Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3232▲ 666 respecto a la semana anterior
Críticas / altas1516▲ 123 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
–

2011 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.8%—Wietse Venema PostfixRedhat Enterprise LinuxRedhat Enterprise Linux DesktopSuse Linux2/5/200516/6/2026
Postfix 2.1.3, when /proc/net/if_inet6 is not available and permit_mx_backup is enabled in smtpd_recipient_restrictions, allows remote attackers to bypass e-mail restrictions and perform mail relaying by sending mail to an IPv6 hostname.
ModificadaAlta (7.5)3.0%—Redhat Enterprise LinuxRedhat Enterprise Linux Desktop2/5/200516/6/2026
Heap-based buffer overflow in less in Red Hat Enterprise Linux 3 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted file, as demonstrated using the UTF-8 locale.
ModificadaBaja (2.1)0.41%—Conectiva LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+12/5/200516/6/2026
Unknown vulnerability in Linux kernel 2.4.x, 2.5.x, and 2.6.x allows NFS clients to cause a denial of service via O_DIRECT.
ModificadaAlta (7.5)3.0%—Ascii PtexCstex CstetexEasy Software Products CupsGnome Gpdf+1827/4/200516/6/2026
El parche para corregir las vulnerabilidades de desbordamiento de entero en Xpdf 2.0 y 3.0 (CAN-2004-0888) es incompleto para arquitecturas de 64 bits en ciertas distribuciones de Linux como Red Hat, lo que podría dejar a los usuarios de Xpdf expuestos a las vulnerabilidades originales.
ModificadaBaja (2.1)0.51%—Avaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+1114/4/200516/6/2026
El soporte de ELF de 64 bits en los kernel de Linux 2.6 anteriores a 2.6.10 en arquitecturas de 64 bits no verifica adecuadamente solapamientos en asignaciones de memoria VMA (virtual memory address), lo que permite a usuarios locales causar una denegación de servicio (caída del sistema) o ejecutar código de su…
ModificadaBaja (2.1)0.43%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux Desktop14/4/200516/6/2026
Vulnerabilidad desconocida en los kernel de Linux anteriores a 2.4.23 sobre las arquitecturas AMD64 Y EMT64, asociada con "establecimiento de límites TSS", permite a usuarios locales causar una denegación de servicio (caída) y posiblemente ejecutar código de su elección.
ModificadaBaja (2.1)0.36%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopSuse Linux14/4/200516/6/2026
Vulnerabilidad desconocida en el código de filtrado de llamada al sistema en el subsistema de auditoría de Red Hat Enterprise Linux 3 permite a usuarios locales causar una denegación de servicio (caída del sistema) mediante vectores de ataque desconocidos.
ModificadaMedia (6.2)2.9%💥 ExploitAvaya Mn100Avaya Network RoutingAvaya Converged Communications ServerAvaya S8710+1614/4/200516/6/2026
Condición de carrera en las llamadas de funciones (1) load_elf_library y (2) binfmt_aout de uselib de los kernel de Linux 2.4 a 2.429-rc2 y 2.6 a 2.6.10 permite a usuarios locales ejecutar código de su elección manipulando el descriptor WMA.
ModificadaAlta (7.2)0.85%💥 ExploitConectiva LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+427/3/200516/6/2026
The bluez_sock_create function in the Bluetooth stack for Linux kernel 2.4.6 through 2.4.30-rc1 and 2.6 through 2.6.11.5 allows local users to gain privileges via (1) socket or (2) socketpair call with a negative protocol value.
ModificadaMedia (5)2.4%—Ipsec-toolsKame RacoonSGI PropackAltlinux ALT Linux+314/3/200516/6/2026
The KAME racoon daemon in ipsec-tools before 0.5 allows remote attackers to cause a denial of service (crash) via malformed ISAKMP packets.
ModificadaMedia (5)3.5%—ROB Flynn GaimMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Enterprise Linux+114/3/200516/6/2026
The HTML parsing functions in Gaim before 1.1.3 allow remote attackers to cause a denial of service (application crash) via malformed HTML that causes "an invalid memory access," a different vulnerability than CVE-2005-0208.
ModificadaMedia (5)5.3%—ROB Flynn GaimMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Enterprise Linux+114/3/200516/6/2026
Gaim before 1.1.3 allows remote attackers to cause a denial of service (infinite loop) via malformed SNAC packets from (1) AIM or (2) ICQ.
ModificadaBaja (2.1)2.1%💥 ExploitConectiva LinuxLinux KernelRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+19/3/200516/6/2026
Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.
ModificadaAlta (7.5)6.5%—Ethereal Group EtherealConectiva LinuxAltlinux ALT LinuxRedhat Enterprise Linux+28/3/200516/6/2026
Multiple buffer overflows in the dissect_a11_radius function in the CDMA A11 (3G-A11) dissector (packet-3g-a11.c) for Ethereal 0.10.9 and earlier allow remote attackers to execute arbitrary code via RADIUS authentication packets with large length values.
ModificadaMedia (5.6)0.51%—FreebsdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+45/3/200516/6/2026
Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack…
ModificadaAlta (7.5)4.5%—LesstifSGI PropackX.org X11r6Xfree86 Project X11r6+72/3/200516/6/2026
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
ModificadaBaja (2.1)0.39%—Redhat Enterprise LinuxRedhat Enterprise Linux Desktop19/2/200516/6/2026
Unknown vulnerability in the Red Hat Enterprise Linux 4 kernel 4GB/4GB split patch, when running on x86 with the hugemem kernel, allows local users to cause a denial of service (crash).
ModificadaBaja (2.1)0.39%—GNU GlibcRedhat Enterprise LinuxRedhat Enterprise Linux Desktop9/2/200516/6/2026
The catchsegv script in glibc 2.3.2 and earlier allows local users to overwrite files via a symlink attack on temporary files.
ModificadaMedia (6.8)2.4%—OpenpkgOracle MysqlRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+39/2/200516/6/2026
Unknown vulnerability in MySQL 3.23.58 and earlier, when a local user has privileges for a database whose name includes a "_" (underscore), grants privileges to other databases that have similar names, which can allow the user to conduct unauthorized activities.
ModificadaBaja (2.1)0.45%—PostgresqlMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Enterprise Linux+29/2/200516/6/2026
The make_oidjoins_check script in PostgreSQL 7.4.5 and earlier allows local users to overwrite files via a symlink attack on temporary files.
ModificadaBaja (2.1)1.3%💥 ExploitLarry Wall PerlSGI PropackIBM AIXRedhat Enterprise Linux+57/2/200516/6/2026
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
ModificadaAlta (10)9.7%—MozillaMozilla ThunderbirdConectiva LinuxRedhat Enterprise Linux+527/1/200516/6/2026
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to execute arbitrary code via malformed VCard attachments that are not properly handled when previewing a message.
ModificadaAlta (10)14%—SambaConectiva LinuxRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+327/1/200516/6/2026
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a small "maximum data bytes" value.
ModificadaAlta (10)9.5%—Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+1227/1/200516/6/2026
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
ModificadaMedia (5)4.9%—SambaSGI SambaConectiva LinuxGentoo Linux+427/1/200516/6/2026
The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.