Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

1569 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)14%💥 ExploitGNU Privacy Guard14/8/200116/6/2026
Format string vulnerability in Gnu Privacy Guard (aka GnuPG or gpg) 1.05 and earlier can allow an attacker to gain privileges via format strings in the original filename that is stored in an encrypted file.
ModificadaBaja (1.2)0.29%—GNU EmacsXemacs7/8/200116/6/2026
rcs2log, as used in Emacs 20.4, xemacs 21.1.10 and other versions before 21.4, and possibly other packages, allows local users to modify files of other users via a symlink attack on a temporary file.
ModificadaAlta (7.5)11%💥 ExploitGNU GroffJgroff26/7/200116/6/2026
Format string vulnerability in pic utility in groff 1.16.1 and other versions, and jgroff before 1.15, allows remote attackers to bypass the -S option and execute arbitrary commands via format string specifiers in the plot command.
ModificadaBaja (2.1)1.1%—GNU TAR12/7/200116/6/2026
Directory traversal vulnerability in GNU tar 1.13.19 and earlier allows local users to overwrite arbitrary files during archive extraction via a tar file whose filenames contain a .. (dot dot).
ModificadaMedia (4.6)0.33%—GNU Mailman3/5/200116/6/2026
Vulnerability in Mailman 2.0.1 and earlier allows list administrators to obtain user passwords.
ModificadaAlta (10)5.5%—Andynorman Gnuserv3/5/200116/6/2026
gnuserv before 3.12, as shipped with XEmacs, does not properly check the specified length of an X Windows MIT-MAGIC-COOKIE cookie, which allows remote attackers to execute arbitrary commands via a buffer overflow, or brute force authentication by using a short cookie length.
ModificadaMedia (5)2.0%—GNU Privacy Guard12/2/200116/6/2026
gpg (aka GnuPG) 1.0.4 and other versions imports both public and private keys from public key servers without notifying the user about the private keys, which could allow an attacker to break the web of trust.
ModificadaBaja (2.1)0.40%—GNU Privacy Guard12/2/200116/6/2026
gpg (aka GnuPG) 1.0.4 and other versions does not properly verify detached signatures, which allows attackers to modify the contents of a file without detection.
ModificadaMedia (4.6)0.39%—GNU ED9/1/200116/6/2026
GNU ed before 0.2-18.1 allows local users to overwrite the files of other users via a symlink attack.
ModificadaBaja (1.2)0.30%—GNU Glibc19/12/200023/9/2026
glibc2 no limpia correctamente las variables de entorno LD_DEBUG_OUTPUT y LD_DEBUG cuando un programa es ejecutado desde un programa setuid, lo que podría permitir a usuarios locales sobrescribir archivos mediante un ataque de enlace simbólico.
ModificadaAlta (7.5)3.0%—GNU Privacy Guard19/12/200023/9/2026
GnuPG (gpg) 1.0.3 no verifica correctamente todas las firmas de un archivo que contiene múltiples documentos, lo que permite a un atacante modificar el contenido de todos los documentos excepto el primero sin detección.
ModificadaAlta (10)2.5%—GNU Cfengine19/12/200023/9/2026
Vulnerabilidad de formato de cadena en el demonio cfd de GNU CFEngine anterior a 1.6.0a11 permite a los atacantes ejecutar comandos arbitrarios mediante caracteres de formato en el comando CAUTH.
ModificadaAlta (10)2.3%—GNU Groff19/12/200023/9/2026
GNU Groff usa el directorio de trabajo actual para encontrar un archivo de descripción de dispositivo, lo que permite a un usuario local obtener privilegios adicionales al incluir una directiva postpro maliciosa en el archivo de descripción, que se ejecuta cuando otro usuario ejecuta groff.
ModificadaAlta (7.2)0.68%—GNU Mailman14/11/200016/6/2026
Mailman 1.1 allows list administrators to execute arbitrary commands via shell metacharacters in the %(listname) macro expansion.
ModificadaAlta (7.2)1.2%💥 ExploitGNU Glibc14/11/200016/6/2026
The unsetenv function in glibc 2.1.1 does not properly unset an environmental variable if the variable is provided twice to a program, which could allow local users to execute arbitrary commands in setuid programs by specifying their own duplicate environmental variables such as LD_PRELOAD or LD_LIBRARY_PATH.
ModificadaAlta (7.5)1.4%—GNU G++GNU GCC1/11/200016/6/2026
The -ftrapv compiler option in gcc and g++ 3.3.3 and earlier does not handle all types of integer overflows, which may leave applications vulnerable to vulnerabilities related to overflows.
ModificadaMedia (4.6)0.34%—GNU Userv20/10/200016/6/2026
GNU userv 1.0.0 and earlier does not properly perform file descriptor swapping, which can corrupt the USERV_GROUPS and USERV_GIDS environmental variables and allow local users to bypass some access restrictions.
ModificadaMedia (4.6)0.39%—GNU MailmanConectiva LinuxRedhat Linux20/10/200016/6/2026
The wrapper program in mailman 2.0beta3 and 2.0beta4 does not properly cleanse untrusted format strings, which allows local users to gain privileges.
ModificadaMedia (5)2.3%—Cygnus Network SecurityCygnus KerbnetMIT KerberosMIT Kerberos 59/6/200016/6/2026
Kerberos 4 KDC program does not properly check for null termination of AUTH_MSG_KDC_REQUEST requests, which allows remote attackers to cause a denial of service via a malformed request.
ModificadaMedia (5)2.9%—Cygnus Network Security Project Cygnus Network SecurityKerbnet Project KerbnetMIT KerberosMIT Kerberos 59/6/200016/6/2026
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the lastrealm variable in the set_tgtkey function.
ModificadaMedia (5)2.4%—Cygnus Network SecurityCygnus KerbnetMIT KerberosMIT Kerberos 59/6/200016/6/2026
Kerberos 4 KDC program improperly frees memory twice (aka "double-free"), which allows remote attackers to cause a denial of service.
ModificadaMedia (5)2.9%—Cygnus Network Security Project Cygnus Network SecurityKerbnet Project KerbnetMIT KerberosMIT Kerberos 59/6/200016/6/2026
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the localrealm variable in the process_v4 function.
ModificadaMedia (5)2.9%—Cygnus Network Security Project Cygnus Network SecurityKerbnet Project KerbnetMIT KerberosMIT Kerberos 59/6/200016/6/2026
Buffer overflow in Kerberos 4 KDC program allows remote attackers to cause a denial of service via the e_msg variable in the kerb_err_reply function.
ModificadaAlta (7.2)0.44%—Cygnus Network SecurityCygnus KerbnetMIT KerberosMIT Kerberos 5+116/5/200016/6/2026
Buffer overflow in ksu in Kerberos 5 allows local users to gain root privileges.
ModificadaAlta (10)4.0%—Cygnus Network SecurityCygnus KerbnetMIT KerberosMIT Kerberos 5+116/5/200016/6/2026
Buffer overflow in krb425_conv_principal function in Kerberos 5 allows remote attackers to gain root privileges.