Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1388 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)8.9%💥 ExploitRoundup-tracker Roundup31/12/200416/6/2026
Directory traversal vulnerability in Roundup 0.6.4 and earlier allows remote attackers to view arbitrary files via .. (dot dot) sequences in an @@ command in an HTTP GET request.
ModificadaAlta (7.5)1.2%💥 ExploitPhpbugtrackerAI31/12/200416/6/2026
SQL injection vulnerability in bug.php in phpBugTracker 0.9.1 allows remote attackers to execute arbitrary SQL commands via (1) the bug_id parameter in a viewvotes operation or (2) the project parameter in an add operation.
ModificadaAlta (7.2)0.85%💥 ExploitNiels Provos SystraceVladimir Kotal Systrace Port FOR FreebsdNetbsd31/12/200416/6/2026
The systrace_exit function in the systrace utility for NetBSD-current and 2.0 before April 16, 2004, and certain FreeBSD ports, does not verify the owner of the /dec/systrace connection before setting euid to 0, which allows local users to gain root privileges.
ModificadaMedia (5)3.8%💥 ExploitMonolith Productions Contract JackMonolith Productions NO ONE Lives Forever 2Monolith Productions Tron31/12/200416/6/2026
The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron 2.0 1.042 and earlier, (4) F.E.A.R. (First Encounter Assault and Recon), and possibly other games, allows remote attackers to cause a denial of service (connection refused) via a UDP packet that…
ModificadaBaja (2.1)1.9%💥 ExploitFreeform Interactive Purge JihadMonolith Productions Alien Versus PredatorMonolith Productions BloodMonolith Productions Contract Jack+731/12/200416/6/2026
Format string vulnerability in the Lithtech engine, as used in multiple games, allows remote authenticated users to cause a denial of service (application crash) via format string specifiers in (1) a nickname or (2) a message.
ModificadaMedia (4.3)1.4%—Cvstrac31/12/200416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in (1) main.c and (2) login.c for CVSTrac before 1.1.5 allow remote attackers to inject arbitrary HTML and web script.
ModificadaMedia (5)1.8%—Gift-fasttrackGentoo Linux6/12/200416/6/2026
El cliente y servidor HTTP de giFT-FastTrack 0.8.6 y anteriores permite a atacantes remotos causar una denegación de servicio (caída), posiblemente mediante una consulta de búsqueda vacía, lo que dispara una desreferencia de puntero NULL.
ModificadaMedia (5)1.7%—Ratbag Dirt Track RacingRatbag Dirt Track Racing AustraliaRatbag Dirt Track Racing Sprint CarsRatbag Leadfoot+123/11/200416/6/2026
El motor de juegos Ratbag, usado en productos como Dirt Track Racing, Leadfoot, y World of Outlaws Spring Cars, permite a atacantes remotos causar una denegación de servicio (consumición de CPU) mediante un paquete TCP que especifica la longitud de los datos para leer y otro paquete TCP enviado a continuación que…
ModificadaAlta (7.2)0.48%—Juan Cespedes Ltrace15/3/200416/6/2026
Desbordamiento de búfer basado en el montón en la función search_for_command de ltrace 0.3.10, si instalado con setuid, podría permitir a usuarios locales ejecutar código arbitrario mediante un nombre de fichero largo.
ModificadaMedia (5)3.5%💥 ExploitNadeo Game EngineNadeo TrackmaniaNadeo Virtual Skipper8/2/200416/6/2026
Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service (server crash) via malformed data to TCP port 2350, possibly due to long values or incorrect size fields.
ModificadaAlta (10)2.8%—Ehud Gavron Traceroute-nanog7/8/200316/6/2026
traceroute-nanog 6.1.1 permite a usuarios locales sobreescribir memoria no autorizada y posiblemente ejecutar código arbitrario mediante ciertos argumentos que causan un desbordamiento de entero que se usa cuando se asigna memoria , lo que produce un desbordamiento de búfer.
