Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
1441 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.38% | — | SUN Solaris | 20/9/2005 | 16/6/2026 | Unspecified vulnerability in the "tl" driver in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors. | |
| Modificada | Alta (7.5) | 2.8% | — | SUN Solaris | 8/9/2005 | 16/6/2026 | Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execute arbitrary code on a DHCP client via certain DHCP responses. | |
| Modificada | Media (4.6) | 1.1% | 💥 Exploit | SUN Solaris | 29/6/2005 | 16/6/2026 | traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot). | |
| Modificada | Alta (7.2) | 1.00% | 💥 Exploit | SUN SolarisSunos | 29/6/2005 | 16/6/2026 | The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT. | |
| Modificada | Baja (2.1) | 0.38% | — | SUN SolarisSunos | 16/6/2005 | 16/6/2026 | Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files. | |
| Modificada | Media (4.6) | 0.33% | — | SUN Solaris | 9/6/2005 | 16/6/2026 | Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges. | |
| Modificada | Media (5) | 1.2% | — | SUN SolarisSunos | 16/5/2005 | 16/6/2026 | Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (rpc.nisd disabled and NIS+ unavailable) via unknown vectors. | |
| Modificada | Baja (2.1) | 0.29% | — | SUN SolarisSunos | 11/5/2005 | 16/6/2026 | Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when "accessing" /xfn/_x500. | |
| Modificada | Media (4.3) | 1.3% | — | Captaris Infinite Mobile Delivery Webmail | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL. | |
| Modificada | Media (5) | 1.6% | — | SUN SolarisSunos | 2/5/2005 | 16/6/2026 | Vulnerabilidad desconocida en Solaris 8 y 9 permite a atacantes remotos provocar la Denegación de Servicio (DoS) mediante ""Heavy UDP Usage"" que lanza una referencia a NULL. | |
| Modificada | Baja (3.6) | 0.33% | — | SUN Solaris | 2/5/2005 | 16/6/2026 | Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files. | |
| Modificada | Alta (7.5) | 1.4% | — | SUN SolarisSunos | 2/5/2005 | 16/6/2026 | The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | SUN Solaris Answerbook2 | 2/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the "View Log Files" function. | |
| Modificada | Media (5) | 1.5% | — | Captaris Infinite Mobile Delivery Webmail | 2/5/2005 | 16/6/2026 | Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain sensitive information via an HTTP request that contains invalid characters for a Windows foldername, which reveals the path in an error message. | |
| Modificada | Media (4.6) | 0.33% | — | SUN SolarisSunos | 2/5/2005 | 16/6/2026 | Unknown vulnerability in the libgss Generic Security Services Library in Solaris 7, 8, and 9 allows local users to gain privileges by loading their own GSS-API. | |
| Modificada | Alta (7.2) | 0.42% | — | SUN SolarisSunos | 2/5/2005 | 16/6/2026 | Buffer overflow in newgrp in Solaris 7 through 9 allows local users to gain root privileges. | |
| Modificada | Media (5) | 80% | 💥 Exploit | Microsoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+4 | 12/4/2005 | 16/6/2026 | Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066,… | |
| Modificada | Media (5) | 20% | 💥 Exploit | SUN SolarisSunos | 12/4/2005 | 16/6/2026 | Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have… | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | SUN Solaris Answerbook2 | 7/3/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function. | |
| Modificada | Media (5.6) | 0.51% | — | FreebsdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+4 | 5/3/2005 | 16/6/2026 | Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack… | |
| Modificada | Baja (2.1) | 0.29% | — | SUN SolarisSunos | 23/2/2005 | 16/6/2026 | The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file. | |
| Modificada | Media (5) | 1.6% | — | SUN SolarisSunos | 15/2/2005 | 16/6/2026 | Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets. | |
| Modificada | Media (4.6) | 0.34% | — | SUN SolarisSunos | 31/12/2004 | 16/6/2026 | The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges. | |
| Modificada | Alta (7.2) | 0.51% | — | SUN SolarisSunos | 31/12/2004 | 16/6/2026 | Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line argument. | |
| Modificada | Alta (7.2) | 1.2% | 💥 Exploit | SUN SolarisSunos | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure. |