Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2680▼ 660 respecto a la semana anterior
Críticas / altas1277▼ 279 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)228▼ 274 respecto a la semana anterior
–

168 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.6%—Plumtree Corporate Portal16/5/200216/6/2026
Cross-site scripting (CSS) vulnerability in error.asp for Plumtree Corporate Portal 3.5 through 4.5 allows remote attackers to execute arbitrary script on other clients via the "Description" parameter.
ModificadaMedia (6.4)1.6%—ACD Incorporated Cwpapi16/5/200216/6/2026
GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root.
ModificadaCrítica (9.8)15%💥 ExploitImmunixMandrakesoft Mandrake Single Network FirewallOpenbsd OpensshOpenpkg+715/3/200216/6/2026
Off-by-one error in the channel code of OpenSSH 2.0 through 3.0.2 allows local users or remote malicious servers to gain privileges.
ModificadaAlta (7.5)7.8%—Apache Http ServerMandrakesoft Mandrake Single Network FirewallMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server28/11/200116/6/2026
The default installation of Apache before 1.3.19 on Mandrake Linux 7.1 through 8.0 and Linux Corporate Server 1.0.1 allows remote attackers to list the directory index of arbitrary web directories.
ModificadaBaja (2.1)0.81%💥 ExploitImmunixUniversity OF Washington PineEngardelinux Secure LinuxMandrakesoft Mandrake Linux+218/10/200116/6/2026
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to overwrite arbitrary files via a symlink attack.
ModificadaAlta (7.5)1.4%—PGP Corporate DesktopPGP E-business ServerPGP FreewarePGP Personal Security+14/9/200116/6/2026
PGP Corporate Desktop before 7.1, Personal Security before 7.0.3, Freeware before 7.0.3, and E-Business Server before 7.1 does not properly display when invalid userID's are used to sign a message, which could allow an attacker to make the user believe that the document has been signed by a trusted third party by…
ModificadaAlta (7.5)2.0%—Caldera Openlinux ServerImmunixMandrakesoft Mandrake Single Network FirewallSquid WEB Proxy+418/7/200116/6/2026
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
ModificadaMedia (5)4.1%—Mandrakesoft Mandrake Single Network FirewallOpenldapDebian LinuxMandrakesoft Mandrake Linux+216/7/200116/6/2026
slapd in OpenLDAP 1.x before 1.2.12, and 2.x before 2.0.8, allows remote attackers to cause a denial of service (crash) via an invalid Basic Encoding Rules (BER) length field.
ModificadaAlta (7.5)2.4%—LicqConectiva LinuxFreebsdMandrakesoft Mandrake Linux+22/7/200116/6/2026
licq before 1.0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
ModificadaAlta (7.5)2.7%—Debian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Linux27/6/200116/6/2026
Buffer overflow in (1) wrapping and (2) unwrapping functions of slrn news reader before 0.9.7.0 allows remote attackers to execute arbitrary commands via a long message header.
ModificadaAlta (7.2)0.86%💥 ExploitDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server3/5/200116/6/2026
Buffer overflow in sudo earlier than 1.6.3p6 allows local users to gain root privileges.
ModificadaBaja (2.1)0.36%—Conectiva LinuxCaldera Openlinux EdesktopMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+126/3/200116/6/2026
kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges.
ModificadaBaja (2.1)0.86%💥 ExploitMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat LinuxTrustix Secure Linux+126/3/200116/6/2026
When using the LD_PRELOAD environmental variable in SUID or SGID applications, glibc does not verify that preloaded libraries in /etc/ld.so.cache are also SUID/SGID, which could allow a local user to overwrite arbitrary files by loading a library from /lib or /usr/lib.
ModificadaBaja (1.2)0.30%—ExmhDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server12/3/200116/6/2026
exmh 2.2 and earlier allows local users to overwrite arbitrary files via a symlink attack on the exmhErrorMsg temporary file.
ModificadaBaja (1.2)0.30%—ImmunixDebian LinuxMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+112/3/200116/6/2026
privatepw program in wu-ftpd before 2.6.1-6 allows local users to overwrite arbitrary files via a symlink attack.
ModificadaBaja (1.2)0.37%—ImmunixMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Linux+112/3/200116/6/2026
sdiff 2.7 in the diffutils package allows local users to overwrite files via a symlink attack.
ModificadaMedia (5)1.9%—Itserv Incorporated Ridewaypn9/1/200116/6/2026
The telnet proxy in RideWay PN proxy server allows remote attackers to cause a denial of service via a flood of connections that contain malformed requests.
ModificadaMedia (5)1.6%—Csandt Corporatetime FOR THE WEB11/12/200016/6/2026
CS&T CorporateTime for the Web returns different error messages for invalid usernames and invalid passwords, which allows remote attackers to determine valid usernames on the server.
Orbitaley — Vulnerabilidades