Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

138 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.45%—Xfree86 Project X11r622/9/200116/6/2026
Buffer overflow in fbglyph.c in XFree86 before 4.2.0, related to glyph clipping for large origins, allows attackers to cause a denial of service and possibly gain privileges via a large number of characters, possibly through the web page search form of KDE Konqueror or from an xterm command with a long title.
ModificadaAlta (7.2)0.44%—Xfree86 Project X11r617/7/200116/6/2026
xman allows local users to gain privileges by modifying the MANPATH to point to a man page whose filename contains shell metacharacters.
ModificadaAlta (7.2)0.77%💥 ExploitXfree86 Project X11r611/7/200116/6/2026
Buffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable.
ModificadaAlta (7.5)2.8%💥 ExploitXfree86 Project X11r64/7/200116/6/2026
XDM in XFree86 3.3 and 3.3.3 generates easily guessable cookies using gettimeofday() when compiled with the HasXdmXauth option, which allows remote attackers to gain unauthorized access to the X display via a brute force attack.
ModificadaMedia (5)3.3%💥 ExploitGnome GDMOpen Group XXfree86 Project X11r619/6/200016/6/2026
libICE in XFree86 allows remote attackers to cause a denial of service by specifying a large value which is not properly checked by the SKIP_STRING macro.
ModificadaMedia (5)1.7%—Open Group XXfree86 Project X11r619/6/200016/6/2026
libX11 X library allows remote attackers to cause a denial of service via a resource mask of 0, which causes libX11 to go into an infinite loop.
ModificadaMedia (5)2.5%💥 ExploitMichael Jennings EtermPuttyRxvtXfree86 Project X11r61/6/200016/6/2026
xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force the window to be resized.
ModificadaMedia (5)3.0%💥 ExploitXfree86 Project X11r618/5/200016/6/2026
XFree86 3.3.x and 4.0 allows a user to cause a denial of service via a negative counter value in a malformed TCP packet that is sent to port 6000.
ModificadaAlta (7.2)0.54%—Xfree86 Project X11r616/4/200016/6/2026
Buffer overflow in XFree86 3.3.x allows local users to execute arbitrary commands via a long -xkbmap parameter.
ModificadaMedia (4.6)0.71%💥 ExploitXfree86 Project X11r6NetbsdRedhat LinuxSlackware Linux+121/3/199916/6/2026
XFree86 startx command is vulnerable to a symlink attack, allowing local users to create files in restricted directories, possibly allowing them to gain privileges or cause a denial of service.
ModificadaMedia (6.2)0.33%—X.org X1119/9/199716/6/2026
Race condition in xterm allows local users to modify arbitrary files via the logging option.
ModificadaAlta (10)21%💥 ExploitX.org X111/7/199716/6/2026
An X server's access control is disabled (e.g. through an "xhost +" command) and allows anyone to connect to the server.
ModificadaAlta (10)4.3%—Xfree86 Project X11r6SGI IrixSUN SolarisSunos1/11/199516/6/2026
Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.
Orbitaley — Vulnerabilidades