Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

176 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)4.1%—Mandrakesoft Mandrake Single Network FirewallOpenldapDebian LinuxMandrakesoft Mandrake Linux+216/7/200116/6/2026
slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field.
ModificadaAlta (7.5)2.4%—LicqConectiva LinuxFreebsdMandrakesoft Mandrake Linux+22/7/200116/6/2026
licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
ModificadaAlta (7.5)4.6%—LicqConectiva LinuxMandrakesoft Mandrake Linux2/7/200116/6/2026
Buffer overflow in logging functions of licq before 1.0.3 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands.
ModificadaAlta (7.2)0.42%—Mandrakesoft Mandrake Linux27/6/200116/6/2026
Vulnerability in rpmdrake in Mandrake Linux 8.0 related to insecure temporary file handling.
ModificadaAlta (7.5)2.1%—ImmunixMuttConectiva LinuxMandrakesoft Mandrake Linux+127/6/200116/6/2026
Format string vulnerability in Mutt before 1.2.5 allows a remote malicious IMAP server to execute arbitrary commands.
ModificadaBaja (2.1)0.44%—Debian Sgml-toolsImmunixMandrakesoft Mandrake Linux27/6/200116/6/2026
sgml-tools (aka sgmltools) before 1.0.9-15 creates temporary files with insecure permissions, which allows other users to read files that are being processed by sgml-tools.
ModificadaAlta (7.5)2.4%—Ralf S. Engelschall EperlDebian LinuxMandrakesoft Mandrake LinuxSuse Linux27/6/200116/6/2026
Multiple buffer overflows in ePerl before 2.2.14-0.7 allow local and remote attackers to execute arbitrary commands.
ModificadaMedia (4.6)0.39%—Mandrakesoft Mandrake LinuxRedhat Linux27/6/200116/6/2026
kdesu in kdelibs package creates world readable temporary files containing authentication info, which can allow local users to gain privileges.
ModificadaAlta (7.5)2.7%—Debian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Linux27/6/200116/6/2026
Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.
ModificadaAlta (10)2.7%—FreebsdMandrakesoft Mandrake LinuxSuse Linux27/6/200116/6/2026
time server daemon timed allows remote attackers to cause a denial of service via malformed packets.
ModificadaBaja (2.1)0.34%—Brian Paul MesaMandrakesoft Mandrake Linux27/6/200116/6/2026
Utah-glx in Mesa before 3.3-14 on Mandrake Linux 7.2 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/glxmemory file.
ModificadaAlta (7.2)0.86%—Debian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server3/5/200116/6/2026
Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
ModificadaBaja (2.1)0.36%—Conectiva LinuxCaldera Openlinux EdesktopMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+126/3/200116/6/2026
kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
ModificadaBaja (2.1)0.86%—Mandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat LinuxTrustix Secure Linux+126/3/200116/6/2026
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
ModificadaAlta (7.2)0.42%—Redhat Linux PowertoolsZopeConectiva LinuxDebian Linux+312/3/200116/6/2026
Zope before 2.2.4 does not properly compute local roles, which could allow users to bypass specified access restrictions and gain privileges.
ModificadaBaja (1.2)0.30%—ImmunixNational Science Foundation Squid WEB ProxyMandrakesoft Mandrake LinuxRedhat Linux+112/3/200116/6/2026
squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.
ModificadaBaja (1.2)0.37%—ImmunixMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Linux+112/3/200116/6/2026
sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.
ModificadaBaja (1.2)0.30%—ImmunixMandrakesoft Mandrake LinuxRedhat Linux12/3/200116/6/2026
rdist 6.1.5 allows local users to overwrite arbitrary files via a symlink attack.
ModificadaBaja (1.2)0.30%—ImmunixMandrakesoft Mandrake LinuxRedhat Linux12/3/200116/6/2026
useradd program in shadow-utils program may allow local users to overwrite arbitrary files via a symlink attack.
ModificadaMedia (5)1.8%—PHPMandrakesoft Mandrake Linux12/3/200116/6/2026
PHP Apache module 4.0.4 and earlier allows remote attackers to bypass .htaccess access restrictions via a malformed HTTP request on an unrestricted page that causes PHP to use those access controls on the next page that is requested.
ModificadaBaja (1.2)0.34%—Caldera Openlinux DesktopImmunixCaldera Openlinux EdesktopCaldera Openlinux Eserver+312/3/200116/6/2026
inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations.
ModificadaMedia (5)45%—ProftpdConectiva LinuxDebian LinuxMandrakesoft Mandrake Linux12/3/200116/6/2026
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and possibly SIZE commands if the server has been improperly installed.
ModificadaBaja (1.2)0.30%—ImmunixMandrakesoft Mandrake LinuxRedhat Linux12/3/200116/6/2026
gpm 1.19.3 allows local users to overwrite arbitrary files via a symlink attack.
ModificadaBaja (1.2)0.30%—ExmhDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server12/3/200116/6/2026
exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file.
ModificadaBaja (1.2)0.30%—ImmunixDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+112/3/200116/6/2026
privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.