Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.45% | — | Xfree86 Project X11r6 | 22/9/2001 | 16/6/2026 | Buffer overflow in fbglyph.c in XFree86 before 4.2.0, related to glyph clipping for large origins, allows attackers to cause a denial of service and possibly gain privileges via a large number of characters, possibly through the web page search form of KDE Konqueror or from an xterm command with a long title. | |
| Modificada | Alta (7.2) | 0.44% | — | Xfree86 Project X11r6 | 17/7/2001 | 16/6/2026 | xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters. | |
| Modificada | Alta (7.2) | 0.77% | 💥 Exploit | Xfree86 Project X11r6 | 11/7/2001 | 16/6/2026 | Buffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable. | |
| Modificada | Alta (7.5) | 2.8% | 💥 Exploit | Xfree86 Project X11r6 | 4/7/2001 | 16/6/2026 | XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Gnome GDMOpen Group XXfree86 Project X11r6 | 19/6/2000 | 16/6/2026 | libICE in XFree86 allows remote attackers to cause a denial of service by specifying a large value which is not properly checked by the SKIP_STRING macro. | |
| Modificada | Media (5) | 1.7% | — | Open Group XXfree86 Project X11r6 | 19/6/2000 | 16/6/2026 | libX11 X library allows remote attackers to cause a denial of service via a resource mask of 0, which causes libX11 to go into an infinite loop. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Michael Jennings EtermPuttyRxvtXfree86 Project X11r6 | 1/6/2000 | 16/6/2026 | xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Xfree86 Project X11r6 | 18/5/2000 | 16/6/2026 | XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000. | |
| Modificada | Alta (7.2) | 0.54% | — | Xfree86 Project X11r6 | 16/4/2000 | 16/6/2026 | Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter. | |
| Modificada | Media (4.6) | 0.71% | 💥 Exploit | Xfree86 Project X11r6NetbsdRedhat LinuxSlackware Linux+1 | 21/3/1999 | 16/6/2026 | XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service. | |
| Modificada | Media (6.2) | 0.33% | — | X.org X11 | 19/9/1997 | 16/6/2026 | Race condition in xterm allows local users to modify arbitrary files via the logging option. | |
| Modificada | Alta (10) | 21% | 💥 Exploit | X.org X11 | 1/7/1997 | 16/6/2026 | An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server. | |
| Modificada | Alta (10) | 4.3% | — | Xfree86 Project X11r6SGI IrixSUN SolarisSunos | 1/11/1995 | 16/6/2026 | Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm. |