Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 82 respecto a la semana anterior
Críticas / altas1248▼ 291 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)249▲ 212 respecto a la semana anterior
–

1112 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.47%—Freebsd23/9/200116/6/2026
Format string vulnerability in Hylafax on FreeBSD allows local users to execute arbitrary code via format specifiers in the -h hostname argument for (1) faxrm or (2) faxalter.
ModificadaMedia (5)1.8%—FreebsdNetbsd20/9/200116/6/2026
NetBSD 1.5 and earlier and FreeBSD 4.3 and earlier allows a remote attacker to cause a denial of service by sending a large number of IP fragments to the machine, exhausting the mbuf pool.
ModificadaBaja (2.1)1.4%💥 ExploitOpenbsd OpensshFreebsd20/9/200116/6/2026
libutil in OpenSSH on FreeBSD 4.4 and earlier does not drop privileges before verifying the capabilities for reading the copyright and welcome files, which allows local users to bypass the capabilities checks and read arbitrary files by specifying alternate copyright or welcome files.
ModificadaAlta (7.2)0.37%—Freebsd4/9/200116/6/2026
rmuser utility in FreeBSD 4.2 and 4.3 creates a copy of the master.passwd file with world-readable permissions while updating the original file, which could allow local users to gain privileges by reading the copied file while rmuser is running, obtain the password hashes, and crack the passwords.
ModificadaAlta (10)1.9%—Freebsd31/8/200116/6/2026
ipfw in FreeBSD does not properly handle the use of "me" in its rules when point to point interfaces are used, which causes ipfw to allow connections from arbitrary remote hosts.
ModificadaMedia (5)1.6%—Carnegie Mellon University Cyrus Imap ServerBsdi BSD OS30/8/200116/6/2026
Cyrus 2.0.15, 2.0.16, and 1.6.24 on BSDi 4.2, with IMAP enabled, allows remote attackers to cause a denial of service (hang) using PHP IMAP clients.
ModificadaCrítica (9.8)2.0%—Freebsd23/8/200116/6/2026
TCP Wrappers (tcp_wrappers) in FreeBSD 4.1.1 through 4.3 with the PARANOID ACL option enabled does not properly check the result of a reverse DNS lookup, which could allow remote attackers to bypass intended access restrictions via DNS spoofing.
ModificadaAlta (7.2)0.33%—Netbsd23/8/200116/6/2026
The (1) dump and (2) dump_lfs commands in NetBSD 1.4.x through 1.5.1 do not properly drop privileges, which could allow local users to gain privileges via the RCMD_CMD environment variable.
ModificadaAlta (7.5)7.1%—Openbsd OpensshSSH22/8/200116/6/2026
The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker to obtain the following information via sniffing: (1) password lengths or ranges of lengths, which simplifies brute force password guessing, (2) whether RSA or DSA authentication…
ModificadaMedia (5)1.4%—Freebsd21/8/200116/6/2026
linprocfs on FreeBSD 4.3 and earlier does not properly restrict access to kernel memory, which allows one process with debugging rights on a privileged process to read restricted memory from that process.
ModificadaBaja (2.1)0.82%💥 ExploitBsdi BSD OS21/8/200116/6/2026
Vulnerability in a system call in BSDI 3.0 and 3.1 allows local users to cause a denial of service (reboot) in the kernel via a particular sequence of instructions.
ModificadaMedia (6.2)0.30%—FreebsdNetbsdOpenbsd17/8/200116/6/2026
fts routines in FreeBSD 4.3 and earlier, NetBSD before 1.5.2, and OpenBSD 2.9 and earlier can be forced to change (chdir) into a different directory than intended when the directory above the current directory is moved, which could cause scripts to perform dangerous actions on the wrong directories.
ModificadaAlta (7.2)0.62%—Openbsd Openssh14/8/200116/6/2026
OpenSSH version 2.9 and earlier, with X forwarding enabled, allows a local attacker to delete any file named 'cookies' via a symlink attack.
ModificadaAlta (10)39%💥 ExploitMIT KerberosMIT Kerberos 5Linux NetkitSGI Irix+714/8/200116/6/2026
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.
ModificadaBaja (2.1)0.33%—Netbsd24/7/200116/6/2026
sendmsg function in NetBSD 1.3 through 1.5 allows local users to cause a denial of service (kernel trap or panic) via a msghdr structure with a large msg_controllen length.
ModificadaAlta (7.2)0.60%—Freebsd10/7/200116/6/2026
FreeBSD 4.3 does not properly clear shared signal handlers when executing a process, which allows local users to gain privileges by calling rfork with a shared signal handler, having the child process execute a setuid program, and sending a signal to the child.
ModificadaMedia (5)22%💥 ExploitFreebsdHp-uxHP VvosLinux Kernel+57/7/200116/6/2026
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by setting the maximum segment size (MSS) to a very small number and requesting large amounts of data, which generates more packets with less TCP-level data that amplify network traffic and consume…
ModificadaAlta (7.2)0.39%—Timecop BubblemonFreebsd2/7/200116/6/2026
BubbleMon 1.31 does not properly drop group privileges before executing programs, which allows local users to execute arbitrary commands with the kmem group id.
ModificadaAlta (7.5)2.4%—LicqConectiva LinuxFreebsdMandrakesoft Mandrake Linux+22/7/200116/6/2026
licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
ModificadaMedia (5)1.6%—Freebsd27/6/200116/6/2026
rwho daemon rwhod in FreeBSD 4.2 and earlier, and possibly other operating systems, allows remote attackers to cause a denial of service via malformed packets with a short length.
ModificadaAlta (10)2.7%—FreebsdMandrakesoft Mandrake LinuxSuse Linux27/6/200116/6/2026
time server daemon timed allows remote attackers to cause a denial of service via malformed packets.
ModificadaMedia (4)2.5%—Openbsd OpensshSSH27/6/200116/6/2026
Implementations of SSH version 1.5, including (1) OpenSSH up to version 2.3.0, (2) AppGate, and (3) ssh-1 up to version 1.2.31, in certain configurations, allow a remote attacker to decrypt and/or alter traffic via a "Bleichenbacher attack" on PKCS#1 version 1.5.
ModificadaBaja (2.1)0.31%—Openbsd27/6/200116/6/2026
readline prior to 4.1, in OpenBSD 2.8 and earlier, creates history files with insecure permissions, which allows a local attacker to recover potentially sensitive information via readline history files.
ModificadaAlta (7.5)2.2%—Openbsd Openssh19/6/200116/6/2026
OpenSSH 2.9 and earlier does not initiate a Pluggable Authentication Module (PAM) session if commands are executed with no pty, which allows local users to bypass resource limits (rlimits) set in pam.d.
ModificadaAlta (10)19%💥 ExploitMIT Kerberos 5SGI IrixFreebsdNetbsd+118/6/200116/6/2026
Buffer overflows in BSD-based FTP servers allows remote attackers to execute arbitrary commands via a long pattern string containing a {} sequence, as seen in (1) g_opendir, (2) g_lstat, (3) g_stat, and (4) the glob0 buffer as used in the glob functions glob2 and glob3.