Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
275 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.7% | — | Ethereal Group EtherealSGI Propack | 18/8/2004 | 16/6/2026 | The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors. | |
| Modificada | Alta (10) | 7.6% | — | Ethereal Group EtherealSGI Propack | 18/8/2004 | 16/6/2026 | Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Alta (10) | 34% | — | Apache Http ServerHP VirtualvaultHP WebproxyIBM Http Server+3 | 6/8/2004 | 16/6/2026 | Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied. | |
| Modificada | Baja (2.1) | 0.33% | — | SGI Irix | 6/8/2004 | 16/6/2026 | Unknown vulnerability in init for IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system panic) as a result of "page invalidation issues." | |
| Modificada | Baja (2.1) | 0.36% | — | SGI Irix | 6/8/2004 | 16/6/2026 | The mapelf32exec function call in IRIX 6.5.20 through 6.5.24 allows local users to cause a denial of service (system crash) via a "corrupted binary." | |
| Modificada | Alta (7.2) | 0.34% | — | SGI Irix | 6/8/2004 | 16/6/2026 | The syssgi SGI_IOPROBE system call in IRIX 6.5.20 through 6.5.24 allows local users to gain privileges by reading and writing to kernel memory. | |
| Modificada | Media (6.8) | 6.0% | 💥 Exploit | Open WebmailSGI PropackSquirrelmail | 6/8/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Squirrelmail 1.2.10 and earlier allow remote attackers to inject arbitrary HTML or script via (1) the $mailer variable in read_body.php, (2) the $senderNames_part variable in mailbox_display.php, and possibly other vectors including (3) the $event_title variable… | |
| Modificada | Media (5) | 3.1% | — | CVSOpenpkgSGI PropackGentoo Linux+1 | 6/8/2004 | 16/6/2026 | Integer overflow in the "Max-dotdot" CVS protocol command (serve_max_dotdot) for CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to cause a server crash, which could cause temporary data to remain undeleted and consume disk space. | |
| Modificada | Alta (10) | 5.7% | — | CVSOpenpkgSGI PropackGentoo Linux+1 | 6/8/2004 | 16/6/2026 | serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | CVSOpenpkgSGI PropackGentoo Linux+1 | 6/8/2004 | 16/6/2026 | Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code. | |
| Modificada | Alta (10) | 4.0% | — | CVSOpenpkgSGI PropackGentoo Linux+1 | 6/8/2004 | 16/6/2026 | CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution. | |
| Modificada | Media (5) | 1.8% | — | SGI Irix | 7/7/2004 | 16/6/2026 | Unknown vulnerability in rpc.mountd for SGI IRIX 6.5.24 allows remote attackers to cause a denial of service (infinite loop) via certain RPC requests. | |
| Modificada | Alta (7.2) | 1.2% | 💥 Exploit | SGI PropackLinux KernelSlackware Linux | 7/7/2004 | 16/6/2026 | Integer overflow in the ip_setsockopt function in Linux kernel 2.4.22 through 2.4.25 and 2.6.1 through 2.6.3 allows local users to cause a denial of service (crash) or execute arbitrary code via the MCAST_MSFILTER socket option. | |
| Modificada | Media (5) | 1.6% | — | SGI Irix | 5/5/2004 | 16/6/2026 | Unknown vulnerability in SGI IRIX 6.5 through 6.5.22m allows remote attackers to cause a denial of service via a certain UDP packet. | |
| Modificada | Media (4.6) | 0.32% | — | SGI Irix | 5/5/2004 | 16/6/2026 | ifconfig "-arp" in SGI IRIX 6.5 through 6.5.22m does not properly disable ARP requests from being sent or received. | |
| Modificada | Media (4.6) | 0.36% | — | Redhat SysstatSGI PropackSysstat | 15/4/2004 | 16/6/2026 | The isag utility, which processes sysstat data, allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CAN-2004-0107. | |
| Modificada | Alta (7.2) | 0.44% | — | SGI PropackWashington University Wu-ftpd | 15/4/2004 | 16/6/2026 | wu-ftpd 2.6.2 and earlier, with the restricted-gid option enabled, allows local users to bypass access restrictions by changing the permissions to prevent access to their home directory, which causes wu-ftpd to use the root directory instead. | |
| Modificada | Media (4.6) | 0.39% | — | Redhat SysstatSGI PropackSysstat | 15/4/2004 | 16/6/2026 | The (1) post and (2) trigger scripts in sysstat 4.0.7 and earlier allow local users to overwrite arbitrary files via symlink attacks on temporary files, a different vulnerability than CVE-2004-0108. | |
| Modificada | Media (5) | 2.1% | — | Gnome GdkpixbufRedhat GDK PixbufSGI PropackRedhat Enterprise Linux+1 | 15/4/2004 | 16/6/2026 | gdk-pixbuf before 0.20 allows attackers to cause a denial of service (crash) via a malformed bitmap (BMP) file. | |
| Modificada | Media (5) | 1.6% | — | SGI IrixAI | 2/4/2004 | 16/6/2026 | Unknown vulnerability in ftpd in SGI IRIX 6.5.20 through 6.5.23 allows remote attackers to cause a denial of service (hang) via the PORT mode. | |
| Modificada | Media (5) | 1.6% | — | SGI Irix | 29/3/2004 | 16/6/2026 | Unknown vulnerability in rpc.mountd in SGI IRIX 6.5 through 6.5.22 allows remote attackers to cause a denial of service (process death) via unknown attack vectors. | |
| Modificada | Alta (7.5) | 1.5% | — | SGI Irix | 29/3/2004 | 16/6/2026 | Unknown vulnerability in rpc.mountd SGI IRIX 6.5.18 through 6.5.22 allows remote attackers to mount from unprivileged ports even with the -n option disabled. | |
| Modificada | Alta (7.5) | 24% | 💥 Exploit | SGI PropackXmlsoft LibxmlXmlsoft Libxml2 | 15/3/2004 | 16/6/2026 | Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL. | |
| Modificada | Alta (7.5) | 26% | 💥 Exploit | Metamail Corporation MetamailSGI PropackRedhat Enterprise LinuxRedhat Linux Advanced Workstation | 3/3/2004 | 16/6/2026 | Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code. | |
| Modificada | Media (5) | 1.9% | — | GNU MailmanSGI Propack | 3/3/2004 | 16/6/2026 | Unknown vulnerability in the mail command handler in Mailman before 2.0.14 allows remote attackers to cause a denial of service (crash) via malformed e-mail commands. |