Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
1112 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 12% | — | ISC BindFreebsdOpenbsd | 29/11/2002 | 16/6/2026 | Desbordamiento de búfer en BIND versiones 4 anteriores a 4.9.10, y versiones 8 anteriores a 8.3.3, permite a atacantes remotos ejecutar código arbitrario mediante una cierta respuesta de servidor DNS conteniendo registros de recursos (RR) SIG. | |
| Modificada | Media (5) | 2.5% | — | Frees WANApple MAC OS XApple MAC OS X ServerFreebsd+8 | 4/11/2002 | 16/6/2026 | Implementaciones de IPSEC, incluyendo FreeS/WAN y KAME no calculan adecuadamente la longitud de los datos de autenticación, lo que permite a atacantes remotos causar una denegación de servicio (kernel panic) mediante paquetes Encapsulating Security Payload (EPS) cortos falsificados, lo que resulta en errores de… | |
| Modificada | Media (4.6) | 0.71% | 💥 Exploit | RogueNetbsd | 28/10/2002 | 16/6/2026 | Multiple buffer overflows in rogue on NetBSD 1.6 and earlier, FreeBSD 4.6, and possibly other operating systems, allows local users to gain "games" group privileges via malformed entries in a game save file. | |
| Modificada | Alta (7.5) | 3.2% | — | Netbsd | 28/10/2002 | 16/6/2026 | Desbordamiento de búfer en talkd en NetBSD 1.6 y anteriores, y posiblemente otros sistemas operativos, pueden permitir a atacantes remotos ejecutar código arbitrario mediante un mensaje largo entrante. | |
| Modificada | Media (4.6) | 1.1% | 💥 Exploit | SendmailNetbsd | 11/10/2002 | 16/6/2026 | Sendmail Consortium's Restricted Shell (SMRSH) en Sendmail 8.12.6, 8.11.6-15 y anteriores, permite a atacantes puentear las restricciones pretendidas de smrsh insertando caractéres adicionales después de secuencias "||" (dos barras verticales) o "/" (barra), que no son adecuadamente filtradas o verificadas. | |
| Modificada | Media (4.6) | 0.35% | — | Freebsd | 24/9/2002 | 16/6/2026 | Integer signedness error in several system calls for FreeBSD 4.6.1 RELEASE-p10 and earlier may allow attackers to access sensitive kernel memory via large negative values to the (1) accept, (2) getsockname, and (3) getpeername system calls, and the (4) vesa FBIO_GETPALETTE ioctl. | |
| Modificada | Baja (2.1) | 0.79% | 💥 Exploit | Freebsd | 24/9/2002 | 16/6/2026 | Programas portados a FreeBSD que usan libkvm para FreeBSD 4.6.2-RELEASE y anteriores, incluyendo asmon, ascpu, bubblemon, wmmon, y wmnet2, dejan abiertos descriptores de ficheros para /dev/mem y /dev/kmem, lo que permite a usuarios locales leer la memoria del kernel. | |
| Modificada | Baja (2.1) | 0.33% | — | Freebsd | 12/8/2002 | 16/6/2026 | The kqueue mechanism in FreeBSD 4.3 through 4.6 STABLE allows local users to cause a denial of service (kernel panic) via a pipe call in which one end is terminated and an EVFILT_WRITE filter is registered for the other end. | |
| Modificada | Baja (2.1) | 0.47% | — | Freebsd | 12/8/2002 | 16/6/2026 | The rc system startup script for FreeBSD 4 through 4.5 allows local users to delete arbitrary files via a symlink attack on X Windows lock files. | |
| Modificada | Alta (7.2) | 0.59% | — | Openbsd | 12/8/2002 | 16/6/2026 | OpenBSD 2.9 through 3.1 allows local users to cause a denial of service (resource exhaustion) and gain root privileges by filling the kernel's file descriptor table and closing file descriptors 0, 1, or 2 before executing a privileged process, which is not properly handled when OpenBSD fails to open an alternate… | |
| Modificada | Alta (7.5) | 1.3% | — | Openbsd OpensshOpenbsd | 12/8/2002 | 16/6/2026 | sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user's password. | |
| Modificada | Media (5) | 2.5% | — | Freebsd | 12/8/2002 | 16/6/2026 | Los mecanismos SYN cache (syncache) y SYN cookie (syncookie) en FreeBSD 4.5 y anteriores, permite a atacantes remotos provocar la Denegación de Servicios (por caida) por algunos de los siguiente métodos: mediante un paquete SYN aceptado utilizando syncookies, que provoca que las opciones TCP del conector (socket)… | |
| Modificada | Alta (7.5) | 1.4% | — | FreebsdNetbsdOpenbsd | 12/8/2002 | 16/6/2026 | KAME-derived implementations of IPsec on NetBSD 1.5.2, FreeBSD 4.5, and other operating systems, does not properly consult the Security Policy Database (SPD), which could cause a Security Gateway (SG) that does not use Encapsulating Security Payload (ESP) to forward forged IPv4 packets. | |
