Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2851▼ 221 respecto a la semana anterior
Críticas / altas1331▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)223▼ 98 respecto a la semana anterior
928 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 3.6% | 💥 Exploit | Redgraphic Sapid CMS | 9/8/2006 | 16/6/2026 | Vulnerabilidad de inclusión remota de archivo en PHP en SAPID CMS 123 rc3 permite a atacantes remotos ejecutar código PHP de su elección mediante una URL en el parámetro (1) root_path en usr/extensions/get_infochannel.inc.php y el parámetro (2) GLOBALS["roog_path"] en usr/extension/get_tree.inc.php. | |
| Modificada | Baja (2.1) | 0.36% | — | Matt Blaze Cryptographic File System | 7/8/2006 | 16/6/2026 | Múltiples desbordamientos de entero en las funciones (1) dodecrypt y (2) doencrypt en cfs_fh.c en cfsd de Matt Blaze Cryptographic File System (CFS) 1.4.1 anterior a Debian GNU/Linux package 1.4.1-17 permite a usuarios locales provocar una denegación de servicio (caída del demonio) añadiendo información a un fichero… | |
| Modificada | Media (5.4) | 10% | 💥 Exploit | Thomas Boutell Graphics Draw Library | 8/6/2006 | 16/6/2026 | The LZW decoding in the gdImageCreateFromGifPtr function in the Thomas Boutell graphics draw (GD) library (aka libgd) 2.0.33 allows remote attackers to cause a denial of service (CPU consumption) via malformed GIF data that causes an infinite loop. | |
| Modificada | Media (6.8) | 2.2% | — | Phpgraphy | 20/4/2006 | 16/6/2026 | phpGraphy 0.9.11 and earlier allows remote attackers to bypass authentication and gain administrator privileges via a direct request to index.php with the editwelcome parameter set to 1, which can then be used to modify the main page to inject arbitrary HTML and web script. NOTE: XSS attacks are resultant from this… | |
| Modificada | Baja (2.6) | 0.77% | — | Adobe Document ServerAdobe Graphics Server | 16/3/2006 | 16/6/2026 | Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service in which the request uses the (1) saveContent or (2)… | |
| Modificada | Alta (7.8) | 1.8% | — | Intel Graphics Accelerator Driver | 4/1/2006 | 16/6/2026 | ialmnt5.sys en el controlador de pantalla ialmrnt5 en Intel Graphics Accelerator Driver 6.14.10.4308 permite a atacantes provocar una denegación de servicio (caída o cambio en la resolución de pantalla) a través de un espacio largo de texto, según lo demostrado usando un título de ventana largo. | |
| Modificada | Media (5) | 2.3% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. | |
| Modificada | Alta (10) | 3.8% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | |
| Modificada | Baja (3.6) | 0.37% | — | Graphviz | 31/12/2005 | 16/6/2026 | graphviz before 2.2.1 allows local users to overwrite arbitrary files via a symlink attack on temporary files. NOTE: this issue was originally associated with a different CVE identifier, CVE-2005-2965, which had been used for multiple different issues. This is the correct identifier. | |
| Modificada | Media (5) | 3.4% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | |
| Modificada | Alta (7.5) | 1.8% | — | Redgraphic Sapid CMS | 5/12/2005 | 16/6/2026 | SAPID CMS before 1.2.3.03 allows remote attackers to bypass authentication via direct requests to the usr/system files (1) insert_file.php, (2) insert_image.php, (3) insert_link.php, (4) insert_qcfile.php, and (5) edit.php. | |
| Modificada | Alta (10) | 1.4% | — | Redgraphic Sapid CMS | 5/12/2005 | 16/6/2026 | Multiple unspecified vulnerabilities in SAPID CMS before 1.2.3.03, related to newly registered users and possibly authorization checks, have unknown impact and attack vectors involving (1) mvc/controller/user_request_analysis.inc.php and (2) usr/xml/ddc/authorization.xml. | |
| Modificada | Alta (7.5) | 7.4% | 💥 Exploit | Graphon Go-global | 3/11/2005 | 16/6/2026 | Buffer overflow in GO-Global for Windows 3.1.0.3270 and earlier allows remote attackers to execute arbitrary code via a data block that is longer than the specified data block size. | |
