Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2723▼ 18 respecto a la semana anterior
Críticas / altas1271▼ 242 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

1569 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)17%💥 ExploitCygnus Network SecurityCygnus KerbnetMIT KerberosMIT Kerberos 5+116/5/200016/6/2026
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
ModificadaAlta (10)4.0%—Cygnus Network SecurityCygnus KerbnetMIT KerberosMIT Kerberos 5+116/5/200016/6/2026
Buffer overflow in krshd in Kerberos 5 allows remote attackers to gain root privileges.
ModificadaAlta (7.5)1.6%—GNU GlibcISC Bind3/5/200016/6/2026
The resolver in glibc 2.1.3 uses predictable IDs, which allows a local attacker to spoof DNS query results.
ModificadaBaja (2.1)0.36%—GNU Emacs18/4/200016/6/2026
Emacs 20 does not properly set permissions for a slave PTY device when starting a new subprocess, which allows local users to read or modify communications between Emacs and the subprocess.
ModificadaBaja (3.6)0.35%—GNU Emacs18/4/200016/6/2026
The make-temp-name Lisp function in Emacs 20 creates temporary files with predictable names, which allows attackers to conduct a symlink attack.
ModificadaMedia (4.6)0.34%—GNU Emacs18/4/200016/6/2026
read-passwd and other Lisp functions in Emacs 20 do not properly clear the history of recently typed keys, which allows an attacker to read unencrypted passwords.
ModificadaMedia (6.2)0.32%—GNU Make1/2/200016/6/2026
GNU make follows symlinks when it reads a Makefile from stdin, which allows other local users to execute commands.
ModificadaMedia (4.6)0.42%—Gnumeric5/8/199916/6/2026
The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.
ModificadaAlta (7.2)0.46%—GNU Fingerd21/7/199916/6/2026
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.
ModificadaMedia (4.6)0.86%💥 ExploitGNU Bash20/4/199916/6/2026
The prompt parsing in bash allows a local user to execute commands as another user by creating a directory with the name of the command to execute.
ModificadaMedia (5)1.5%—GNU Wget2/1/199916/6/2026
wget 1.5.3 follows symlinks to change permissions of the target file instead of the symlink itself.
ModificadaAlta (7.5)2.0%—GNU InetWashington University Wu-ftpdCaldera OpenlinuxFreebsd+710/12/199716/6/2026
FTP servers can allow an attacker to connect to arbitrary ports on machines other than the FTP client, aka FTP bounce.
ModificadaMedia (5)96%💥 ExploitCisco IOSGNU InetMicrosoft WinsockHp-ux+41/12/199716/6/2026
Land IP denial of service.
ModificadaMedia (5)2.6%—GNU InetHp-uxLinux Kernel1/11/199716/6/2026
Denial of service of inetd on Linux through SYN and RST packets.
ModificadaAlta (7.5)4.0%—GNU Fingerd1/7/199716/6/2026
The Perl fingerd program allows arbitrary command execution from remote users.
ModificadaMedia (5.4)0.81%—GNU InetSGI Irix29/5/199716/6/2026
Race condition in signal handling routine in ftpd, allowing read/write arbitrary files.
ModificadaBaja (0)68%—GNU Finger ServiceGNU FingerdMicrosoft Windows 2000Microsoft Windows NT1/3/199716/6/2026
A version of finger is running that exposes valid user information to any entity on the network.
ModificadaAlta (7.5)9.1%💥 ExploitGNU LibcCray UnicosCray Unicos MAXIBM AIX+213/2/199716/6/2026
Buffer overflow in NLS (Natural Language Service).
ModificadaMedia (4.6)0.40%—GNU BashTcsh13/9/199616/6/2026
(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.
Orbitaley — Vulnerabilidades