Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
667 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.2% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2010 | 16/6/2026 | AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 generates different error messages depending on whether a share exists, which allows remote attackers to enumerate valid share names via unspecified vectors. | |
| Modificada | Media (6) | 2.3% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2010 | 16/6/2026 | Directory traversal vulnerability in AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote authenticated users to execute arbitrary code by creating files that are outside the bounds of a share. | |
| Modificada | Media (5) | 2.3% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2010 | 16/6/2026 | AFP Server in Apple Mac OS X 10.5.8 and 10.6.x before 10.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon restart) via crafted reconnect authentication packets. | |
| Modificada | Media (4.3) | 1.7% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2010 | 16/6/2026 | Time Machine in Apple Mac OS X 10.6.x before 10.6.5 does not verify the unique identifier of its remote AFP volume, which allows remote attackers to obtain sensitive information by spoofing this volume. | |
| Modificada | Crítica (9.8) | 1.3% | — | Apple MAC OS XApple MAC OS X Server | 15/11/2010 | 16/6/2026 | OpenSSL in Apple Mac OS X 10.6.x before 10.6.5 does not properly perform arithmetic, which allows remote attackers to bypass X.509 certificate authentication via an arbitrary certificate issued by a legitimate Certification Authority. | |
| Modificada | Crítica (9.8) | 6.4% | — | Apple CupsApple MAC OS XApple MAC OS X ServerFedoraproject Fedora+9 | 5/11/2010 | 16/6/2026 | ipp.c in cupsd in CUPS 1.4.4 and earlier does not properly allocate memory for attribute values with invalid string data types, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted IPP request. | |
| Modificada | Media (6.8) | 1.8% | — | Apple MAC OS XApple MAC OS X Server | 21/9/2010 | 16/6/2026 | Apple Filing Protocol (AFP) Server in Apple Mac OS X 10.6.x through 10.6.4 does not properly handle errors, which allows remote attackers to bypass the password requirement for shared-folder access by leveraging knowledge of a valid account name. | |
| Modificada | Media (6.8) | 3.3% | — | Apple Type ServicesApple MAC OS XApple MAC OS X Server | 25/8/2010 | 16/6/2026 | Stack-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded font in a document. | |
| Modificada | Media (6.4) | 0.80% | — | Apple LibsecurityApple MAC OS XApple MAC OS X Server | 25/8/2010 | 16/6/2026 | libsecurity in Apple Mac OS X 10.5.8 and 10.6.4 does not properly perform comparisons to domain-name strings in X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a certificate associated with a similar domain name, as demonstrated by use of a www.example.con certificate to spoof… | |
| Modificada | Media (6.8) | 3.3% | — | Apple CoregraphicsApple MAC OS XApple MAC OS X Server | 25/8/2010 | 16/6/2026 | Heap-based buffer overflow in CoreGraphics in Apple Mac OS X 10.5.8 and 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF file. | |
| Modificada | Media (5) | 1.3% | — | Apple CfnetworkApple MAC OS XApple MAC OS X Server | 25/8/2010 | 16/6/2026 | CFNetwork in Apple Mac OS X 10.6.3 and 10.6.4 supports anonymous SSL and TLS connections, which allows man-in-the-middle attackers to redirect a connection and obtain sensitive information via crafted responses. | |
| Modificada | Crítica (9.8) | 28% | 💥 Exploit | OpenldapVmware EsxiOpensuseApple MAC OS X+1 | 28/7/2010 | 16/6/2026 | The slap_modrdn2mods function in modrdn.c in OpenLDAP 2.4.22 does not check the return value of a call to the smr_normalize function, which allows remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a modrdn call with an RDN string containing invalid UTF-8… | |
| Modificada | Crítica (9.8) | 43% | 💥 Exploit | LibpngGoogle ChromeApple ItunesApple Safari+13 | 30/6/2010 | 16/6/2026 | Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row. | |
