Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
–

1112 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.6%💥 ExploitFreebsdOpenbsdSUN SolarisSunos3/7/200216/6/2026
FreeBSD 4.5 and earlier, and possibly other BSD-based operating systems, allows local users to write to or read from restricted files by closing the file descriptors 0 (standard input), 1 (standard output), or 2 (standard error), which may then be reused by a called setuid process that intended to perform I/O on…
ModificadaMedia (5)2.0%—Freebsd3/7/200216/6/2026
Memory leak in FreeBSD 4.5 and earlier allows remote attackers to cause a denial of service (memory exhaustion) via ICMP echo packets that trigger a bug in ip_output() in which the reference count for a routing table entry is not decremented, which prevents the entry from being removed.
ModificadaCrítica (9.8)18%—Openbsd Openssh3/7/200216/6/2026
Integer overflow in sshd in OpenSSH 2.9.9 through 3.3 allows remote attackers to execute arbitrary code during challenge response authentication (ChallengeResponseAuthentication) when OpenSSH is using SKEY or BSD_AUTH authentication.
ModificadaAlta (10)27%💥 ExploitOpenbsd Openssh3/7/200216/6/2026
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large number of responses during challenge response authentication when OpenBSD is using PAM modules with interactive keyboard authentication (PAMAuthenticationViaKbdInt).
ModificadaAlta (7.2)1.5%💥 ExploitOpenbsd3/7/200216/6/2026
mail in OpenBSD 2.9 and 3.0 processes a tilde (~) escape character in a message even when it is not in interactive mode, which could allow local users to gain root privileges via calls to mail in cron.
ModificadaMedia (5)2.0%—FreebsdNetbsdOpenbsd25/6/200216/6/2026
The TCP implementation in various BSD operating systems (tcp_input.c) does not properly block connections to broadcast addresses, which could allow remote attackers to bypass intended filters via packets with a unicast link layer address and an IP broadcast address.
ModificadaAlta (7.5)4.2%💥 ExploitOpenbsd Openssh18/6/200216/6/2026
Buffer overflow in OpenSSH before 2.9.9, and 3.x before 3.2.1, with Kerberos/AFS support and KerberosTgtPassing or AFSTokenPassing enabled, allows remote and local authenticated users to gain privileges.
ModificadaCrítica (9.8)15%💥 ExploitImmunixMandrakesoft Mandrake Single Network FirewallOpenbsd OpensshOpenpkg+715/3/200216/6/2026
Error 'off-by-one' en el código de canal de OpenSSH 2.0 a 3.0.2 permite a usuarios locales o a servidores remotos ganar privilegios.
ModificadaAlta (7.2)0.49%—Debian LinuxFreebsdRedhat LinuxSuse Linux+18/3/200223/7/2026
El desbordamiento del búfer en ncurses 5.0, y el paquete de compatibilidad ncurses4 basado en él, permite a usuarios locales la obtención de privilegios.
ModificadaAlta (7.2)1.3%💥 ExploitCaldera Openlinux ServerCaldera Openlinux WorkstationDebian LinuxFreebsd+527/2/200216/6/2026
Corrupción de memoria en el comando "at" permite que usuarios locales ejecuten código arbitrario haciendo uso de un tiempo de ejecución mal escrito (lo que provoca que at libere la misma memoria dos veces).
ModificadaAlta (7.5)2.2%—Openbsd Openssh31/12/200116/6/2026
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.
ModificadaAlta (7.2)0.40%—BSD NVI31/12/200116/6/2026
Format string vulnerability in nvi before 1.79 allows local users to gain privileges via format string specifiers in a filename.
ModificadaMedia (5.5)1.5%💥 ExploitOpenbsd31/12/200116/6/2026
The uipc system calls (uipc_syscalls.c) in OpenBSD 2.9 and 3.0 provide user mode return instead of versus rval kernel mode values to the fdrelease function, which allows local users to cause a denial of service and trigger a null dereference.
ModificadaAlta (7.2)0.60%—Bsdi BSD OS31/12/200116/6/2026
Buffer overflow in Unix-to-Unix Copy Protocol (UUCP) in BSDI BSD/OS 3.0 through 4.2 allows local users to execute arbitrary code via a long command line argument.
ModificadaMedia (6.8)1.9%—Openbsd Openssh31/12/200116/6/2026
SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 through 2001-02-08, does not perform a challenge-response step to ensure that the client has the proper private key, which allows remote attackers to bypass authentication as other users by…
ModificadaAlta (7.2)0.87%—Openbsd OpensshRedhat LinuxSuse Linux21/12/200116/6/2026
OpenSSH 3.0.1 y anteriores con UseLogin activado no limpia variables de entorno críticas como LD_PRELOAD, lo que permite a usuario locales ganar privilegios de root.
ModificadaMedia (6.2)0.81%💥 ExploitFreebsd10/12/200116/6/2026
Algunas operaciones AIO en FreeBSD 4.4 podrían ser retrasadas hasta la llamada a execve, lo cual, podría permitir a usuarios locales la sobreescritura en memorioa de nuevos procesos y la obtención de privilegios.
ModificadaAlta (7.5)1.8%—Openbsd Openssh6/12/200116/6/2026
OpenSSH before 2.9.9, when running sftp using sftp-server and using restricted keypairs, allows remote authenticated users to bypass authorized_keys2 command= restrictions using sftp commands.
ModificadaMedia (5)1.6%—SGI IrixFreebsd6/12/200116/6/2026
SGI IRIX 6.5 a 6.5.12f y posiblemente versiones anteriores, y FreeBSD 3.0, permiten a un atacante remoto producir una denegación de servicio mediante un paquete un paquete IGMP malformado con un pequeño retardo de respuesta.
ModificadaAlta (7.5)75%💥 ExploitDavid Madore Ftpd-bsdWashington University Wu-ftpd30/11/200116/6/2026
wu-ftpd 2.6.1 allows remote attackers to execute arbitrary commands via a "~{" argument to commands such as CWD, which is not properly handled by the glob function (ftpglob).
ModificadaMedia (4.6)0.31%—Openbsd13/11/200116/6/2026
vi.recover in OpenBSD before 3.1 allows local users to remove arbitrary zero-byte files such as device nodes.
ModificadaAlta (7.2)0.36%—Netbsd18/10/200116/6/2026
Hitachi Super-H architecture in NetBSD 1.5 and 1.4.1 allows a local user to gain privileges via modified Status Register contents, which are not properly handled by (1) the sigreturn system call or (2) the process_write_regs kernel routine.
ModificadaAlta (7.5)2.9%—Openbsd Openssh18/10/200116/6/2026
OpenSSH before 2.9.9, while using keypairs and multiple keys of different types in the ~/.ssh/authorized_keys2 file, may not properly handle the "from" option associated with a key, which could allow remote attackers to login from unauthorized IP addresses.
ModificadaAlta (7.5)6.6%—BSDFreebsdNetbsdOpenbsd3/10/200116/6/2026
Buffer overflow in BSD line printer daemon (in.lpd or lpd) in various BSD-based operating systems allows remote attackers to execute arbitrary code via an incomplete print job followed by a request to display the printer queue.
ModificadaMedia (5)7.8%—Openbsd Openssh27/9/200116/6/2026
The "echo simulation" traffic analysis countermeasure in OpenSSH before 2.9.9p2 sends an additional echo packet after the password and carriage return is entered, which could allow remote attackers to determine that the countermeasure is being used.