ModificadaAlta (7.2)0.41%—Michael C. Toren Tcptraceroute7/8/200316/6/2026
tcptraceroute 1.4 y anteriores tiene un fallo al soltar los privilegios de root después de obtener un descriptor de fichero para capturar paquetes, lo que puede permitir que usuarios locales ganen acceso al descriptor mediante una vulnerabilidad seperar en tcptraceroute.
ModificadaMedia (6.8)1.2%—Best Practical Solutions Request Tracker27/5/200316/6/2026
Vulnerabilidad de secuencias de comandos en sitios cruzados en la interfaz web para Request Racker (RT) 1.0 hasta 1.0.7 permite que atacantes remotos ejecuten script mediante cuerpos de mensaje.
ModificadaMedia (4.6)0.32%—Ehud Gavron Tracesroute2/1/200316/6/2026
El modo de difusión en traceroute-nanog (también llamado traceroute-ng) puede permitir a usuarios locales sobreescribir posiciones de memoria arbitrarias mediante un desbordamiento de índice de array usando el argumento nprobes (número de sondas)
ModificadaMedia (4.6)0.46%—Ehud Gavron Tracesroute2/1/200316/6/2026
Desbordamiento de búfer en traceroute-nanog (también llamado traceroute-ng) puede permitir a usuarios locales ejecutar código arbitrario mediante un argumento hostname largo.
ModificadaMedia (5)1.4%—Zendocs Zentrack31/12/200216/6/2026
zenTrack 2.0.3 and earlier allows remote attackers to obtain the full path to the web root via an invalid ticket ID, which leaks the path in an error message.
ModificadaAlta (7.5)0.86%—Teekai Tracking Online31/12/200216/6/2026
TeeKai Tracking Online 1.0 uses weak encryption of web usage statistics in data/userlog/log.txt, which allows remote attackers to identify IP's visiting the site by dividing each octet by the MD5 hash of '20'.
ModificadaMedia (4.3)3.5%💥 ExploitTeekai Tracking Online31/12/200216/6/2026
Cross-site scripting (XSS) vulnerability in userlog.php in TeeKai Tracking Online 1.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaAlta (7.2)1.7%💥 ExploitEhud Gavron Tracesroute23/12/200216/6/2026
Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS responses.
ModificadaMedia (4.6)0.59%—Ehud Gavron Tracesroute4/10/200216/6/2026
Format string vulnerability in TrACESroute 6.0 GOLD (aka NANOG traceroute) allows local users to execute arbitrary code via the -T (terminator) command line argument.
ModificadaAlta (10)6.2%—Linux Directory Penguin Traceroute12/8/200216/6/2026
Linux Directory Penguin traceroute.pl CGI script 1.0 allows remote attackers to execute arbitrary code via shell metacharacters in the host parameter.
ModificadaMedia (5)1.7%—Fasttrack KazaaGroksterMusic City Networks Morpheus25/6/200216/6/2026
fasttrack p2p, as used in (1) KaZaA before 1.5, (2) grokster, and (3) morpheus allows remote attackers to cause a denial of service (memory exhaustion) via a series of client-to-client messages, which pops up new windows per message.
ModificadaAlta (7.5)1.8%—Fasttrack KazaaGroksterMusic City Networks Morpheus25/6/200216/6/2026
fasttrack p2p, as used in (1) KaZaA, (2) grokster, and (3) morpheus allows remote attackers to spoof other users by modifying the username and network information in the message header.
ModificadaMedia (5)2.5%—Netscape Fasttrack Server26/3/200116/6/2026
The caching module in Netscape Fasttrack Server 4.1 allows remote attackers to cause a denial of service (resource exhaustion) by requesting a large number of non-existent URLs.
ModificadaMedia (5)1.9%—Netscape Enterprise ServerNetscape Fasttrack Server12/3/200116/6/2026
Netscape Enterprise 3.5.1 and FastTrack 3.01 servers allow a remote attacker to view source code to scripts by appending a %20 to the script's URL.