Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2871▲ 236 respecto a la semana anterior
Críticas / altas1338▼ 92 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
–

1808 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)85%💥 ExploitSambaSamba-tngApple MAC OS XCompaq Tru64+45/5/200316/6/2026
Desbordamiento de búfer en la función call_trans2open en trans2.c de Samba 2.2.x anteriores a 2.2.8a, 2.0.10 y versiones anteriores 2.0.x, y Samba-TNG anteriores a de 0.3.2, permite a atacantes remotos ejecutar código arbitrario.
ModificadaAlta (10)23%—SambaSamba-tngCompaq Tru64Hp-ux+35/5/200316/6/2026
Múltiples desbordamientos de búfer en Samba anteriores a 2.2.8a puede permitir a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio, descubierto por el equipo de Samba y una vulnerabilidad distinta de CAN-2003-0201.
ModificadaAlta (7.2)0.49%—XfsdumpSGI Irix5/5/200316/6/2026
xfsdq en xfsdump no crea los ficheros de información de cuota con seguridad, lo que permite a usuarios locales ganar privilegios de root.
ModificadaAlta (10)86%💥 ExploitSambaHP Cifs-9000 Server31/3/200316/6/2026
Buffer overflow in the SMB/CIFS packet fragment re-assembly code for SMB daemon (smbd) in Samba before 2.2.8, and Samba-TNG before 0.3.1, allows remote attackers to execute arbitrary code.
ModificadaAlta (7.5)15%—GNU GlibcMIT Kerberos 5OpenafsSGI Irix+925/3/200316/6/2026
Desbordamiento de entero en la función xdrmem_getbytes(), y posiblemente otras funciones, de librerias XDR (representación de datos externos) derivadas de SunRPC, incluyendo libnsl, libc y glibc permite a atacantes remotos ejecutar código arbitrario mediante ciertos valores enteros en campos de longitud.
ModificadaAlta (10)2.4%—Linksys Befsr11Linksys Befsr41Linksys Befsru3131/12/200216/6/2026
Linksys EtherFast Cable/DSL BEFSR11, BEFSR41 and BEFSRU31 with the firmware 1.42.7 upgrade installed opens TCP port 5678 for remote administration even when the "Block WAN" and "Remote Admin" options are disabled, which allows remote attackers to gain access.
ModificadaAlta (7.5)6.1%—Greg Roelofs Libpng26/12/200216/6/2026
Portable Network Graphics (PNG) library libpng 1.2.5 and earlier does not correctly calculate offsets, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a buffer overflow attack on the row buffers.
ModificadaAlta (10)52%💥 ExploitSambaSGI IrixHP Cifs-9000 Server11/12/200216/6/2026
Desbordamiento de búfer en Samba 2.2.2 a 2.2.6 permite a atacantes remotos causar una denegación de servicio y posíblemente ejecutar código arbitrario mediante una contraseña cifrada que causa un desbordamiento durante el descifrado en la cual una cadena de página de códigos DOS es convertida a una cadena unicode UCS2…
ModificadaMedia (5)2.0%—Linksys Befn2ps4Linksys Befsr11Linksys Befsr41Linksys Befsr81+520/11/200216/6/2026
Buffer overflow in the Web management interface in Linksys BEFW11S4 wireless access point router 2 and BEFSR11, BEFSR41, and BEFSRU31 EtherFast Cable/DSL routers with firmware before 1.43.3 with remote management enabled allows remote attackers to cause a denial of service (router crash) via a long password.
ModificadaMedia (5)7.1%💥 ExploitLinksys Befsr4112/11/200216/6/2026
El servidor de adminsitración web remota del router Linksys BEFSR41 EtherFast Cable/DSL con firmware anterior a 1.42.7 permite a atacantes remotos causar una denegación de servicio (caída) mediante una petición HTTP a Gozilla.cgi sin argumentos.
ModificadaAlta (7.2)0.57%—HP JFSHp-ux16/10/200216/6/2026
JFS (JFS3.1 and OnlineJFS) in HP-UX 10.20, 11.00, and 11.04 does not properly implement the sticky bit functionality, which could allow attackers to bypass intended restrictions on filesystems.
