Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

94 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.9%—Midnight CommanderSGI PropackGentoo LinuxSlackware Linux18/8/200416/6/2026
Multiple format string vulnerabilities in Midnight Commander (mc) before 4.6.0 may allow attackers to cause a denial of service or execute arbitrary code.
ModificadaAlta (10)3.2%—SGI PropackSquirrelmail18/8/200416/6/2026
SQL injection vulnerability in SquirrelMail before 1.4.3 RC1 allows remote attackers to execute unauthorized SQL statements, with unknown impact, probably via abook_database.php.
ModificadaMedia (6.8)6.0%💥 ExploitOpen WebmailSGI PropackSquirrelmail6/8/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable…
ModificadaAlta (10)4.0%—CVSOpenpkgSGI PropackGentoo Linux+16/8/200416/6/2026
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.
ModificadaAlta (10)5.7%—CVSOpenpkgSGI PropackGentoo Linux+16/8/200416/6/2026
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.
ModificadaAlta (10)34%—Apache Http ServerHP VirtualvaultHP WebproxyIBM Http Server+36/8/200416/6/2026
Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.
ModificadaMedia (5)3.1%—CVSOpenpkgSGI PropackGentoo Linux+16/8/200416/6/2026
Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space.
ModificadaAlta (10)13%💥 ExploitCVSOpenpkgSGI PropackGentoo Linux+16/8/200416/6/2026
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.
ModificadaAlta (7.2)1.2%💥 ExploitSGI PropackLinux KernelSlackware Linux7/7/200416/6/2026
Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option.
ModificadaAlta (7.2)0.44%—SGI PropackWashington University Wu-ftpd15/4/200416/6/2026
wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead.
ModificadaMedia (4.6)0.39%—Redhat SysstatSGI PropackSysstat15/4/200416/6/2026
The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108.
ModificadaMedia (4.6)0.36%—Redhat SysstatSGI PropackSysstat15/4/200416/6/2026
The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107.
ModificadaMedia (5)2.1%—Gnome GdkpixbufRedhat GDK PixbufSGI PropackRedhat Enterprise Linux+115/4/200416/6/2026
gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file.
ModificadaAlta (7.5)24%💥 ExploitSGI PropackXmlsoft LibxmlXmlsoft Libxml215/3/200416/6/2026
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.
ModificadaAlta (7.5)26%💥 ExploitMetamail Corporation MetamailSGI PropackRedhat Enterprise LinuxRedhat Linux Advanced Workstation3/3/200416/6/2026
Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
ModificadaAlta (7.5)8.2%—Metamail Corporation MetamailSGI PropackRedhat Enterprise LinuxRedhat Linux Advanced Workstation3/3/200416/6/2026
Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
ModificadaMedia (5)1.9%—GNU MailmanSGI Propack3/3/200416/6/2026
Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands.
ModificadaMedia (4.9)0.38%—GNU GlibcGNU ZebraQuagga Routing Software SuiteSGI Propack+315/12/200316/6/2026
The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.
ModificadaMedia (5)8.4%💥 ExploitGNU ZebraQuaggaSGI Propack15/12/200316/6/2026
The vty layer in Quagga before 0.96.4, and Zebra 0.93b and earlier, does not verify that sub-negotiation is taking place when processing the SE marker, which allows remote attackers to cause a denial of service (crash) via a malformed telnet command to the telnet CLI port, which may trigger a null dereference.
Orbitaley — Vulnerabilidades