| Modificada | Alta (7.2) | 0.45% | — | Freebsd | 12/8/2002 | 16/6/2026 | Kerberos 5 su (k5su) en FreeBSD 4.5 y anteriores no verifican que el usuario sea miembro del grupo antes de otorgarle privilegios de superusuario, de modo podría permitir a usuarios no autorizados la ejecución de comandos como root. | |
| Modificada | Media (6.9) | 0.66% | 💥 Exploit | Freebsd Point-to-point Protocol Daemon | 12/8/2002 | 16/6/2026 | BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device. | |
| Modificada | Media (5) | 2.0% | — | Openbsd | 12/8/2002 | 16/6/2026 | PF en OpenBSD 3.0 con la regla return-rst establece el TTL (Time to Live) a 128 en el paquete RST, lo que permite a atacantes remotos determinar si un puerto está siendo filtrado porque el TTL es diferente del de por defecto. | |
| Modificada | Media (4.6) | 0.33% | — | Freebsd | 12/8/2002 | 16/6/2026 | Integer overflow in the Berkeley Fast File System (FFS) in FreeBSD 4.6.1 RELEASE-p4 and earlier allows local users to access arbitrary file contents within FFS to gain privileges by creating a file that is larger than allowed by the virtual memory system. | |
| Modificada | Alta (7.2) | 0.41% | — | Freebsd | 12/8/2002 | 16/6/2026 | FreeBSD kernel 4.6 and earlier closes the file descriptors 0, 1, and 2 after they have already been assigned to /dev/null when the descriptors reference procfs or linprocfs, which could allow local users to reuse the file descriptors in a setuid or setgid program to modify critical data and gain privileges. | |
| Modificada | Crítica (9.8) | 58% | — | FreebsdOpenbsdSUN SolarisSunos+3 | 12/8/2002 | 16/6/2026 | Integer overflow in xdr_array function in RPC servers for operating systems that use libc, glibc, or other code based on SunRPC including dietlibc, allows remote attackers to execute arbitrary code by passing a large number of arguments to xdr_array through RPC services such as rpc.cmsd and dmispd. | |
| Modificada | Media (5) | 1.6% | — | Freebsd | 12/8/2002 | 16/6/2026 | The accept_filter mechanism in FreeBSD 4 through 4.5 does not properly remove entries from the incomplete listen queue when adding a syncache, which allows remote attackers to cause a denial of service (network service availability) via a large number of connection attempts, which fills the queue. | |
| Modificada | Media (5) | 1.8% | — | Freebsd | 12/8/2002 | 16/6/2026 | Network File System (NFS) in FreeBSD 4.6.1 RELEASE-p7 and earlier, NetBSD 1.5.3 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service (hang) via an RPC message with a zero length payload, which causes NFS to reference a previous payload and enter an infinite loop. | |
| Modificada | Alta (7.2) | 0.37% | — | ImmunixNetbsdOpenbsdRedhat Linux | 12/8/2002 | 16/6/2026 | Vulnerabilidad de cadena de formato en la función startprinting() de printjob.c en el paquete lpr lpd basado en BSD puede permitir a usuarios locales ganar privilegios mediante una llamada impropia a syslog que usa cadenas de formato de la llamada checkremote(). | |
| Modificada | Alta (7.2) | 0.39% | — | Freebsd HeimdalKTH HeimdalFreebsd | 12/8/2002 | 16/6/2026 | Kerberos 5 su (k5su) en FreeBSD 4.4 y anteriores se basa en la llamada al sistema getlogin para determinar si el usuario que esta ejecutando k5su es root, lo cual podría permitir a procesos sin privilegios, la obtención de permisos si ese proceso tiene un getlogin como root. | |
| Modificada | Baja (2.1) | 0.33% | — | FreebsdOpenbsd | 23/7/2002 | 16/6/2026 | ktrace en sistemas opertativos basados en BSD permite al propietario de un proceso con privilegios especiales trazar el proceso después de que sus privilegios han sido bajados, lo que puede permitir al propietario obtener información sensible que el proceso obtuviera mientras corría con privilegios extra. | |
| Modificada | Alta (7.5) | 1.2% | — | Openbsd | 3/7/2002 | 16/6/2026 | Vulnerability in OpenBSD 3.0, when using YP with netgroups in the password database, causes (1) rexec or (2) rsh to run another user's shell, or (3) atrun to change to a different user's directory, possibly due to memory allocation failures or an incorrect call to auth_approval(). |