Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
1388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 8.9% | 💥 Exploit | Roundup-tracker Roundup | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | PhpbugtrackerAI | 31/12/2004 | 16/6/2026 | SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation. | |
| Modificada | Alta (7.2) | 0.85% | 💥 Exploit | Niels Provos SystraceVladimir Kotal Systrace Port FOR FreebsdNetbsd | 31/12/2004 | 16/6/2026 | The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges. | |
| Modificada | Media (5) | 3.8% | 💥 Exploit | Monolith Productions Contract JackMonolith Productions NO ONE Lives Forever 2Monolith Productions Tron | 31/12/2004 | 16/6/2026 | The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that… | |
| Modificada | Baja (2.1) | 1.9% | 💥 Exploit | Freeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+7 | 31/12/2004 | 16/6/2026 | Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message. | |
| Modificada | Media (4.3) | 1.4% | — | Cvstrac | 31/12/2004 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script. | |
| Modificada | Media (5) | 1.8% | — | Gift-fasttrackGentoo Linux | 6/12/2004 | 16/6/2026 | El cliente y servidor HTTP de giFT-FastTrack 0.8.6 y anteriores permite a atacantes remotos causar una denegación de servicio (caída), posiblemente mediante una consulta de búsqueda vacía, lo que dispara una desreferencia de puntero NULL. | |
| Modificada | Media (5) | 1.7% | — | Ratbag Dirt Track RacingRatbag Dirt Track Racing AustraliaRatbag Dirt Track Racing Sprint CarsRatbag Leadfoot+1 | 23/11/2004 | 16/6/2026 | El motor de juegos Ratbag, usado en productos como Dirt Track Racing, Leadfoot, y World of Outlaws Spring Cars, permite a atacantes remotos causar una denegación de servicio (consumición de CPU) mediante un paquete TCP que especifica la longitud de los datos para leer y otro paquete TCP enviado a continuación que… | |
| Modificada | Alta (7.2) | 0.48% | — | Juan Cespedes Ltrace | 15/3/2004 | 16/6/2026 | Desbordamiento de búfer basado en el montón en la función search_for_command de ltrace 0.3.10, si instalado con setuid, podría permitir a usuarios locales ejecutar código arbitrario mediante un nombre de fichero largo. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Nadeo Game EngineNadeo TrackmaniaNadeo Virtual Skipper | 8/2/2004 | 16/6/2026 | Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields. | |
| Modificada | Alta (10) | 2.8% | — | Ehud Gavron Traceroute-nanog | 7/8/2003 | 16/6/2026 | traceroute-nanog 6.1.1 permite a usuarios locales sobreescribir memoria no autorizada y posiblemente ejecutar código arbitrario mediante ciertos argumentos que causan un desbordamiento de entero que se usa cuando se asigna memoria , lo que produce un desbordamiento de búfer. | |
| Modificada | Alta (7.2) | 0.41% | — | Michael C. Toren Tcptraceroute | 7/8/2003 | 16/6/2026 | tcptraceroute 1.4 y anteriores tiene un fallo al soltar los privilegios de root después de obtener un descriptor de fichero para capturar paquetes, lo que puede permitir que usuarios locales ganen acceso al descriptor mediante una vulnerabilidad seperar en tcptraceroute. | |
| Modificada | Media (6.8) | 1.2% | — | Best Practical Solutions Request Tracker | 27/5/2003 | 16/6/2026 | Vulnerabilidad de secuencias de comandos en sitios cruzados en la interfaz web para Request Racker (RT) 1.0 hasta 1.0.7 permite que atacantes remotos ejecuten script mediante cuerpos de mensaje. | |
| Modificada | Media (4.6) | 0.32% | — | Ehud Gavron Tracesroute | 2/1/2003 | 16/6/2026 | El modo de difusión en traceroute-nanog (también llamado traceroute-ng) puede permitir a usuarios locales sobreescribir posiciones de memoria arbitrarias mediante un desbordamiento de índice de array usando el argumento nprobes (número de sondas) | |
| Modificada | Media (4.6) | 0.46% | — | Ehud Gavron Tracesroute | 2/1/2003 | 16/6/2026 | Desbordamiento de búfer en traceroute-nanog (también llamado traceroute-ng) puede permitir a usuarios locales ejecutar código arbitrario mediante un argumento hostname largo. | |
| Modificada | Media (5) | 1.4% | — | Zendocs Zentrack | 31/12/2002 | 16/6/2026 | zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message. | |
| Modificada | Alta (7.5) | 0.86% | — | Teekai Tracking Online | 31/12/2002 | 16/6/2026 | TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'. | |
| Modificada | Media (4.3) | 3.5% | 💥 Exploit | Teekai Tracking Online | 31/12/2002 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in userlog.php in TeeKai Tracking Online 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Alta (7.2) | 1.7% | 💥 Exploit | Ehud Gavron Tracesroute | 23/12/2002 | 16/6/2026 | Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses. | |
| Modificada | Media (4.6) | 0.59% | — | Ehud Gavron Tracesroute | 4/10/2002 | 16/6/2026 | Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument. | |
| Modificada | Alta (10) | 6.2% | — | Linux Directory Penguin Traceroute | 12/8/2002 | 16/6/2026 | Linux Directory Penguin traceroute.pl CGI script 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter. | |
| Modificada | Media (5) | 1.7% | — | Fasttrack KazaaGroksterMusic City Networks Morpheus | 25/6/2002 | 16/6/2026 | fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message. | |
| Modificada | Alta (7.5) | 1.8% | — | Fasttrack KazaaGroksterMusic City Networks Morpheus | 25/6/2002 | 16/6/2026 | fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header. | |
| Modificada | Media (5) | 2.5% | — | Netscape Fasttrack Server | 26/3/2001 | 16/6/2026 | The caching module in Netscape Fasttrack Server 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by requesting a large number of non-existent URLs. | |
| Modificada | Media (5) | 1.9% | — | Netscape Enterprise ServerNetscape Fasttrack Server | 12/3/2001 | 16/6/2026 | Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script's URL. |