Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3000▲ 369 respecto a la semana anterior
Críticas / altas1450▲ 18 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1441 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.38%—SUN Solaris20/9/200516/6/2026
Unspecified vulnerability in the "tl" driver in Solaris 10 allows local users to cause a denial of service (panic) via unknown vectors.
ModificadaAlta (7.5)2.8%—SUN Solaris8/9/200516/6/2026
Unknown vulnerability in the net-svc script on Solaris 10 allows remote authenticated users to execute arbitrary code on a DHCP client via certain DHCP responses.
ModificadaMedia (4.6)1.1%💥 ExploitSUN Solaris29/6/200516/6/2026
traceroute in Sun Solaris 10 on x86 systems allows local users to execute arbitrary code with PRIV_NET_RAWACCESS privileges via (1) a large number of -g arguments or (2) a malformed -s argument with a trailing . (dot).
ModificadaAlta (7.2)1.00%💥 ExploitSUN SolarisSunos29/6/200516/6/2026
The runtime linker (ld.so) in Solaris 8, 9, and 10 trusts the LD_AUDIT environment variable in setuid or setgid programs, which allows local users to gain privileges by (1) modifying LD_AUDIT to reference malicious code and possibly (2) using a long value for LD_AUDIT.
ModificadaBaja (2.1)0.38%—SUN SolarisSunos16/6/200516/6/2026
Unknown vulnerability in lpadmin on Sun Solaris 7, 8, and 9 allows local users to overwrite arbitrary files.
ModificadaMedia (4.6)0.33%—SUN Solaris9/6/200516/6/2026
Unknown vulnerability in the Sun Solaris C library (libc and libproject) in Solaris 10 allows local users to gain privileges.
ModificadaMedia (5)1.2%—SUN SolarisSunos16/5/200516/6/2026
Unknown vulnerability in NIS+ on Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (rpc.nisd disabled and NIS+ unavailable) via unknown vectors.
ModificadaBaja (2.1)0.29%—SUN SolarisSunos11/5/200516/6/2026
Unknown vulnerability in Solaris 7 through 9, when using Federated Naming Services (FNS), autofs, and FNS X.500 configuration, allows local users to cause a denial of service (automountd crash) when "accessing" /xfn/_x500.
ModificadaMedia (4.3)1.3%—Captaris Infinite Mobile Delivery Webmail2/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL.
ModificadaMedia (5)1.6%—SUN SolarisSunos2/5/200516/6/2026
Vulnerabilidad desconocida en Solaris 8 y 9 permite a atacantes remotos provocar la Denegación de Servicio (DoS) mediante ""Heavy UDP Usage"" que lanza una referencia a NULL.
ModificadaBaja (3.6)0.33%—SUN Solaris2/5/200516/6/2026
Unknown vulnerability in Standard Type Services Framework (STSF) Font Server Daemon (stfontserverd) in Solaris 9 allows local users to modify or delete arbitrary files.
ModificadaAlta (7.5)1.4%—SUN SolarisSunos2/5/200516/6/2026
The Solaris Management Console (SMC) GUI for Solaris 8 and 9, when creating user accounts that are configured for password aging, creates the accounts with a blank password, which allows remote or local attackers to break into those accounts.
ModificadaMedia (4.3)1.7%💥 ExploitSUN Solaris Answerbook22/5/200516/6/2026
Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the "View Log Files" function.
ModificadaMedia (5)1.5%—Captaris Infinite Mobile Delivery Webmail2/5/200516/6/2026
Infinite Mobile Delivery Webmail 2.6 allows remote attackers to gain sensitive information via an HTTP request that contains invalid characters for a Windows foldername, which reveals the path in an error message.
ModificadaMedia (4.6)0.33%—SUN SolarisSunos2/5/200516/6/2026
Unknown vulnerability in the libgss Generic Security Services Library in Solaris 7, 8, and 9 allows local users to gain privileges by loading their own GSS-API.
ModificadaAlta (7.2)0.42%—SUN SolarisSunos2/5/200516/6/2026
Buffer overflow in newgrp in Solaris 7 through 9 allows local users to gain root privileges.
ModificadaMedia (5)80%💥 ExploitMicrosoft Windows 2000Microsoft Windows 2003 ServerMicrosoft Windows 98Microsoft Windows 98se+412/4/200516/6/2026
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (reset TCP connections) via spoofed ICMP error messages, aka the "blind connection-reset attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066,…
ModificadaMedia (5)20%💥 ExploitSUN SolarisSunos12/4/200516/6/2026
Multiple TCP/IP and ICMP implementations allow remote attackers to cause a denial of service (network throughput reduction for TCP connections) via a blind throughput-reduction attack using spoofed Source Quench packets, aka the "ICMP Source Quench attack." NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have…
ModificadaMedia (4.3)1.7%💥 ExploitSUN Solaris Answerbook27/3/200516/6/2026
Cross-site scripting (XSS) vulnerability in Solaris AnswerBook2 Documentation 1.4.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the Search function.
ModificadaMedia (5.6)0.51%—FreebsdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+45/3/200516/6/2026
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack…
ModificadaBaja (2.1)0.29%—SUN SolarisSunos23/2/200516/6/2026
The logging feature in kcms_configure in the KCMS package on Solaris 8 and 9, and possibly other versions, allows local users to corrupt arbitrary files via a symlink attack on the KCS_ClogFile file.
ModificadaMedia (5)1.6%—SUN SolarisSunos15/2/200516/6/2026
Solaris 7, 8, and 9 allows remote attackers to cause a denial of service (hang) via a flood of certain ARP packets.
ModificadaMedia (4.6)0.34%—SUN SolarisSunos31/12/200416/6/2026
The pfexec function for Sun Solaris 8 and 9 does not properly handle when a custom profile contains an invalid entry in the exec_attr database, which may allow local users with custom rights profiles to execute profile commands with additional privileges.
ModificadaAlta (7.2)0.51%—SUN SolarisSunos31/12/200416/6/2026
Buffer overflow in uustat in Sun Solaris 8 and 9 allows local users to execute arbitrary code via a long -S command line argument.
ModificadaAlta (7.2)1.2%💥 ExploitSUN SolarisSunos31/12/200416/6/2026
Directory traversal vulnerability in the vfs_getvfssw function in Solaris 2.6, 7, 8, and 9 allows local users to load arbitrary kernel modules via crafted (1) mount or (2) sysfs system calls. NOTE: this might be the same issue as CVE-2004-1767, but there are insufficient details to be sure.