Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2831▲ 194 respecto a la semana anterior
Críticas / altas1317▼ 115 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)234▲ 220 respecto a la semana anterior
–

1550 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)1.7%—Driverse17/12/200516/6/2026
Multiple unspecified vulnerabilities in Driverse before 0.56b have unknown impact and attack vectors, related to (1) a "ptrace exploit" and (2) "some other potential security problems."
ModificadaAlta (7.5)8.7%💥 ExploitGpsdrive7/11/200516/6/2026
Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (direction) field.
ModificadaMedia (5)1.7%—Compuware Driverstudio22/9/200516/6/2026
Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to cause a denial of service (reboot) via a UDP packet sent directly to port 9110.
ModificadaAlta (7.5)1.8%—Compuware Driverstudio22/9/200516/6/2026
Compuware DriverStudio Remote Control service (DSRsvc.exe) 2.7 and 3.0 beta 2 allows remote attackers to bypass authentication via a null session.
ModificadaAlta (7.5)64%💥 ExploitATI Catalyst DriverMicrosoft .net FrameworkMicrosoft OfficeMicrosoft Project+219/8/200516/6/2026
Microsoft Internet Explorer 5.01, 5.5, and 6 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a web page with embedded CLSIDs that reference certain COM objects that are not intended for use within Internet Explorer, as originally demonstrated using the…
ModificadaMedia (5)1.3%—Codemasters Toca Race Driver26/7/200516/6/2026
Vulenrabilidad de formateo de cadenas en Race Driver 1.20 y anteriores permite que atacantes remotos causen una denegación de servicio (caída de la aplicación) mediante especificadores de formato de cadenas en un mensaje "nickname" o "chat".
ModificadaMedia (5)1.4%—Codemasters Toca Race Driver26/7/200516/6/2026
Desbordamiento de búfer en Race Driver 1.20 y anteriores permite que atacantes remotos causen una denegación de servicio (caída de la aplicación) mediante un mensaje largo "nickname" o "chat".
ModificadaMedia (5)1.7%—Compuware Softice Driverstudio29/5/200516/6/2026
The DbgMsg.sys driver in Compuware SoftICE DriverStudio 3.1 and 3.2 allows remote attackers to cause a denial of service (application crash) via an invalid Debug Message pointer.
ModificadaAlta (7.2)0.43%—Mandrakesoft Mandrake Multi Network FirewallSpeedtouch USB DriverGentoo LinuxMandrakesoft Mandrake Linux+123/12/200416/6/2026
Vulnerabilidad de cadena de formato en Speedtouch USB driver anteriores a 1.3.1 permite a usuarios locales ejecutar código de su elección mediante modem_run pppoa2, o pppoa3
ModificadaBaja (2.1)0.22%—Lexar Jumpdrive Secure13/9/200416/6/2026
Lexar Safe Guard for JumpDrive Secure 1.0 stores the password insecurely in memory using XOR encryption, which allows local users to read the password directly from the device and access the password protected part of the drive.
ModificadaBaja (2.1)0.43%—Pedestal Software Integrity Protection Driver17/8/200416/6/2026
The ZwOpenSection function in Integrity Protection Driver (IPD) 1.4 and earlier allows local users to cause a denial of service (crash) via an invalid pointer in the "oa" argument.
ModificadaAlta (7.5)4.5%—Wildtangent Webdriver29/1/200416/6/2026
Buffer overflow in the (1) WTHoster and (2) WebDriver modules in WildTangent Web Driver 4.0 allows remote attackers to execute arbitrary code via a long filename.
ModificadaBaja (2.1)0.33%—Pedestal Software Integrity Protection Driver31/12/200316/6/2026
NtCreateSymbolicLinkObject in ntdll.dll in Integrity Protection Driver (IPD) 1.2 and 1.3 allows local users to create and overwrite arbitrary files via a symlink attack on \winnt\system32\drivers using the subst command.
