Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

151 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)8.0%💥 ExploitDconnect Daemon14/8/200616/6/2026
Stack-based buffer overflow in main.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to execute arbitrary code via a large nickname, which is not properly handled by the listen_thread_udp function.
ModificadaAlta (7.5)4.5%💥 ExploitAlt-n Mdaemon30/5/200616/6/2026
Buffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows remote attackers to execute arbitrary code via a long A0001 argument that begins with a '"' (double quote).
ModificadaMedia (5)4.7%💥 ExploitX-doomZdaemon3/4/200616/6/2026
The (1) ZD_MissingPlayer, (2) ZD_UseItem, and (3) ZD_LoadNewClientLevel functions in sv_main.cpp for (a) Zdaemon 1.08.01 and (b) X-Doom allows remote attackers to cause a denial of service (crash) via an invalid player slot or item number, which causes an invalid memory access, possibly due to an invalid array index.
ModificadaAlta (7.5)5.4%—X-doomZdaemon3/4/200616/6/2026
Buffer overflow in the is_client_wad_ok function in w_wad.cpp for (1) Zdaemon 1.08.01 and (2) X-Doom allows remote attackers to execute arbitrary code via a long filename argument.
ModificadaMedia (5)3.1%💥 ExploitAlt-n Mdaemon28/2/200616/6/2026
Format string vulnerability in the IMAP4rev1 server in Alt-N MDaemon 8.1.1 and possibly 8.1.4 allows remote attackers to cause a denial of service (CPU consumption) by creating and then listing folders whose names contain format string specifiers.
ModificadaAlta (7.5)4.1%💥 ExploitPower Daemon15/2/200616/6/2026
Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable.
ModificadaAlta (7.5)1.3%—Alt-n MdaemonAlt-n Worldclient15/12/200516/6/2026
WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as other users by guessing or sniffing the random value.
ModificadaMedia (4.3)2.1%💥 ExploitAlt-n MdaemonAlt-n Worldclient13/12/200516/6/2026
WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being able to access the Inbox folder, possibly due to a cross-site scripting (XSS) vulnerability.
ModificadaMedia (5)62%💥 Exploit3com 3cdaemon2/5/200516/6/2026
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a long argument, such as cd, send, or ls.
ModificadaMedia (5)1.6%—3com 3cdaemon2/5/200516/6/2026
Multiple format string vulnerabilities in the FTP service in 3Com 3CDaemon 2.0 revision 10 allow remote attackers to cause a denial of service (application crash) via format string specifiers in (1) the username, (2) cd, (3) delete, (4) rename, (5) rmdir, (6) literal, (7) stat, or (8) CWD commands.
ModificadaBaja (2.1)0.40%—KDE DcopserverKDE Desktop Communication Protocol Daemon2/5/200516/6/2026
Desktop Communication Protocol (DCOP) daemon, aka dcopserver, in KDE before 3.4 allows local users to cause a denial of service (dcopserver consumption) by "stalling the DCOP authentication process."
ModificadaMedia (5)1.2%—3com 3cdaemon2/5/200516/6/2026
TFTP in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) via a GET request containing an MS-DOS device name.
ModificadaMedia (5)1.5%—3com 3cdaemon2/5/200516/6/2026
The FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to gain sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an error message.
ModificadaBaja (2.1)2.7%💥 ExploitWAR FTP Daemon27/1/200516/6/2026
WarFTPD 1.82 RC9, when running as an NT service, allows remote authenticated users to cause a denial of service (access violation) via a CWD command with a crafted pathname, as demonstrated using a large string of "%s" sequences, possibly indicating a format string vulnerability.
ModificadaMedia (5)31%💥 ExploitAlt-n Mdaemon31/12/200416/6/2026
Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP server or (2) LIST command to the IMAP server.
ModificadaMedia (5)12%—Alt-n Mdaemon31/12/200416/6/2026
Buffer overflow in Alt-N MDaemon 7.0.1 allows remote attackers to cause a denial of service (application crash) via a long STATUS command to the IMAP server.
ModificadaAlta (7.2)0.48%—Alt-n Mdaemon31/12/200416/6/2026
The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes child processes such as NOTEPAD.EXE with SYSTEM privileges when users create new files, which allows local users with physical access to gain privileges.
ModificadaAlta (7.5)68%💥 ExploitBerlios GPS Daemon31/12/200416/6/2026
Format string vulnerability in the gpsd_report function for BerliOS GPD daemon (gpsd, formerly pygps) 1.9.0 through 2.7 allows remote attackers to execute arbitrary code via certain GPS requests containing format string specifiers that are not properly handled in syslog calls.
ModificadaMedia (5)1.6%—Music Daemon23/8/200416/6/2026
Music daemon (musicd) 0.0.3 and earlier allows remote attackers to read arbitrary files by calling LOAD with a full pathname, then calling SHOWLIST.
ModificadaMedia (5)7.0%💥 ExploitMusic Daemon23/8/200416/6/2026
Music daemon (musicd) 0.0.3 and earlier allows remote attackers to cause a denial of service (crash) by calling LOAD with a binary file as an argument, then calling SHOWLIST.
ModificadaAlta (9)5.0%—Alt-n Mdaemon31/12/200316/6/2026
Buffer overflow in IMAP service in MDaemon 6.7.5 and earlier allows remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a CREATE command with a long mailbox name.
ModificadaMedia (6.3)1.1%—Alt-n Mdaemon31/12/200316/6/2026
MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service (crash) via a (1) DELE or (2) UIDL with a negative number.
ModificadaAlta (7.5)65%💥 ExploitAlt-n Mdaemon29/12/200316/6/2026
Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbitrary code via a long From parameter to Form2Raw.cgi.
ModificadaAlta (7.5)4.2%—Cistron Radius Daemon7/8/200316/6/2026
Cistron RADIUS daemon (radiusd-cistron) 1.6.6 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large value in an NAS-Port attribute, which is interpreted as a negative number and causes a buffer overflow.
ModificadaAlta (7.5)8.2%💥 ExploitWsmp3 DaemonWsmp3 WEB Server22/5/200316/6/2026
Multiple heap-based buffer overflows in WsMp3 daemon (WsMp3d) 0.0.10 and earlier allow remote attackers to execute arbitrary code via long HTTP requests.
Orbitaley — Vulnerabilidades