Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 1.3% | — | Apple InstallerApple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an Apple server. | |
| Modificada | Media (5) | 0.98% | — | Apple TerminalApple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | The default configuration of Terminal in Apple Mac OS X 10.6 before 10.6.7 uses SSH protocol version 1 within the New Remote Connection dialog, which might make it easier for man-in-the-middle attackers to spoof SSH servers by leveraging protocol vulnerabilities. | |
| Modificada | Media (6.8) | 2.9% | — | Apple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | QuickLook in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via an Excel spreadsheet with a crafted formula that uses unspecified opcodes. | |
| Modificada | Media (5) | 1.9% | — | Apple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Libinfo in Apple Mac OS X before 10.6.7 does not properly handle an unspecified integer field in an NFS RPC packet, which allows remote attackers to cause a denial of service (lockd, statd, mountd, or portmap outage) via a crafted packet, related to an "integer truncation issue." | |
| Modificada | Alta (7.2) | 1.7% | 💥 Exploit | Apple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | The i386_set_ldt system call in the kernel in Apple Mac OS X before 10.6.7 does not properly handle call gates, which allows local users to gain privileges via vectors involving the creation of a call gate entry. | |
| Modificada | Media (6.8) | 2.8% | — | Apple MAC OS XApple ImageioApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Integer overflow in ImageIO in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted XBM image. | |
| Modificada | Baja (2.1) | 0.68% | 💥 Exploit | Apple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Integer overflow in HFS in Apple Mac OS X before 10.6.7 allows local users to read arbitrary (1) HFS, (2) HFS+, or (3) HFS+J files via a crafted F_READBOOTSTRAP ioctl call. | |
| Modificada | Media (6.8) | 2.4% | — | Apple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | CoreText in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a document that contains a crafted embedded font. | |
| Modificada | Baja (2.1) | 0.33% | — | Apple MAC OS XApple CarboncoreApple MAC OS X Server | 23/3/2011 | 16/6/2026 | The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory. | |
| Modificada | Media (6.8) | 2.8% | — | Apple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted SFNT table in an embedded font. | |
| Modificada | Media (6.8) | 2.8% | — | Apple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded Type 1 font. | |
| Modificada | Media (6.8) | 2.8% | — | Apple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Multiple buffer overflows in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code via a document that contains a crafted embedded TrueType font. | |
| Modificada | Media (6.8) | 2.2% | — | Apple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.7 allows remote attackers to execute arbitrary code via a document that contains a crafted embedded OpenType font. | |
| Modificada | Media (6.8) | 1.8% | — | Apple MAC OS XApplescriptApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Multiple format string vulnerabilities in AppleScript in Apple Mac OS X before 10.6.7 allow context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) display dialog or (2) display alert command in a dialog in an AppleScript Studio… | |
| Modificada | Media (4.9) | 0.53% | — | Apple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | AirPort in Apple Mac OS X 10.6 before 10.6.7 allows remote attackers to cause a denial of service (divide-by-zero error and reboot) via Wi-Fi frames on the local wireless network, a different vulnerability than CVE-2011-0162. | |
| Modificada | Media (6.8) | 5.5% | — | Apple MAC OS XApple MAC OS X ServerApple Iphone OS | 11/3/2011 | 16/6/2026 | Integer overflow in QuickLook, as used in Apple Mac OS X before 10.6.7 and MobileSafari in Apple iOS before 4.2.7 and 4.3.x before 4.3.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a Microsoft Office document with a crafted size field in… | |
| Modificada | Media (6.8) | 2.2% | — | Apple MAC OS XApple MAC OS X Server | 10/1/2011 | 16/6/2026 | Format string vulnerability in PackageKit in Apple Mac OS X 10.6.x before 10.6.6 allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to interaction between Software Update and distribution scripts. | |
| Modificada | Media (4) | 0.89% | — | Apple MAC OS X Server | 17/11/2010 | 16/6/2026 | Dovecot in Apple Mac OS X 10.6.5 10H574 does not properly manage memory for user names, which allows remote authenticated users to read the private e-mail of other persons in opportunistic circumstances via standard e-mail clients accessing a user's own mailbox, related to a "memory aliasing issue." | |
| Modificada | Media (6.8) | 2.9% | — | Apple MAC OS XApple MAC OS X Server | 16/11/2010 | 16/6/2026 | Integer signedness error in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 allows remote attackers to execute arbitrary code via a crafted embedded Compact Font Format (CFF) font in a document. | |
| Modificada | Media (6.8) | 3.3% | — | Apple MAC OS XApple MAC OS X Server | 16/11/2010 | 16/6/2026 | Heap-based buffer overflow in xar in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted xar archive. | |
| Modificada | Baja (3.5) | 1.3% | — | Apple MAC OS X Server | 16/11/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | — | Apple MAC OS XApple MAC OS X Server | 16/11/2010 | 16/6/2026 | Safari RSS in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 does not block Java applets in an RSS feed, which allows remote attackers to obtain sensitive information via a feed: URL containing an applet that performs DOM modifications. | |
| Modificada | Media (6.8) | 2.9% | — | Apple MAC OS XApple MAC OS X Server | 16/11/2010 | 16/6/2026 | QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of GIF image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted GIF file. | |
| Modificada | Media (6.8) | 2.9% | — | Apple MAC OS XApple MAC OS X Server | 16/11/2010 | 16/6/2026 | QuickTime in Apple Mac OS X 10.6.x before 10.6.5 accesses uninitialized memory locations during processing of FlashPix image data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FlashPix file. | |
| Modificada | Media (6.8) | 2.8% | — | Apple QuicktimeApple MAC OS XApple MAC OS X Server | 16/11/2010 | 16/6/2026 | QuickTime in Apple Mac OS X 10.6.x before 10.6.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Sorenson movie file. |