ModificadaCrítica (9.8)1.6%—Pedestalsoftware Integrity Protection Driver31/12/200316/6/2026
Pedestal Software Integrity Protection Driver (IPD) 1.3 and earlier allows privileged attackers, such as rootkits, to bypass file access restrictions to the Windows kernel by using the NtCreateSymbolicLinkObject function to create a symbolic link to (1) \Device\PhysicalMemory or (2) to a drive letter using the subst…
ModificadaAlta (10)73%💥 ExploitSendmailHP Alphaserver SCGentoo LinuxHp-ux+57/3/200316/6/2026
Desbordamiento de búfer en Sendmail 5.79 a la 8.12.7 que permite a atacantes remotos la ejecución arbitraria de código mediante ciertos campos de dirección formateados, relativos a comentarios de cabecera de emisor y receptor, procesados por la función crackaddr del fichero headers.c.
ModificadaBaja (2.1)0.43%—Pedestal Software Integrity Protection Driver31/12/200216/6/2026
restrictEnabled in Integrity Protection Driver (IPD) 1.2 delays driver installation for 20 minutes, which allows local users to insert malicious code by setting system clock to an earlier time.
ModificadaBaja (2.1)0.35%—Pedestal Software Integrity Protection Driver31/12/200216/6/2026
Integrity Protection Driver (IPD) 1.2 and earlier blocks access to \Device\PhysicalMemory by its name, which could allow local privileged processes to overwrite kernel memory by accessing the device through a symlink.
ModificadaAlta (7.5)2.9%💥 ExploitSUN PCI II Driver4/10/200216/6/2026
SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing the random byte challenge, which is used as the key for encrypted communications.
ModificadaMedia (4.6)0.38%—Cisco Iscsi Driver12/8/200216/6/2026
Linux-iSCSI iSCSI implementation installs the iscsi.conf file with world-readable permissions on some operating systems, including Red Hat Linux Limbo Beta #1, which could allow local users to gain privileges by reading the cleartext CHAP password.
ModificadaMedia (6.2)0.44%—HP Photosmart Print Driver12/8/200216/6/2026
HP Photosmart printer driver for Mac OS X installs the hp_imaging_connectivity program and the hp_imaging_connectivity.app directory with world-writable permissions, which allows local users to gain privileges of other Photosmart users by replacing hp_imaging_connectivity with a Trojan horse.
ModificadaBaja (2.1)0.34%—Intel PRO Wireless 2011b LAN USB Device Driver16/5/200216/6/2026
Compaq Intel PRO/Wireless 2011B LAN USB Device Driver en sus versiones de la 1.5.16.0 a la 1.5.18.0 almacena la clave 128-bit WEP (Wired Equivalent Privacy) en texto plano en una entrada del registro con permisos débiles, lo que permite a usuarios locales descifrar el tráfico en la red leyendo la clave WEP del…
ModificadaMedia (4.6)0.35%—Iomega ZIP 100 MB Drive21/12/200125/9/2026
La unidad ZIP para discos Iomego ZIP-100 permite a atacantes con acceso físico a la unidad permite evitar la protección con contraseña insertando un disco conocido con una contraseña conocida, esperarando a que la unidad se pare y reemplazando manualmente el disco conocido por el disco objetivo.
ModificadaMedia (6.2)1.0%💥 ExploitSamsung Ml-85g GDI Printer DriverSamsung Ml-85p Printer Driver17/7/200116/6/2026
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files.
ModificadaAlta (10)3.0%—I-drive Filo7/6/200016/6/2026
Buffer overflow in the HTTP proxy server for the i-drive Filo software allows remote attackers to execute arbitrary commands via a long HTTP GET request.
ModificadaMedia (4)32%💥 PoCApple MAC OS XApple MacosCisco IOSHp-ux+101/8/199716/6/2026
Información ICMP como (1) máscara de red y (2) marca de tiempo está permitida desde hosts arbitrarios.