Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3091▲ 520 respecto a la semana anterior
Críticas / altas1463▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2067 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | — | Avaya CvlanRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Linux Advanced Workstation | 23/11/2004 | 16/6/2026 | Multiple extfs backend scripts for GNOME virtual file system (VFS) before 1.0.1 may allow remote attackers to perform certain unauthorized actions via a gnome-vfs URI. | |
| Modificada | Alta (7.5) | 9.5% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | La función do_change_cipher_spec en OpenSSL 0.9.6c hasta 0.9.6.k y 0.9.7a hasta 0.9.7c permite que atacantes remotos provoquen una denegación de servicio (caída) mediante una hábil unión SSL/TLS que provoca un puntero nulo. | |
| Modificada | Media (5) | 10% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+61 | 23/11/2004 | 16/6/2026 | El código que une SSL/TLS en OpenSSL 0.9.7a, 0.9.7b y 0.9.7c, usando Kerberos, no comprueba adecuadamente la longitud de los tickets de Kerberos, lo que permite que atacantes remotos provoquen una denegación de servicio. | |
| Modificada | Alta (7.5) | 1.4% | — | Redhat Enterprise LinuxRedhat Enterprise Linux Desktop | 20/10/2004 | 16/6/2026 | Vulnerabilidad desconocida en redhat-config-nfs anteriores a 1.0.13, cuando los recursos compartido se exportan a múltiples máquinas, puede producir permisos incorrectos y prevenir que la opción all_squash sea aplicada. | |
| Modificada | Media (5) | 1.7% | — | MozillaSGI PropackRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+3 | 18/10/2004 | 16/6/2026 | Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme. | |
| Modificada | Alta (7.5) | 8.3% | — | MIT Kerberos 5Debian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 28/9/2004 | 16/6/2026 | Vulnerabilidades de liberación doble en el código de manejo de errores de ASN.1 en (1) la librería del Centro de Distribución de Claves (KDC) y (2) librería de cliente de MIT Kerberos 5 (krb5) 1.3.4 y anteriores puede permitir a atacantes remotos ejecutar código arbitrario. | |
| Modificada | Media (4.6) | 8.9% | — | MIT Kerberos 5Debian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 28/9/2004 | 16/6/2026 | Vulnerabilidad de doble liberación de memoria en la función krb5_rd_cred de MIT Kerberos 5 (krb5) 1.3.1 y anteriores pueden permitir a usuarios locales ejecutar código de su elección. | |
| Modificada | Alta (7.5) | 5.5% | — | Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+10 | 16/9/2004 | 16/6/2026 | Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files. | |
| Modificada | Media (5) | 17% | — | Apache Http ServerHP Secure WEB Server FOR Tru64Gentoo LinuxHp-ux+8 | 16/9/2004 | 16/6/2026 | The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access. | |
| Modificada | Media (4.6) | 3.0% | — | Mozilla FirefoxMozillaNetscape NavigatorConectiva Linux+6 | 14/9/2004 | 16/6/2026 | Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain. | |
| Modificada | Media (5) | 4.1% | — | LibpngOpenpkgRedhat LibpngRedhat Enterprise Linux+2 | 18/8/2004 | 16/6/2026 | La librería de Graficos de Red Portables (libpng) 1.0.15 y anteriores permiten a atacantes causar una denegación de servicio (caída) mediante un fichero de imagen PNG que dispara un error que causa un lectura fuera de límites cuando se crea el mensaje de error. | |
| Modificada | Alta (10) | 25% | 💥 Exploit | SOXConectiva LinuxGentoo LinuxRedhat Enterprise Linux+2 | 6/8/2004 | 16/6/2026 | Múltiples desbordamientos de búfer en Sound eXchange (SoX) anteriores a 12.17 permite a atacantes remotos ejecutar código arbitrario mediante ciertos campos de cabecera de ficheros WAV. | |
| Modificada | Media (4.9) | 2.5% | — | SGI IrixDebian LinuxMandrakesoft Mandrake LinuxMicrosoft Windows 98+7 | 31/12/2002 | 16/6/2026 | The Internet Group Management Protocol (IGMP) allows local users to cause a denial of service via an IGMP membership report to a target's Ethernet address instead of the Multicast group address, which causes the target to stop sending reports to the router and effectively disconnect the group from the network. | |
| Modificada | Alta (10) | 5.2% | — | Caldera Openlinux DesktopCaldera Openlinux EdesktopCaldera Openlinux Eserver | 26/3/2001 | 16/6/2026 | Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrary commands. | |
| Modificada | Baja (1.2) | 0.34% | — | Caldera Openlinux DesktopImmunixCaldera Openlinux EdesktopCaldera Openlinux Eserver+3 | 12/3/2001 | 16/6/2026 | inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations. | |
| Modificada | Media (5) | 9.9% | 💥 Exploit | Caldera Openlinux DesktopCaldera Openlinux EbuilderCaldera Openlinux EdesktopCaldera Openlinux Eserver+2 | 4/7/2000 | 16/6/2026 | BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters. | |
| Modificada | Baja (2.1) | 0.55% | — | Debian LinuxFreebsdMandrakesoft Mandrake LinuxRedhat Enterprise Linux+2 | 16/7/1996 | 16/6/2026 | cpio on FreeBSD 2.1.0, Debian GNU/Linux 3.0, and possibly other operating systems, uses a 0 umask when creating files using the -O (archive) or -F options, which creates the files with mode 0666 and allows local users to read or overwrite those files. |