Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

247 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.6%—KDE KonquerorKDE2/5/200516/6/2026
The International Domain Name (IDN) support in Konqueror 3.2.1 on KDE 3.2.1 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.
ModificadaMedia (4.6)0.36%—Bernd Wuebben KpppKDE2/5/200516/6/2026
KPPP 2.1.2 in KDE 3.1.5 and earlier, when setuid root without certain wrappers, does not properly close a privileged file descriptor for a domain socket, which allows local users to read and write to /etc/hosts and /etc/resolv.conf and gain control over DNS name resolution by opening a number of file descriptors…
ModificadaBaja (2.1)0.40%—KDE DcopserverKDE Desktop Communication Protocol Daemon2/5/200516/6/2026
Desktop Communication Protocol (DCOP) daemon, aka dcopserver, in KDE before 3.4 allows local users to cause a denial of service (dcopserver consumption) by "stalling the DCOP authentication process."
ModificadaAlta (7.5)3.0%—Ascii PtexCstex CstetexEasy Software Products CupsGnome Gpdf+1827/4/200516/6/2026
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
ModificadaAlta (7.5)3.0%—KDE QuantaConectiva LinuxGentoo LinuxKDE+222/4/200516/6/2026
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
ModificadaAlta (10)6.2%—Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+1227/1/200516/6/2026
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
ModificadaAlta (10)9.5%—Easy Software Products CupsGnome GpdfKDE KofficeKDE Kpdf+1227/1/200516/6/2026
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
ModificadaMedia (5)5.4%—LibtiffPdflib PDF LibraryWxgtk2Apple MAC OS X+927/1/200516/6/2026
Multiple integer overflows in libtiff 3.6.1 and earlier allow remote attackers to cause a denial of service (crash or memory corruption) via TIFF images that lead to incorrect malloc calls.
ModificadaAlta (7.5)2.7%—KDE KonquerorMandrakesoft Mandrake LinuxRedhat Fedora Core10/1/200516/6/2026
Konqueror 3.x up to 3.2.2-6, and possibly other versions, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window or tab whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection"…
ModificadaAlta (7.5)4.4%💥 ExploitKdelibsKDE Konqueror10/1/200516/6/2026
Konqueror 3.3.1 allows remote attackers to execute arbitrary FTP commands via an ftp:// URL that contains a URL-encoded newline ("%0a") before the FTP command, which causes the commands to be inserted into the resulting FTP session, as demonstrated using a PORT command.
ModificadaAlta (9.3)6.6%—Easy Software Products CupsXpdfKDE10/1/200516/6/2026
Buffer overflow in the Gfx::doImage function in Gfx.cc for xpdf 3.00, and other products that share code such as tetex-bin and kpdf in KDE 3.2.x to 3.2.3 and 3.3.x to 3.3.2, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted PDF file that causes…
ModificadaBaja (2.1)0.45%—KDEMandrakesoft Mandrake LinuxRedhat Fedora Core10/1/200516/6/2026
KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames…
ModificadaMedia (5)13%💥 ExploitOpera BrowserGentoo LinuxKDESuse Linux31/12/200416/6/2026
Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitrary code via a shortcut or launcher that contains an Exec entry.
ModificadaAlta (7.5)8.3%—LibtiffPdflib PDF LibraryWxgtk2Apple MAC OS X+923/12/200416/6/2026
Multiple vulnerabilities in the RLE (run length encoding) decoders for libtiff 3.6.1 and earlier, related to buffer overflows and integer overflows, allow remote attackers to execute arbitrary code via TIFF files.
ModificadaAlta (7.5)17%—KDE KonquerorMicrosoft IEMicrosoft Internet ExplorerMozilla Firefox+123/12/200416/6/2026
Mozilla Firefox 0.9.2 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session. NOTE: it was later reported that 2.x is also affected.
ModificadaAlta (7.5)1.9%—KDE KonquerorGentoo LinuxKDEMandrakesoft Mandrake Linux+120/10/200416/6/2026
Konqueror in KDE 3.2.3 and earlier allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk and .firm.in, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
ModificadaAlta (7.1)0.43%—KDEDebian Linux28/9/200416/6/2026
KDE before 3.3.0 does not properly handle when certain symbolic links point to "stale" locations, which could allow local users to create or truncate arbitrary files.
ModificadaMedia (4.6)0.52%—KDE28/9/200416/6/2026
The DCOPServer in KDE 3.2.3 and earlier allows local users to gain unauthorized access via a symlink attack on DCOP files in the /tmp directory.
ModificadaMedia (5)1.5%—KDE Konqueror16/9/200416/6/2026
KDE Konqueror does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent over a secure channel (HTTPS/SSL) in the same domain, which could allow remote attackers to steal cookies and conduct unauthorized activities, aka "Cross Security Boundary Cookie Injection."
ModificadaAlta (7.5)10%—KDE KonquerorMicrosoft IEMicrosoft Internet ExplorerMozilla Firefox+116/9/200416/6/2026
Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.
ModificadaMedia (5)1.0%—Ngsec Stackdefender18/8/200416/6/2026
NGSEC StackDefender 1.10 allows attackers to cause a denial of service (system crash) via an invalid address for the ObjectAttribues parameter to the hooks for the (1) ZwCreateFile or (2) ZwOpenFile functions.
ModificadaMedia (5)1.0%—Ngsec Stackdefender18/8/200416/6/2026
NGSEC StackDefender 2.0 allows attackers to cause a denial of service (system crash) via an invalid address for the BaseAddress parameter to the hooks for the (1) ZwAllocateVirtualMemory or (2) ZwProtectVirtualMemory functions.
ModificadaMedia (5)5.8%💥 ExploitKDE Konqueror6/8/200416/6/2026
KDE Konqueror 2.1.1 and 2.2.2 allows remote attackers to spoof a legitimate URL in the status bar via A HREF tags with modified "alt" values that point to the legitimate site, combined with an image map whose href points to the malicious site, which facilitates a "phishing" attack.
ModificadaAlta (7.5)1.6%—KDE Konqueror27/7/200416/6/2026
Konqueror 3.1.3, 3.2.2, and possibly other versions does not properly prevent a frame in one domain from injecting content into a frame that belongs to another domain, which facilitates web site spoofing and other attacks, aka the frame injection vulnerability.
ModificadaAlta (7.5)7.8%—KDE Konqueror7/7/200416/6/2026
The URI handlers in Konqueror for KDE 3.2.2 and earlier do not properly filter "-" characters that begin a hostname in a (1) telnet, (2) rlogin, (3) ssh, or (4) mailto URI, which allows remote attackers to manipulate the options that are passed to the associated programs, possibly to read arbitrary files or execute…
Orbitaley — Vulnerabilidades