Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2766▼ 23 respecto a la semana anterior
Críticas / altas1275▼ 257 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)241▲ 204 respecto a la semana anterior
1569 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.7) | 0.54% | — | GNU Cpio | 15/12/2005 | 16/6/2026 | Buffer overflow in cpio 2.6-8.FC4 on 64-bit platforms, when creating a cpio archive, allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a file whose size is represented by more than 8 digits. | |
| Modificada | Alta (7.8) | 3.1% | — | GNU Mailman | 11/12/2005 | 16/6/2026 | Mailman 2.1.4 a 2.1.6 permite a atacantes remotos causar una denegación de servicio mediante un mensaje que causa que el servidor "falle con un desbordamiento en datos de fecha incorrectos en un mensaje procesado", una vulnerabilidad diferente de CVE-2005-3572. | |
| Modificada | Baja (1.9) | 0.36% | — | Gnump3d | 18/11/2005 | 16/6/2026 | GNU Gnump3d before 2.9.8 allows local users to modify or delete arbitrary files via a symlink attack on the index.lok temporary file. | |
| Modificada | Media (6.4) | 2.2% | — | Gnump3d | 18/11/2005 | 16/6/2026 | Directory traversal vulnerability in GNU Gnump3d before 2.9.8 has unknown impact via "CGI parameters, and cookie values". | |
| Modificada | Media (5) | 2.7% | — | GNU Mailman | 16/11/2005 | 16/6/2026 | Scrubber.py in Mailman 2.1.5-8 does not properly handle UTF8 character encodings in filenames of e-mail attachments, which allows remote attackers to cause a denial of service (application crash). | |
| Modificada | Media (4.3) | 1.8% | — | Gnump3d | 1/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2005-3424. | |
| Modificada | Media (4.3) | 1.4% | — | Gnump3d | 1/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in GNUMP3D before 2.9.5 allows remote attackers to inject arbitrary web script or HTML via 404 error pages, a different vulnerability than CVE-2005-3425. | |
| Modificada | Media (5) | 3.0% | — | Gnump3d | 30/10/2005 | 16/6/2026 | Directory traversal vulnerability in GNUMP3D before 2.9.6 allows remote attackers to read arbitrary files via crafted sequences such as "/.//..//////././", which is collapsed into "/.././" after ".." and "//" sequences are removed. | |
| Modificada | Baja (2.1) | 0.43% | — | GNU CfengineDebian Linux | 5/10/2005 | 16/6/2026 | cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in, a different vulnerability than CVE-2005-3137. | |
| Modificada | Baja (2.1) | 0.43% | — | GNU Cfengine | 5/10/2005 | 16/6/2026 | The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960. | |
| Modificada | Baja (1.2) | 0.51% | — | GNU Texinfo | 21/9/2005 | 16/6/2026 | The sort_offline function for texindex in texinfo 4.8 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | GNU Mailutils | 13/9/2005 | 16/6/2026 | Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command. | |
| Modificada | Alta (10) | 4.0% | — | GNU TAR | 10/8/2005 | 16/6/2026 | Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges. | |
| Modificada | Media (4.3) | 1.8% | 💥 Exploit | GNU Phpbook | 27/7/2005 | 16/6/2026 | Vulnerabilidad de secuencia de comandos en sitios cruzados en guestbook.php en phpBook 1.46 permite que atacantes remotos inyecten script web arbitrario o HTML mediante el parámetro "admin". | |
| Modificada | Baja (2.1) | 0.35% | — | GNU Gnats | 11/7/2005 | 16/6/2026 | gen-index in GNATS 4.0, 4.1.0, and possibly earlier versions, when installed setuid, does not properly check files passed to the -o argument and opens the file with write access, which allows local users to overwrite arbitrary files. | |
| Modificada | Alta (7.5) | 1.1% | — | GNU Mailutils | 2/6/2005 | 16/6/2026 | The sql_escape_string function in auth/sql.c for the mailutils SQL authentication module does not properly quote the "\" (backslash) character, which is used as an escape character and makes the module vulnerable to SQL injection attacks. | |
| Modificada | Alta (7.5) | 9.8% | 💥 Exploit | GNU Mailutils | 26/5/2005 | 16/6/2026 | Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands. | |
| Modificada | Alta (7.5) | 3.3% | — | GNU Mailutils | 26/5/2005 | 16/6/2026 | Integer overflow in the fetch_io function of the imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a partial message request with a large value in the END parameter, which leads to a heap-based buffer overflow. | |
| Modificada | Alta (7.5) | 6.7% | 💥 Exploit | GNU Mailutils | 26/5/2005 | 16/6/2026 | Buffer overflow in the header_get_field_name function in header.c for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via a crafted e-mail. | |
| Modificada | Media (5) | 1.7% | — | GNU Mailutils | 26/5/2005 | 16/6/2026 | The imap4d server for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows authenticated remote users to cause a denial of service (CPU consumption) via a large range value in the FETCH command. | |
| Modificada | Alta (7.2) | 0.44% | — | GNU GDB | 24/5/2005 | 16/6/2026 | gdb before 6.3 searches the current working directory to load the .gdbinit configuration file, which allows local users to execute arbitrary commands as the user running gdb. | |
| Modificada | Media (4.6) | 0.60% | — | GNU GDB | 24/5/2005 | 16/6/2026 | Integer overflow in the Binary File Descriptor (BFD) library for gdb before 6.3, binutils, elfutils, and possibly other packages, allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow. | |
| Modificada | Media (4.6) | 0.53% | — | GNU GzipCanonical Ubuntu Linux | 13/5/2005 | 16/6/2026 | zgrep in gzip before 1.3.5 does not properly sanitize arguments, which allows local users to execute arbitrary commands via filenames that are injected into a sed script. | |
| Modificada | Media (5) | 2.2% | — | Gnutls | 3/5/2005 | 16/6/2026 | The "record packet parsing" in GnuTLS 1.2 before 1.2.3 and 1.0 before 1.0.25 allows remote attackers to cause a denial of service, possibly related to padding bytes in gnutils_cipher.c. | |
| Modificada | Media (4.7) | 0.31% | — | GNU CpioDebian LinuxCanonical Ubuntu Linux | 2/5/2005 | 16/6/2026 | Race condition in cpio 2.6 and earlier allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by cpio after the decompression is complete. |