| Modificada | Media (6.5) | 2.7% | — | SquirrelmailFedoraproject FedoraApple MAC OS XApple MAC OS X Server+3 | 22/6/2010 | 16/6/2026 | The Mail Fetch plugin in SquirrelMail 1.4.20 and earlier allows remote authenticated users to bypass firewall restrictions and use SquirrelMail as a proxy to scan internal networks via a modified POP3 port number. | |
| Modificada | Media (6.8) | 13% | 💥 PoC | Apple MAC OS XApple MAC OS X Server | 17/6/2010 | 16/6/2026 | Multiple integer overflows in the Fax3SetupState function in tif_fax3.c in the FAX3 decoder in LibTIFF before 3.9.3, as used in ImageIO in Apple Mac OS X 10.5.8 and Mac OS X 10.6 before 10.6.4, allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF file… | |
| Modificada | Baja (3.5) | 1.5% | — | Apple MAC OS XApple MAC OS X Server | 17/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Wiki Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows remote authenticated users to inject arbitrary web script or HTML via crafted Wiki content, related to lack of a charset field. | |
| Modificada | Baja (3.5) | 1.5% | — | Apple MAC OS XApple MAC OS X Server | 17/6/2010 | 16/6/2026 | The default configuration of SMB File Server in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, enables support for wide links, which allows remote authenticated users to access arbitrary files via vectors involving symbolic links. NOTE: this might overlap CVE-2010-0926. | |
| Modificada | Alta (7.5) | 3.7% | — | Apple MAC OS XApple MAC OS X Server | 17/6/2010 | 16/6/2026 | Integer overflow in the cgtexttops CUPS filter in Printing in Apple Mac OS X 10.6 before 10.6.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to page sizes. | |
| Modificada | Media (5) | 2.4% | — | Apple MAC OS XApple MAC OS X Server | 17/6/2010 | 16/6/2026 | Printer Setup in Apple Mac OS X 10.6 before 10.6.4 does not properly interpret character encoding, which allows remote attackers to cause a denial of service (printing failure) by deploying a printing device that has a Unicode character in its printing-service name. | |
| Modificada | Alta (9.3) | 2.7% | — | Apple MAC OS XApple MAC OS X Server | 17/6/2010 | 16/6/2026 | Open Directory in Apple Mac OS X 10.6 before 10.6.4 creates an unencrypted connection upon certain SSL failures, which allows man-in-the-middle attackers to spoof arbitrary network account servers, and possibly execute arbitrary code, via unspecified vectors. | |
| Modificada | Media (6.8) | 3.2% | — | Apple MAC OS XApple MAC OS X Server | 17/6/2010 | 16/6/2026 | Multiple format string vulnerabilities in Network Authorization in Apple Mac OS X 10.6 before 10.6.4 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via format string specifiers in a (1) afp, (2) cifs, or (3) smb URL. | |
| Modificada | Alta (7.2) | 0.35% | — | Apple MAC OS XApple MAC OS X Server | 17/6/2010 | 16/6/2026 | NetAuthSysAgent in Network Authorization in Apple Mac OS X 10.5.8 does not have the expected authorization requirements, which allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (4.3) | 2.3% | — | Apple MAC OS XApple MAC OS X Server | 17/6/2010 | 16/6/2026 | Directory traversal vulnerability in iChat in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, when AIM is used, allows remote attackers to create arbitrary files via directory traversal sequences in an inline image-transfer operation. | |
| Modificada | Media (4.3) | 1.2% | — | Apple MAC OS XApple MAC OS X Server | 17/6/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Help Viewer in Apple Mac OS X 10.6 before 10.6.4 allows remote attackers to inject arbitrary web script or HTML via a crafted help: URL, related to "URL parameters in HTML content." | |
| Modificada | Baja (3.3) | 0.35% | — | Apple MAC OS XApple MAC OS X Server | 17/6/2010 | 16/6/2026 | Folder Manager in Apple Mac OS X 10.5.8, and 10.6 before 10.6.4, allows local users to delete arbitrary folders via a symlink attack in conjunction with an unmount operation on a crafted volume, related to the Cleanup At Startup folder. |