Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2774▲ 9 respecto a la semana anterior
Críticas / altas1289▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

1569 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.7)0.66%—GNU GzipFreebsdGentoo LinuxRedhat Enterprise Linux+92/5/200516/6/2026
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
ModificadaCrítica (9.8)2.6%—SIR Gnuboard2/5/200516/6/2026
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.
ModificadaMedia (5)1.4%—GNU MailmanUbuntu Linux2/5/200516/6/2026
The 55_options_traceback.dpatch patch for mailman 2.1.5 in Ubuntu 4.10 displays a different error message depending on whether the e-mail address is subscribed to a private list, which allows remote attackers to determine the list membership for a given e-mail address.
ModificadaMedia (5)1.8%—Magnus Lundvall Yawcam2/5/200516/6/2026
Directory traversal vulnerability in Yawcam 0.2.5 allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in a GET request.
ModificadaBaja (2.1)0.36%—GNU Sharutils2/5/200516/6/2026
unshar (unshar.c) in sharutils 4.2.1 allows local users to overwrite arbitrary files via a symlink attack on the unsh.X temporary file.
ModificadaMedia (5)2.9%—Gnupg2/5/200516/6/2026
The integrity check feature in OpenPGP, when handling a message that was encrypted using cipher feedback (CFB) mode, allows remote attackers to recover part of the plaintext via a chosen-ciphertext attack when the first 2 bytes of a message block are known, and an oracle or other mechanism is available to determine…
ModificadaMedia (4.6)2.1%—GNU Cpio2/5/200516/6/2026
Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file.
ModificadaMedia (5)3.6%—GNU Gzip2/5/200516/6/2026
Directory traversal vulnerability in gunzip -N in gzip 1.2.4 through 1.3.5 allows remote attackers to write to arbitrary directories via a .. (dot dot) in the original filename within a compressed file.
ModificadaBaja (3.7)0.28%—GNU Coreutils2/5/200516/6/2026
Race condition in Core Utilities (coreutils) 5.2.1, when (1) mkdir, (2) mknod, or (3) mkfifo is running with the -m switch, allows local users to modify permissions of other files.
ModificadaMedia (5)2.9%—GNU Mailman2/5/200516/6/2026
Directory traversal vulnerability in the true_path function in private.py for Mailman 2.1.5 and earlier allows remote attackers to read arbitrary files via ".../....///" sequences, which are not properly cleansed by regular expressions that are intended to remove "../" and "./" sequences.
ModificadaMedia (5)12%💥 ExploitGNU Wget27/4/200516/6/2026
wget 1.8.x y 1.9.x no filtra o pone comillas a caractéres de control cuando se muestran respuestas HTTP en el terminal, lo que puede permitir a servidores web maliciosos inyectar secuencias de escape y ejecutar código de su elección.
ModificadaMedia (5)1.7%—GNU Wget27/4/200516/6/2026
wget 1.8.x y 1.9.x permite a un servidor web remoto malicioso sobreescribir ciertos ficheros mediante una redirección URL conteniendo un ".." que se resuelve como la dirección IP de un usuario malicioso, lo que se salta el filtrado de wget de secuencias "..".
ModificadaBaja (2.1)0.40%—GNU GettextUbuntu Linux9/2/200516/6/2026
The (1) autopoint and (2) gettextize scripts in the GNU gettext package 1.14 and later versions, as used in Trustix Secure Linux 1.5 through 2.1 and other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
ModificadaBaja (2.1)0.36%—GNU Gzip9/2/200516/6/2026
The (1) gzexe, (2) zdiff, and (3) znew scripts in the gzip package, as used by other packages such as ncompress, allows local users to overwrite files via a symlink attack on temporary files. NOTE: the znew vulnerability may overlap CVE-2003-0367.
ModificadaBaja (2.1)0.37%—GNU GroffGentoo LinuxUbuntu Linux9/2/200516/6/2026
The groffer script in the Groff package 1.18 and later versions, as used in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
ModificadaBaja (2.1)0.39%—GNU GlibcRedhat Enterprise LinuxRedhat Enterprise Linux Desktop9/2/200516/6/2026
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
ModificadaAlta (7.5)4.3%—GNU EmacsGNU Xemacs7/2/200516/6/2026
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.
ModificadaAlta (7.5)4.4%—GNU Enscript21/1/200516/6/2026
Enscript 1.6.3 does not sanitize filenames, which allows remote attackers or local users to execute arbitrary commands via crafted filenames.
ModificadaMedia (4.6)1.2%—GNU EnscriptSGI PropackRedhat Fedora CoreSuse Linux21/1/200516/6/2026
The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.
ModificadaMedia (4.3)1.8%—GNU Mailman10/1/200516/6/2026
Cross-site scripting (XSS) vulnerability in the driver script in mailman before 2.1.5 allows remote attackers to inject arbitrary web script or HTML via a URL, which is not properly escaped in the resulting error page.
ModificadaAlta (10)16%💥 ExploitGNU A2psSUN Java Desktop SystemSuse Linux10/1/200516/6/2026
a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
ModificadaMedia (5)4.0%—GNU Enscript31/12/200416/6/2026
Multiple buffer overflows in enscript 1.6.3 allow remote attackers or local users to cause a denial of service (application crash).
ModificadaMedia (6.4)2.0%—GNU Less31/12/200416/6/2026
Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid, then this is not a vulnerability unless…
ModificadaBaja (2.6)0.96%💥 ExploitGNU Wget31/12/200416/6/2026
Wget 1.9 and 1.9.1 allows local users to overwrite arbitrary files via a symlink attack on the name of the file being downloaded.
ModificadaAlta (7.8)1.7%—Gnutls31/12/200416/6/2026
X.509 Certificate Signature Verification in Gnu transport layer security library (GnuTLS) 1.0.16 allows remote attackers to cause a denial of service (CPU consumption) via certificates containing long chains and signed with large RSA keys.