Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2776▲ 17 respecto a la semana anterior
Críticas / altas1289▼ 241 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1569 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.42%—GNU Mailutils31/12/200416/6/2026
Unknown vulnerability in the dotlock implementation in mailutils before 1:0.5-4 on Debian GNU/Linux allows attackers to gain privileges.
ModificadaAlta (7.5)2.5%—GNU InetutilsAI31/12/200416/6/2026
Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function.
ModificadaAlta (7.5)3.0%—GNU Sharutils31/12/200416/6/2026
Multiple buffer overflows in sharutils 4.2.1 and earlier may allow attackers to execute arbitrary code via (1) long output from wc to shar, or (2) unknown vectors in unshar.
ModificadaMedia (4.6)0.65%—GNU Sharutils31/12/200416/6/2026
Stack-based buffer overflow in shar in GNU sharutils 4.2.1 allows local users to execute arbitrary code via a long -o command line argument.
ModificadaAlta (7.5)2.5%—Gnubiff31/12/200416/6/2026
Buffer overflow in pop3.c in gnubiff before 2.0.0 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code.
ModificadaBaja (2.1)0.36%—GNU Glibc31/12/200416/6/2026
GNU glibc 2.3.4 before 2.3.4.20040619, 2.3.3 before 2.3.3.20040420, and 2.3.2 before 2.3.2-r10 does not restrict the use of LD_DEBUG for a setuid program, which allows local users to gain sensitive information, such as the list of symbols used by the program.
ModificadaBaja (2.1)0.59%—Gnubiff31/12/200416/6/2026
Unknown vulnerability in gnubiff 1.2.0 and earlier allows local users to obtain passwords, related to the password table.
ModificadaMedia (5)1.6%—Gnubiff31/12/200416/6/2026
Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Unique IDentification Listing (UIDL) list.
ModificadaBaja (2.1)0.36%—GNU Glibc31/12/200416/6/2026
The glibcbug script in glibc 2.3.4 and earlier allows local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2004-0968.
ModificadaBaja (2.1)0.36%—GNU GroffAI31/12/200416/6/2026
The (1) eqn2graph and (2) pic2graph scripts in groff 1.18.1 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
ModificadaAlta (7.5)1.7%—SIR Gnuboard31/12/200416/6/2026
PHP remote file inclusion vulnerability in index.php in GNUBoard 3.39 and earlier allows remote attackers to execute arbitrary PHP code by modifying the doc parameter to reference a URL on a remote web server that contains the code.
ModificadaAlta (7.5)3.3%—GNU Queue31/12/200416/6/2026
Buffer overflow in (1) queue.c and (2) queued.c in queue before 1.30.1 may allow remote attackers to execute arbitrary code.
ModificadaAlta (7.5)1.6%—GNU Mailman31/12/200416/6/2026
The password generation in mailman before 2.1.5 generates only 5 million unique passwords, which makes it easier for remote attackers to guess passwords via a brute force attack.
ModificadaBaja (2.1)0.36%—GNU A2psTurbolinux HomeTurbolinux ServerTurbolinux Workstation27/12/200416/6/2026
The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
ModificadaAlta (7.2)0.40%—GNU Realtime Linux Security ModuleConectiva LinuxUbuntu Linux23/12/200416/6/2026
The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges.
ModificadaMedia (5)1.6%—GNU Radius23/12/200416/6/2026
Desbordamiento de enteros en la función asn_decode_string() definida en asn1.c en radiusd de GNU Radius 1.1 y 1.2 anteriores a 1.2.94, cuando se compila con la opción --enable-snmp, permite a atacantes remotos causar una denegación de servicio (caída del demonio) mediante ciertas peticiones SNMP.
ModificadaAlta (10)4.5%—GNU Gnats6/12/200416/6/2026
Vulnerabilidad de cadena de formato en misc.c en GNU GNATS 4.00 puede permitir a atacantes remotos ejecuta código arbitrario mediante especificadores de cadena de formato en una cadena que sea registrada por syslog
ModificadaAlta (10)3.1%—GNU Gzip6/12/200416/6/2026
gzexe en gzip 1.3.3 y anteriores ejecutaran un argumento cuando la creación de un fichero temporal falla, en lugar de terminar el programa, lo que podría permitir a atacantes remotos o usuarios locales ejecutar órdenes de su elección, una vulnerabilidad diferente de CVE-1999-1332.
ModificadaMedia (5)1.6%—GNU Radius6/12/200416/6/2026
El demonio radius (radiusd) de GNU Radius 1.1, cuando se compila con la opción -enable-snmp, permite a atacantes remotos causar una denegación de servicio (caída del servidor) mediante un mensaje SNMP malformado conteniendo un OID no válido.
ModificadaAlta (10)4.7%💥 ExploitGNU Anubis23/11/200416/6/2026
Multiple buffer overflows in auth_ident() function in auth.c for GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to gain privileges via a long string.
ModificadaBaja (2.1)0.35%—GNU Libtool23/11/200416/6/2026
GNU libtool anteriores a 1.5.2, durante la compilación, permite a usuarios locales sobreescribir ficheros arbitrarios mediante un ataque de enlaces simbólicos en directorios de libtool en /tmp.
ModificadaAlta (10)16%💥 ExploitGNU Anubis23/11/200416/6/2026
Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function in errs.c, or (3) the ssl_error function in ssl.c.
ModificadaMedia (5)2.4%—GNU CVS20/10/200416/6/2026
CVS 1.11.x anteriores a 1.11.17 y 1.12.x anteriores a 1.12.9 permite a atacantes remotos determinar la existencia de ficheros y directorios de su elección mediante el comando -X de un fichero de historia alternativo, lo que hace que devuelve diferentes mensajes de error.
ModificadaBaja (2.1)0.59%—GNU GzipOracle Solaris4/10/200416/6/2026
gzip before 1.3 in Solaris 8, when called with the -f or -force flags, will change the permissions of files that are hard linked to the target files, which allows local users to view or modify these files.
ModificadaMedia (5)3.0%—GNU Mailman18/8/200416/6/2026
Mailman anteriores a 2.1.5 permiten a atacantes remotos obtener contraseñas de usuario mediante peticiones de correo electronico especialmente elaboradas.