch on FreeBSD 4.1 through 5.3 allows remote malicious servers to execute arbitrary code via certain HTTP headers in an HTTP response, which lead to a buffer overflow. | |
| Modificada | Media (5) | 1.6% | — | Openbsd | 13/1/2005 | 16/6/2026 | The TCP stack (tcp_input.c) in OpenBSD 3.5 and 3.6 allows remote attackers to cause a denial of service (system panic) via crafted values in the TCP timestamp option, which causes invalid arguments to be used when calculating the retransmit timeout. | |
| Modificada | Baja (3.6) | 0.32% | — | Freebsd | 10/1/2005 | 16/6/2026 | Los pseudoficheros cmdline en procfs en FreeBSD 4.8 a 5.3, y linprocfs en FreeBSD 5.x a 5.3 no validan adecuadamente un vector de argumento de proceso, lo que permite a usuarios locales causar una denegación de servicio (pánico) o leer porciones de memoria del kernle. NOTA: Esta candidata puede ser separada en dos… | |
| Modificada | Baja (2.1) | 0.35% | — | Openbsd | 31/12/2004 | 16/6/2026 | Heap-based buffer overflow in isakmpd on OpenBSD 3.4 through 3.6 allows local users to cause a denial of service (panic) and corrupt memory via IPSEC credentials on a socket. | |
| Modificada | Alta (7.1) | 7.7% | 💥 Exploit | CVSOpenpkgSGI PropackFreebsd+2 | 31/12/2004 | 16/6/2026 | Format string vulnerability in wrapper.c in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16 allows remote attackers with CVSROOT commit access to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a wrapper line. | |
| Modificada | Alta (7.5) | 1.7% | — | Openbsd | 31/12/2004 | 16/6/2026 | login_radius on OpenBSD 3.2, 3.5, and possibly other versions does not verify the shared secret in a response packet from a RADIUS server, which allows remote attackers to bypass authentication by spoofing server replies. | |
| Modificada | Media (4.6) | 0.42% | — | Freebsd | 31/12/2004 | 16/6/2026 | The syscons CONS_SCRSHOT ioctl in FreeBSD 5.x allows local users to read arbitrary kernel memory via (1) negative coordinates or (2) large coordinates. | |
| Modificada | Alta (7.2) | 0.85% | 💥 Exploit | Niels Provos SystraceVladimir Kotal Systrace Port FOR FreebsdNetbsd | 31/12/2004 | 16/6/2026 | The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges. | |
| Modificada | Alta (7.5) | 1.5% | — | Openbsd | 31/12/2004 | 16/6/2026 | PF in certain OpenBSD versions, when stateful filtering is enabled, does not limit packets for a session to the original interface, which allows remote attackers to bypass intended packet filters via spoofed packets to other interfaces. | |
| Modificada | Media (6.8) | 8.7% | — | Openbsd Openssh | 31/12/2004 | 16/6/2026 | sshd in OpenSSH 3.5p1, when PermitRootLogin is disabled, immediately closes the TCP connection after a root login attempt with the correct password, but leaves the connection open after an attempt with an incorrect password, which makes it easier for remote attackers to guess the password by observing the connection… | |
| Modificada | Media (5) | 3.4% | — | Openbsd Openssh | 31/12/2004 | 16/6/2026 | sshd.c in OpenSSH 3.6.1p2 and 3.7.1p2 and possibly other versions, when using privilege separation, does not properly signal the non-privileged process when a session has been terminated after exceeding the LoginGraceTime setting, which leaves the connection open and allows remote attackers to cause a denial of… | |
| Modificada | Alta (7.5) | 1.5% | — | Openbsd | 31/12/2004 | 16/6/2026 | OpenBSD 3.3 and 3.4 does not properly parse Accept and Deny rules without netmasks on big-endian 64-bit platforms such as SPARC64, which may allow remote attackers to bypass access restrictions. | |
| Modificada | Alta (7.2) | 0.41% | — | Netbsd | 18/12/2004 | 16/6/2026 | Multiple buffer overflows in NetBSD kernel may allow local users to execute arbitrary code and gain privileges. | |
| Modificada | Baja (2.1) | 0.33% | — | Netbsd | 16/12/2004 | 16/6/2026 | Multiple syscalls in the compat subsystem for NetBSD before 2.0 allow local users to cause a denial of service (kernel crash) via a large signal number to (1) xxx_sys_kill, (2) xxx_sys_sigaction, and possibly other translation functions. | |
| Modificada | Baja (2.1) | 0.85% | 💥 Exploit | Freebsd | 6/12/2004 | 16/6/2026 | FreeBSD 5.1 para procesadores Alfa permite a usuarios locales causar una denegación de servicio (caída) mediante una llamada de sistema con una dirección de memoria no alineada como argumento. | |
| Modificada | Baja (2.1) | 0.38% | — | Freebsd | 6/12/2004 | 16/6/2026 | El modo de compatibilidad binaria de FreeBSD 4.x y 5.x no maneja adecuadamente ciertas llamadas al sistema de Linux, lo que podría permitir a usuarios locales acceder a memoria del kernel para ganar privilegios o causar un pánico de sistema. | |
| Modificada | Alta (7.5) | 9.5% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo. | |
| Modificada | Media (5) | 10% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+61 | 23/11/2004 | 16/6/2026 | El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio. | |
| Modificada | Media (5) | 2.5% | — | NetbsdOpenbsd | 23/11/2004 | 16/6/2026 | OpenBSD 3.4 y NetBSD 1.6 y 1.6.1 permiten a atacantes remotos causar una denegación de servicio (caida) enviand un paquete IPv6 con una MTU pequeña a un puerto en escucha y a continuación un conectar TCP a ese puerto. | |
| Modificada | Media (5) | 7.2% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | OpenSSL 0.9.6 anteriores a la 0.9.6d no manejan adecuadamente los tipos de mensajes desconocidos, lo que permite a atacantes remotos causar una denegación de servicios (por bucle infinito), como se demuestra utilizando la herramienta de testeo Codenomicon TLS. | |
| Modificada | Alta (7.2) | 0.56% | — | Debian Bsdmainutils | 20/10/2004 | 16/6/2026 | El programa de calendario en bsdmainutils 6.0 a 6.0.14 cuando se ejecuta con la opción -a, no suelta los privilegios de root, lo que permite a atacantes ejecutar órdenes de su elección mediante un cierto fichero de evento de calendario. | |
| Modificada | Alta (7.5) | 8.1% | — | X.org X11r6Xfree86 Project X11r6OpenbsdSuse Linux | 20/10/2004 | 16/6/2026 | Múltiples desbordamientos de búfer basados en la pila en (1) xpmParseColors en parse.c, (2) ParseAndPutPixels en create.c, y (3) ParsePixels en parse.c de libXpm anteriores a 6.8.1 permite a atacantes remotos ejecutar código de su elección mediante una imagen XPM malformada. | |
| Modificada | Alta (7.5) | 7.2% | — | X.org X11r6Xfree86 Project X11r6OpenbsdSuse Linux | 20/10/2004 | 16/6/2026 | Múltiples desbordamientos de búfer en xpmParseColors en parse.c de libXpm anteriores a 6.8.1 permite a atacantes remotos ejecutar código arbitrario mediante un fichero de imagen XPM malformado. |