| Modificada | Media (4.3) | 2.0% | — | Phpgraphy | 30/8/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in phpGraphy 0.9.9a and earlier allows remote attackers to inject arbitrary web script or HTML via EXIF data, such as the Camera Model Tag. | |
| Modificada | Media (5) | 4.2% | — | GraphicsmagickImagemagick | 24/5/2005 | 16/6/2026 | The XWD Decoder in ImageMagick before 6.2.2.3, and GraphicsMagick before 1.1.6-r1, allows remote attackers to cause a denial of service (infinite loop) via an image with a zero color mask. | |
| Modificada | Alta (7.5) | 4.4% | — | GraphicsmagickImagemagickSGI PropackDebian Linux+2 | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in psd.c for ImageMagick 6.1.0, 6.1.7, and possibly earlier versions allows remote attackers to execute arbitrary code via a .PSD image file with a large number of layers. | |
| Modificada | Media (5) | 14% | 💥 Exploit | GraphicsmagickImagemagick | 25/4/2005 | 16/6/2026 | Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attackers to cause a denial of service (application crash) via a PNM file with a small colors value. | |
| Modificada | Alta (10) | 28% | 💥 Exploit | GD Graphics Library GdlibOpenpkgGentoo LinuxSuse Linux+1 | 1/3/2005 | 16/6/2026 | Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a… | |
| Modificada | Alta (10) | 11% | — | GD Graphics Library GdlibTrustix Secure Linux | 9/2/2005 | 16/6/2026 | Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 and earlier may allow remote attackers to execute arbitrary code via malformed image files that trigger the overflows due to improper calls to the gdMalloc function, a different set of vulnerabilities than CVE-2004-0990. | |
| Modificada | Media (5) | 1.5% | — | Gamespy Roger WilcoGamespy Roger Wilco Dedicated ServerGamespy Roger Wilco Graphical ServerGamespy Roger Wilco Mark | 31/12/2004 | 16/6/2026 | The client and server for Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier report sensitive information such as IDs and source IP addresses, which allows remote attackers to obtain sensitive information. | |
| Modificada | Media (5) | 5.7% | 💥 Exploit | Gamespy Roger Wilco Dedicated ServerGamespy Roger Wilco Graphical Server | 31/12/2004 | 16/6/2026 | Roger Wilco 1.4.1.6 and earlier or Roger Wilco Base Station 0.30a and earlier allows remote attackers to cause a denial of service (application crash) via a long, malformed UDP datagram. | |
| Modificada | Alta (10) | 11% | — | Open Group CDE Common Desktop EnvironmentXI Graphics DextopIBM AIX | 4/5/2004 | 16/6/2026 | Vulnerabilidad de doble liberación de memora en dtlogin de CDE sobre Solaris, y posiblemente otros sistemas operativos, permite a atacantes remotos ejecutar código arbitrario mediante cierto paquete UDP. | |
| Modificada | Alta (7.5) | 9.2% | 💥 Exploit | Gamespy Roger Wilco Dedicated ServerGamespy Roger Wilco Graphical Server | 17/9/2003 | 16/6/2026 | Desbordamiento de búfer en RogerWilco graphical server 1.4.1.6 y anteriores, dedicated server 0.32a y anteriores para Windows, y 0.27 para Linux y BSD, permite a atacantes remotos causar una denegación de servicio y ejecutar código arbitrario mediante un valor de longitud grande. | |
| Modificada | Alta (10) | 23% | — | Caldera UnixwareXI Graphics DextopCaldera OpenunixCompaq Tru64+4 | 5/9/2002 | 16/6/2026 | Desbordamiento de búfer en el servidor de bases de datos RPC ToolTalk (rpc.ttdbserverd) de Common Desktop Environment (CDE) permite a atacantes remotos ejecutar código arbitrario mediante un argumento al procedimiento T_TT_CREATE_FILE. | |
| Modificada | Alta (7.2) | 9.4% | — | Caldera UnixwareXI Graphics DextopSGI IrixCaldera Openunix+5 | 23/7/2002 | 16/6/2026 | El servidor de bases de datos CDE ToolTalk (ttdbserver) permite a usuarios locales sobreescribir ficheros arbitrarios mediante un ataque en enlaces simbólicos (symlink attack) en el fichero de registro (log) de transacciones usado por el procedimiento RPC _TT_TRANSACTION |