ModificadaAlta (7.2)2.4%💥 ExploitHP Cifs-9000 Server4/10/200216/6/2026
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, allows local users to gain root privileges via long (1) -U, (2) -D, (3) -P, (4) -S, (5) -N, or (6) -u parameters.
ModificadaMedia (5)2.1%—Greg Roelofs Libpng12/8/200216/6/2026
Desbordamiento de búfer en la lectura progresiva con libpng 1.2.4 y 1.0.14 permite que atacantes remotos provoquen una denegación de servicio por medio de un stream de datos PNG que tiene más datos IDAT de los que se indican en el chunk IHDR.
ModificadaAlta (7.5)3.0%—Greg Roelofs LibpngGreg Roelofs Libpng312/8/200216/6/2026
Buffer overflow in libpng 1.0.12-3.woody.2 and libpng3 1.2.1-1.1.woody.2 on Debian GNU/Linux 3.0, and other operating systems, may allow attackers to cause a denial of service and possibly execute arbitrary code, a different vulnerability than CVE-2002-0728.
ModificadaAlta (7.5)4.1%—Matt Blaze CFS25/6/200216/6/2026
Buffer overflows in CFS daemon (cfsd) before 1.3.3-8.1, and 1.4x before 1.4.1-5, allow remote attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaAlta (7.5)3.0%—Foundstone Fscan18/6/200216/6/2026
Format string vulnerability in Foundstone FScan 1.12 with banner grabbing enabled allows remote attackers to execute arbitrary code on the scanning system via format string specifiers in the server banner.
ModificadaMedia (6.4)1.7%—Linksys Befn2ps4Linksys Befsr41Linksys Befsr8125/3/20029/10/2026
Los routers Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81, y posiblemente otros productos, permiten a atacantes remotos obterner información sensible y provocar una denegación de servicio mediante una consulta SNMP con la cadena de comunidad por defecto "public," lo que provoca que el router cambie su configuración…
ModificadaAlta (7.5)3.5%—Celtech Software Expressfs28/11/200116/6/2026
Buffer overflow in Celtech ExpressFS FTP server 2.x allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long USER command.
ModificadaAlta (10)2.5%—HP Cifs-9000 Server31/8/200116/6/2026
HP CIFS/9000 Server (SAMBA) A.01.07 and earlier with the "unix password sync" option enabled calls the passwd program without specifying the username of the user making the request, which could cause the server to change the password of a different user.
ModificadaMedia (5)1.8%—Linksys Befsr4110/8/200116/6/2026
LinkSys EtherFast BEFSR41 Cable/DSL routers running firmware before 1.39.3 Beta allows a remote attacker to view administration and user passwords by connecting to the router and viewing the HTML source for (1) index.htm and (2) Password.htm.
ModificadaAlta (7.2)1.1%💥 ExploitFtpfs27/6/200116/6/2026
Buffer overflow in FTPFS allows local users to gain root privileges via a long user name.
ModificadaAlta (10)12%💥 ExploitSambaHP Cifs-9000 Server23/6/200116/6/2026
Directory traversal vulnerability in the %m macro in the smb.conf configuration file in Samba before 2.2.0a allows remote attackers to overwrite certain files via a .. in a NETBIOS name, which is used as the name for a .log file.
ModificadaAlta (7.2)1.2%💥 ExploitHans Reiser ReiserfsSuse Linux26/3/200116/6/2026
Buffer overflow in ReiserFS 3.5.28 in SuSE Linux allows local users to cause a denial of service and possibly execute arbitrary commands by via a long directory name.
ModificadaMedia (5)1.3%—Xlink Technology Omni-nfs X Enterprise6/10/199916/6/2026
NFS daemon (nfsd.exe) for Omni-NFS/X 6.1 allows remote attackers to cause a denial of service (resource exhaustion) via certain packets, possibly with the Urgent (URG) flag set, to port 111.
ModificadaAlta (7.5)1.9%—Tenfour TFS Gateway Smtp2/9/199916/6/2026
A buffer overflow in TenFour TFS Gateway SMTP mail server 3.2 allows an attacker to crash the mail server and possibly execute arbitrary code by offering more than 128 bytes in a MAIL FROM string.