Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2709▼ 126 respecto a la semana anterior
Críticas / altas1231▼ 312 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)257▲ 221 respecto a la semana anterior
–

1280 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)2.8%💥 ExploitPwdutils5/11/200516/6/2026
chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.
ModificadaAlta (7.5)15%💥 ExploitGNU Mailutils13/9/200516/6/2026
Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command.
ModificadaAlta (7.2)0.43%—Andries Brouwer Util-linux13/9/200516/6/2026
umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages such as loop-aes-utils, allows local users with unmount permissions to gain privileges via the -r (remount) option, which causes the file system to be remounted with just the read-only flag, which effectively clears the nosuid, nodev, and…
ModificadaAlta (7.5)1.1%—GNU Mailutils2/6/200516/6/2026
The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "\" (backslash) character, which is used as an escape character and makes the module vulnerable to SQL injection attacks.
ModificadaAlta (7.5)6.7%💥 ExploitGNU Mailutils26/5/200516/6/2026
Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a crafted e-mail.
ModificadaMedia (5)1.7%—GNU Mailutils26/5/200516/6/2026
The imap4d server for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows authenticated remote users to cause a denial of service (CPU consumption) via a large range value in the FETCH command.
ModificadaAlta (7.5)3.3%—GNU Mailutils26/5/200516/6/2026
Integer overflow in the fetch_io function of the imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a partial message request with a large value in the END parameter, which leads to a heap-based buffer overflow.
ModificadaAlta (7.5)9.8%💥 ExploitGNU Mailutils26/5/200516/6/2026
Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands.
ModificadaBaja (3.7)0.28%—GNU Coreutils2/5/200516/6/2026
Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.
ModificadaAlta (7.2)0.35%—Dameware Development Mini Remote ControlDameware Development NT Utilities2/5/200516/6/2026
Unknown vulnerability in DameWare NT Utilities 4.8 and earlier, and Mini Remote Control 4.8 and earlier, allows local users to gain additional rights.
ModificadaBaja (2.1)0.35%—Dameware Development Dameware NT UtilitiesDameware Development Miniremote Control2/5/200516/6/2026
The DNTUS26 process in Dameware NT Utilities and the DWRCS process in MiniRemote Control 4.9 and earlier stores the username and password in cleartext in memory, which could allow attackers to obtain sensitive information.
ModificadaBaja (2.1)0.36%—GNU Sharutils2/5/200516/6/2026
unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
ModificadaAlta (7.5)3.1%—Gocr Optical Character Recognition Utility15/4/200516/6/2026
Heap-based buffer overflow in the readpgm function in pnm.c for GOCR 0.40, when it is not using netpbm, allows remote attackers to execute arbitrary code via a P3 format PNM file with more data than implied by its width and height values.
ModificadaMedia (4.6)0.36%—Rsnapshot Filesystem Snapshot Utility10/4/200516/6/2026
The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files.
ModificadaBaja (2.1)0.39%—LVM Logical Volume Management UtilitiesGentoo Linux9/2/200516/6/2026
The lvmcreate_initrd script in the lvm package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
ModificadaMedia (5)2.4%—Nfs-utilsDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+210/1/200516/6/2026
statd en nfs-utils 1.257 y anteriores hace caso a la señal SIGPIPE, lo que permite a atacanes remotos causar una denegación de servicio (caída de proceso de servidor) mediante una conexión TCP que es terminada prematuramente.
ModificadaBaja (2.1)0.36%—Uml-utilities10/1/200516/6/2026
La función slip_down del programa uml_net de uml-utilities 20030903, cuando uml_net está instalado con setuid root, no verifica si el usuario llamante tiene suficientes permisos para desactivar una interfaz, lo que permite a usuarios locales causar una denegación de servicio (servicio de red deshabilitado)
ModificadaAlta (10)11%—Nfs-utilsRedhat Enterprise LinuxRedhat Enterprise Linux Desktop10/1/200516/6/2026
rquotad en nfs-utils (rquota_server.c) anteriores a 1.0.6-r6 en arquitecturas de 64 bits no realiza una conversión de enteros adecuadamente, lo que conduce a un desbordamiento de búfer basado en la pila y permite a atacantes remotos ejecutar código arbitrario mediante una petición NFS artesanal.
ModificadaBaja (2.1)0.43%—Context TexutilAI31/12/200416/6/2026
TEXutil in ConTEXt, when executed with the --silent option, allows local users to overwrite arbitrary files via a symlink attack on texutil.log.
ModificadaAlta (7.5)3.0%—GNU Sharutils31/12/200416/6/2026
Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.
ModificadaAlta (7.5)3.8%—Twilight Utilities WEB Server31/12/200416/6/2026
Buffer overflow in postfile.exe for Twilight Utilities Web Server 2.0.0.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request with a long attfile attribute.
ModificadaAlta (10)5.6%💥 ExploitDell Truemobile 1300 Wlan Mini-pci Card Util Trayapplet31/12/200416/6/2026
Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which allows local users to gain privileges by accessing the Help functionality.
ModificadaMedia (5)2.6%—Intel CLI Auto-configuration UtilityIntel Client System Setup UtilityIntel Server Configuration WizardIntel Server Control+1831/12/200416/6/2026
The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.
ModificadaBaja (2.1)0.30%—SUN Storedge QFSSUN Storedge Sam-qfsSUN Storeedge Performance SuiteSUN Storeedge Utilization Suite31/12/200416/6/2026
Shared Sun StorEdge QFS and SAM-QFS file systems, as used in Utilization Suite 4.0 through 4.1 and Performance Suite 4.0 through 4.1, might allow local users to read portions of deleted files by accessing data within sparse files.
ModificadaAlta (7.2)0.42%—GNU Mailutils31/12/200416/6/2026
Unknown vulnerability in the dotlock implementation in mailutils before 1:0.5-4 on Debian GNU/Linux allows attackers to gain privileges.