Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

176 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)2.4%—Nfs-utilsDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+210/1/200516/6/2026
statd in nfs-utils 1.257 and earlier does not ignore the SIGPIPE signal, which allows remote attackers to cause a denial of service (server process crash) via a TCP connection that is prematurely terminated.
ModificadaAlta (7.5)2.7%—KDE KonquerorMandrakesoft Mandrake LinuxRedhat Fedora Core10/1/200516/6/2026
Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection"…
ModificadaMedia (5.1)3.4%—Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+1231/12/200416/6/2026
Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.
ModificadaAlta (7.5)4.9%—Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+1231/12/200416/6/2026
Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.
ModificadaBaja (2.1)0.34%—Mandrakesoft Mandrake Multi Network FirewallMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server31/12/200416/6/2026
Memory leak in passwd 0.68 allows local users to cause a denial of service (memory consumption) via a large number of failed read attempts from the password buffer.
ModificadaMedia (5)1.5%—Mandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server31/12/200416/6/2026
libuser 0.51.7 allows attackers to cause a denial of service (crash or disk consumption) via unknown attack vectors, related to read failures and other bugs.
ModificadaBaja (2.1)0.36%—Mandrakesoft Mandrake Multi Network FirewallMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server31/12/200416/6/2026
Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.
ModificadaAlta (7.5)3.8%—Mpg123Mandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server23/12/200416/6/2026
Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) mp2 file.
ModificadaAlta (7.2)0.43%—Mandrakesoft Mandrake Multi Network FirewallSpeedtouch USB DriverGentoo LinuxMandrakesoft Mandrake Linux+123/12/200416/6/2026
Format string vulnerability in Speedtouch USB driver before 1.3.1 allows local users to execute arbitrary code via (1) modem_run, (2) pppoa2, or (3) pppoa3.
ModificadaAlta (7.5)8.3%—LibtiffPdflib PDF LibraryWxgtk2Apple MAC OS X+923/12/200416/6/2026
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
ModificadaAlta (7.5)6.3%—Avaya Call Management System ServerAvaya CvlanAvaya Integrated ManagementAvaya Interactive Response+1521/12/200416/6/2026
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
ModificadaMedia (5)18%—Ethereal Group EtherealGentoo LinuxMandrakesoft Mandrake LinuxRedhat Enterprise Linux+16/12/200416/6/2026
The iSNS dissector for Ethereal 0.10.3 through 0.10.4 allows remote attackers to cause a denial of service (process abort) via an integer overflow.
ModificadaAlta (7.2)0.39%—Mandrakesoft Mandrake Multi Network FirewallSuse Email ServerSuse Linux Connectivity ServerSuse Linux Database Server+96/12/200416/6/2026
Multiple unknown vulnerabilities in Linux kernel 2.6 allow local users to gain privileges or access kernel memory, a different set of vulnerabilities than those identified in CVE-2004-0495, as found by the Sparse source code checking tool.
ModificadaMedia (5)5.3%—Ethereal Group EtherealGentoo LinuxMandrakesoft Mandrake LinuxRedhat Enterprise Linux+16/12/200416/6/2026
The SMB SID snooping capability in Ethereal 0.9.15 to 0.10.4 allows remote attackers to cause a denial of service (process crash) via a handle without a policy name, which causes a null dereference.
ModificadaBaja (2.1)0.80%—Mandrakesoft Mandrake Multi Network FirewallConectiva LinuxGentoo LinuxLinux Kernel+56/12/200416/6/2026
Unknown vulnerability in Linux kernel 2.x may allow local users to modify the group ID of files, such as NFS exported files in kernel 2.4.
ModificadaBaja (2.1)0.44%—Mandrakesoft Mandrake Multi Network FirewallGentoo LinuxLinux KernelMandrakesoft Mandrake Linux+26/12/200416/6/2026
Floating point information leak in the context switch code for Linux 2.4.x only checks the MFH bit but does not verify the FPH owner, which allows local users to read register values of other processes by setting the MFH bit.
ModificadaMedia (5)5.3%—Ethereal Group EtherealGentoo LinuxMandrakesoft Mandrake LinuxRedhat Enterprise Linux+16/12/200416/6/2026
The SNMP dissector in Ethereal 0.8.15 through 0.10.4 allows remote attackers to cause a denial of service (process crash) via a (1) malformed or (2) missing community string, which causes an out-of-bounds read.
ModificadaBaja (2.1)0.36%—UserminWebminMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server20/10/200416/6/2026
The maketemp.pl script in Usermin 1.070 and 1.080 allows local users to overwrite arbitrary files at install time via a symlink attack on the /tmp/.usermin directory.
ModificadaAlta (7.5)1.9%—KDE KonquerorGentoo LinuxKDEMandrakesoft Mandrake Linux+120/10/200416/6/2026
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
ModificadaAlta (7.5)5.0%—ROB Flynn GaimGentoo LinuxMandrakesoft Mandrake Linux28/9/200416/6/2026
Buffer overflow in the MSN protocol plugins (1) object.c and (2) slp.c for Gaim before 0.82 allows remote attackers to cause a denial of service and possibly execute arbitrary code via MSNSLP protocol messages that are not properly handled in a strncpy call.
ModificadaMedia (5)17%—Apache Http ServerHP Secure WEB Server FOR Tru64Gentoo LinuxHp-ux+816/9/200416/6/2026
The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
ModificadaAlta (7.5)5.5%—Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+1016/9/200416/6/2026
Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.
ModificadaMedia (5)5.5%—SambaSGI SambaConectiva LinuxMandrakesoft Mandrake Linux+113/9/200416/6/2026
Samba 3.0.6 and earlier allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via certain malformed requests that cause new processes to be spawned and enter an infinite loop.
ModificadaMedia (4.6)0.37%—GNU KsymoopsMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server6/8/200416/6/2026
ksymoops-gznm script in Mandrake Linux 9.1 through 10.0, and Corporate Server 2.1, allows local users to delete arbitrary files via a symlink attack on files in /tmp.
ModificadaBaja (2.1)0.41%—Mandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Fedora CoreSuse Linux6/8/200416/6/2026
Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service.