Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
176 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2.1) | 0.47% | — | Mandrakesoft Mandrake Multi Network FirewallSuse Email ServerSuse Linux Admin-cd FOR FirewallSuse Linux Connectivity Server+13 | 6/8/2004 | 16/6/2026 | The e1000 driver for Linux kernel 2.4.26 and earlier does not properly initialize memory before using it, which allows local users to read portions of kernel memory. NOTE: this issue was originally incorrectly reported as a "buffer overflow" by some sources. | |
| Modificada | Alta (10) | 17% | — | Infoblox DNS ONE ApplianceISC DhcpdSuse Email ServerSuse Linux Admin-cd FOR Firewall+7 | 6/8/2004 | 16/6/2026 | The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf to use the less safe vsprintf function, which can lead to buffer overflow vulnerabilities that enable a denial of service (server crash) and… | |
| Modificada | Alta (10) | 45% | — | Infoblox DNS ONE ApplianceISC DhcpdSuse Email ServerSuse Linux Admin-cd FOR Firewall+7 | 6/8/2004 | 16/6/2026 | Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via multiple hostname options in (1) DISCOVER, (2) OFFER, (3) REQUEST, (4) ACK, or (5) NAK messages, which… | |
| Modificada | Media (4.6) | 0.48% | — | XpcdMandrakesoft Mandrake Linux | 7/7/2004 | 16/6/2026 | Buffer overflow in xpcd-svga in xpcd before 2.08, and possibly other versions, may allow local users to execute arbitrary code. | |
| Modificada | Alta (10) | 27% | — | MplayerGentoo LinuxMandrakesoft Mandrake Linux | 4/5/2004 | 16/6/2026 | Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header. | |
| Modificada | Media (5) | 1.7% | — | SUN SolarisSunosDebian LinuxMandrakesoft Mandrake Linux+1 | 16/2/2004 | 16/6/2026 | Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash). | |
| Modificada | Media (5) | 1.4% | — | IrssiMandrakesoft Mandrake Linux | 5/1/2004 | 16/6/2026 | The format_send_to_gui function in formats.c for irssi before 0.8.9 allows remote IRC users to cause a denial of service (crash). | |
| Modificada | Baja (1.2) | 0.65% | — | Mandrakesoft Mandrake Multi Network FirewallLinux KernelMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server | 27/8/2003 | 16/6/2026 | A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc/base.c on Linux 2.4 allows local users to cause a denial of service (crash). | |
| Modificada | Alta (7.5) | 41% | — | Adobe AcrobatXpdfMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+3 | 24/7/2003 | 16/6/2026 | Various PDF viewers including (1) Adobe Acrobat 5.06 and (2) Xpdf 1.01 allow remote attackers to execute arbitrary commands via shell metacharacters in an embedded hyperlink. | |
| Modificada | Alta (10) | 3.5% | — | MIT Kerberos FTP ClientRedhat LinuxMandrakesoft Mandrake Multi Network FirewallMandrakesoft Mandrake Linux | 19/2/2003 | 16/6/2026 | Kerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client. | |
| Modificada | Baja (1.2) | 0.29% | — | JmcceMandrakesoft Mandrake Linux | 31/12/2002 | 16/6/2026 | jmcce 1.3.8 in Mandrake 8.1 creates log files in /tmp with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. | |
| Modificada | Media (5.5) | 0.38% | — | Mandrakesoft Mandrake Linux | 31/12/2002 | 16/6/2026 | The Standard security setting for Mandrake-Security package (msec) in Mandrake 8.2 installs home directories with world-readable permissions, which could allow local users to read other user's files. | |
| Modificada | Media (4.6) | 1.1% | — | Gnome BonoboMandrakesoft Mandrake LinuxRedhat LinuxSlackware Linux | 31/12/2002 | 16/6/2026 | Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long command line arguments. | |
| Modificada | Media (4.9) | 2.5% | — | SGI IrixDebian LinuxMandrakesoft Mandrake LinuxMicrosoft Windows 98+7 | 31/12/2002 | 16/6/2026 | The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network. | |
| Modificada | Media (5) | 2.7% | — | John Drake Killer Protection | 31/12/2002 | 16/6/2026 | Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows remote attackers to obtain user names and passwords and log in using protection.php. | |
| Modificada | Alta (7.5) | 8.0% | — | HP Secure OSMandrakesoft Mandrake LinuxRedhat Linux | 28/10/2002 | 16/6/2026 | dvips converter for Postscript files in the tetex package calls the system() function insecurely, which allows remote attackers to execute arbitrary commands via certain print jobs, possibly involving fonts. | |
| Modificada | Media (6.2) | 0.53% | — | Mandrakesoft Mandrake Single Network FirewallHP Secure OSMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+1 | 12/8/2002 | 16/6/2026 | setpwnam.c in the util-linux package, as included in Red Hat Linux 7.3 and earlier, and other operating systems, does not properly lock a temporary file when modifying /etc/passwd, which may allow local users to gain privileges via a complex race condition that uses an open file descriptor in utility programs such as… | |
| Modificada | Crítica (9.8) | 15% | — | ImmunixMandrakesoft Mandrake Single Network FirewallOpenbsd OpensshOpenpkg+7 | 15/3/2002 | 16/6/2026 | Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges. | |
| Modificada | Alta (7.2) | 1.3% | — | Caldera Openlinux ServerCaldera Openlinux WorkstationDebian LinuxFreebsd+5 | 27/2/2002 | 16/6/2026 | Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice. | |
| Modificada | Alta (7.5) | 5.3% | — | StunnelEngardelinux Secure LinuxMandrakesoft Mandrake LinuxRedhat Linux | 31/1/2002 | 16/6/2026 | Format string vulnerability in stunnel before 3.22 when used in client mode for (1) smtp, (2) pop, or (3) nntp allows remote malicious servers to execute arbitrary code. | |
| Modificada | Media (4.6) | 0.40% | — | Mandrakesoft Mandrake Linux | 12/12/2001 | 16/6/2026 | The default PAM files included with passwd in Mandrake Linux 8.1 do not support MD5 passwords, which could result in a lower level of password security than intended. | |
| Modificada | Alta (7.2) | 0.38% | — | Mandrakesoft Mandrake Linux | 30/11/2001 | 16/6/2026 | Packaging error for expect 8.3.3 in Mandrake Linux 8.1 causes expect to search for its libraries in the /home/snailtalk directory before other directories, which could allow a local user to gain root privileges. | |
| Modificada | Alta (7.5) | 7.8% | — | Apache Http ServerMandrakesoft Mandrake Single Network FirewallMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server | 28/11/2001 | 16/6/2026 | The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories. | |
| Modificada | Baja (2.1) | 0.81% | — | ImmunixUniversity OF Washington PineEngardelinux Secure LinuxMandrakesoft Mandrake Linux+2 | 18/10/2001 | 16/6/2026 | Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack. | |
| Modificada | Alta (7.5) | 2.0% | — | Caldera Openlinux ServerImmunixMandrakesoft Mandrake Single Network FirewallSquid WEB Proxy+4 | 18/7/2001 | 16/6/2026 | Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning. |