Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 9 respecto a la semana anterior
Críticas / altas1289▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
1569 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.7) | 0.66% | — | GNU GzipFreebsdGentoo LinuxRedhat Enterprise Linux+9 | 2/5/2005 | 16/6/2026 | Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete. | |
| Modificada | Crítica (9.8) | 2.6% | — | SIR Gnuboard | 2/5/2005 | 16/6/2026 | The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters. | |
| Modificada | Media (5) | 1.4% | — | GNU MailmanUbuntu Linux | 2/5/2005 | 16/6/2026 | The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address. | |
| Modificada | Media (5) | 1.8% | — | Magnus Lundvall Yawcam | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in Yawcam 0.2.5 allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in a GET request. | |
| Modificada | Baja (2.1) | 0.36% | — | GNU Sharutils | 2/5/2005 | 16/6/2026 | unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file. | |
| Modificada | Media (5) | 2.9% | — | Gnupg | 2/5/2005 | 16/6/2026 | The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine… | |
| Modificada | Media (4.6) | 2.1% | — | GNU Cpio | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file. | |
| Modificada | Media (5) | 3.6% | — | GNU Gzip | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file. | |
| Modificada | Baja (3.7) | 0.28% | — | GNU Coreutils | 2/5/2005 | 16/6/2026 | Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files. | |
| Modificada | Media (5) | 2.9% | — | GNU Mailman | 2/5/2005 | 16/6/2026 | Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences. | |
| Modificada | Media (5) | 12% | 💥 Exploit | GNU Wget | 27/4/2005 | 16/6/2026 | wget 1.8.x y 1.9.x no filtra o pone comillas a caractéres de control cuando se muestran respuestas HTTP en el terminal, lo que puede permitir a servidores web maliciosos inyectar secuencias de escape y ejecutar código de su elección. | |
| Modificada | Media (5) | 1.7% | — | GNU Wget | 27/4/2005 | 16/6/2026 | wget 1.8.x y 1.9.x permite a un servidor web remoto malicioso sobreescribir ciertos ficheros mediante una redirección URL conteniendo un ".." que se resuelve como la dirección IP de un usuario malicioso, lo que se salta el filtrado de wget de secuencias "..". | |
| Modificada | Baja (2.1) | 0.40% | — | GNU GettextUbuntu Linux | 9/2/2005 | 16/6/2026 | The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Baja (2.1) | 0.36% | — | GNU Gzip | 9/2/2005 | 16/6/2026 | The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367. | |
| Modificada | Baja (2.1) | 0.37% | — | GNU GroffGentoo LinuxUbuntu Linux | 9/2/2005 | 16/6/2026 | The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Baja (2.1) | 0.39% | — | GNU GlibcRedhat Enterprise LinuxRedhat Enterprise Linux Desktop | 9/2/2005 | 16/6/2026 | The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 4.3% | — | GNU EmacsGNU Xemacs | 7/2/2005 | 16/6/2026 | Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets. | |
| Modificada | Alta (7.5) | 4.4% | — | GNU Enscript | 21/1/2005 | 16/6/2026 | Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames. | |
| Modificada | Media (4.6) | 1.2% | — | GNU EnscriptSGI PropackRedhat Fedora CoreSuse Linux | 21/1/2005 | 16/6/2026 | The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters. | |
| Modificada | Media (4.3) | 1.8% | — | GNU Mailman | 10/1/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | GNU A2psSUN Java Desktop SystemSuse Linux | 10/1/2005 | 16/6/2026 | a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename. | |
| Modificada | Media (5) | 4.0% | — | GNU Enscript | 31/12/2004 | 16/6/2026 | Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash). | |
| Modificada | Media (6.4) | 2.0% | — | GNU Less | 31/12/2004 | 16/6/2026 | Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid, then this is not a vulnerability unless… | |
| Modificada | Baja (2.6) | 0.96% | 💥 Exploit | GNU Wget | 31/12/2004 | 16/6/2026 | Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded. | |
| Modificada | Alta (7.8) | 1.7% | — | Gnutls | 31/12/2004 | 16/6/2026 | X.509 Certificate Signature Verification in Gnu transport layer security library (GnuTLS) 1.0.16 allows remote attackers to cause a denial of service (CPU consumption) via certificates containing long chains and signed with large RSA keys. |