Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2767▼ 5 respecto a la semana anterior
Críticas / altas1280▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 207 respecto a la semana anterior
–

1112 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.40%—Freebsd14/11/200016/6/2026
Multiple buffer overflows in eject on FreeBSD and possibly other OSes allows local users to gain root privileges.
ModificadaAlta (7.5)3.8%💥 ExploitNetbsdOpenbsdRedhat Linux20/10/200016/6/2026
mopd (Maintenance Operations Protocol loader daemon) does not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary commands.
ModificadaAlta (7.2)0.39%—Freebsd20/10/200016/6/2026
Buffer overflows in brouted in FreeBSD and possibly other OSes allows local users to gain root privileges via long command line arguments.
ModificadaAlta (7.2)0.46%—Freebsd20/10/200016/6/2026
Buffer overflow in the Linux binary compatibility module in FreeBSD 3.x through 5.x allows local users to gain root privileges via long filenames in the linux shadow file system.
ModificadaBaja (2.1)0.33%—Freebsd20/10/200016/6/2026
FreeBSD 5.x, 4.x, and 3.x allows local users to cause a denial of service by executing a program with a malformed ELF image header.
ModificadaAlta (7.5)2.3%—NetbsdOpenbsdRedhat Linux20/10/200016/6/2026
Buffer overflow in mopd (Maintenance Operations Protocol loader daemon) allows remote attackers to execute arbitrary commands via a long file name.
ModificadaAlta (7.2)0.36%—Freebsd16/9/200016/6/2026
Buffer overflow in FreeBSD fts library routines allows local user to modify arbitrary files via the periodic program.
ModificadaMedia (5)59%💥 ExploitOpenbsd FtpdWashington University Wu-ftpd7/7/200016/6/2026
FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.
ModificadaMedia (4.6)0.51%—Freebsd5/7/200016/6/2026
libedit searches for the .editrc file in the current directory instead of the user's home directory, which may allow local users to execute arbitrary commands by installing a modified .editrc in another directory.
ModificadaMedia (5)9.9%💥 ExploitCaldera Openlinux DesktopCaldera Openlinux EbuilderCaldera Openlinux EdesktopCaldera Openlinux Eserver+24/7/200016/6/2026
BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters.
ModificadaAlta (10)5.9%💥 ExploitDebian LinuxFreebsd2/7/200016/6/2026
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.
ModificadaMedia (5)1.4%—OpensslFreebsd12/6/200016/6/2026
OpenSSL 0.9.4 and OpenSSH for FreeBSD do not properly check for the existence of the /dev/random or /dev/urandom devices, which are absent on FreeBSD Alpha systems, which causes them to produce weak keys which may be more easily broken.
ModificadaAlta (10)2.6%—Openbsd Openssh8/6/200016/6/2026
OpenSSH does not properly drop privileges when the UseLogin option is enabled, which allows local users to execute arbitrary commands by providing the command to the ssh daemon.
ModificadaAlta (7.5)1.8%—Freebsd7/6/200016/6/2026
A FreeBSD patch for SSH on 2000-01-14 configures ssh to listen on port 722 as well as port 22, which might allow remote attackers to access SSH through port 722 even if port 22 is otherwise filtered.
ModificadaBaja (2.1)0.34%—FreebsdNetbsd29/5/200016/6/2026
The undocumented semconfig system call in BSD freezes the state of semaphores, which allows local users to cause a denial of service of the semaphore system by using the semconfig call.
ModificadaBaja (2.1)0.34%—Netbsd28/5/200016/6/2026
NetBSD 1.4.2 and earlier allows local users to cause a denial of service by repeatedly running certain system calls in the kernel which do not yield the CPU, aka "cpu-hog".
ModificadaBaja (2.1)0.37%—Netbsd28/5/200016/6/2026
ftpd in NetBSD 1.4.2 does not properly parse entries in /etc/ftpchroot and does not chroot the specified users, which allows those users to access other files outside of their home directory.
ModificadaAlta (7.2)0.73%💥 ExploitFreebsdMandrakesoft Mandrake Linux17/5/200016/6/2026
xsoldier program allows local users to gain root access via a long argument.
ModificadaMedia (5)3.2%💥 ExploitFreebsdNetbsd1/5/200016/6/2026
NetBSD 1.4.2 and earlier allows remote attackers to cause a denial of service by sending a packet with an unaligned IP timestamp option.
ModificadaAlta (7.2)0.40%—Freebsd27/3/200016/6/2026
Buffer overflow in the huh program in the orville-write package allows local users to gain root privileges.
ModificadaAlta (7.2)0.42%—FreebsdMandrakesoft Mandrake LinuxRedhat LinuxTurbolinux28/2/200016/6/2026
Buffer overflow in the dump utility in the Linux ext2fs backup package allows local users to gain privileges via a long command line argument.
ModificadaMedia (5.1)0.97%—Openbsd OpensshSSHSsh224/2/200016/6/2026
The default configuration of SSH allows X forwarding, which could allow a remote attacker to control a client's X sessions via a malicious xauth program.
ModificadaMedia (4.6)0.72%💥 ExploitFreebsd21/2/200016/6/2026
asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file.
ModificadaAlta (7.2)0.72%💥 ExploitNetbsd16/2/200016/6/2026
procfs in BSD systems allows local users to gain root privileges by modifying the /proc/pid/mem interface via a modified file descriptor for stderr.
ModificadaMedia (4.6)0.35%—Openbsd OpensshSSH11/2/200016/6/2026
The SSH protocol server sshd allows local users without shell access to redirect a TCP connection through a service that uses the standard system password database for authentication, such as POP or FTP.