Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3149▲ 581 respecto a la semana anterior
Críticas / altas1502▲ 105 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)238▲ 224 respecto a la semana anterior
2286 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 8.4% | — | Apache Http ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 5/8/2005 | 16/6/2026 | Error de fuera-por-uno en la retrollamda de verificación de Lista de Revocación de Certificados (CRL) de mod_ssl para Apache, cuando se configura para usar un CRL, permite a atacantes remotos causar una denegación de servicio (caída de proceso hijo) mediante una CRL que causa un desbordamiento de búfer de un byte nule. | |
| Modificada | Media (5) | 5.5% | 💥 Exploit | Hauri Virobot Linux Server | 15/6/2005 | 16/6/2026 | Buffer overflow in addschup in HAURI ViRobot 2.0, and possibly other products, allows remote attackers to execute arbitrary code via a long ViRobot_ID cookie (HTTP_COOKIE). | |
| Modificada | Baja (3.7) | 0.66% | — | GNU GzipFreebsdGentoo LinuxRedhat Enterprise Linux+9 | 2/5/2005 | 16/6/2026 | Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete. | |
| Modificada | Media (5) | 2.5% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight Commander (mc) 4.5.55 y versiones anteriores, permiten a atacantes remotos causar la Denegación de Servicio (DoS) por bucle infinito mediante un ataque desconocido. | |
| Modificada | Alta (7.5) | 3.1% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight Commander (mc) 4.5.55 y versiones anteriores, permiten a atacantes remotos causar la Denegación de Servicio (DoS) mediante una sección corrupta de la cabecera. | |
| Modificada | Alta (7.5) | 1.6% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters. | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory. | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory." | |
| Modificada | Alta (7.5) | 1.6% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Múltiples vulnerabilidades de cadena de formato en Midnight Commander (mc) 4.5.55 y versiones anteriores, permiten a atacantes remotos ejecutar acciones de impacto desconocido. | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight Commander (mc) 4.5.55 y versiones anteriores, permiten a atacantes remotos causar la Denegación de Servicio (DoS) provocando una referencia nula. | |
| Modificada | Media (5) | 1.4% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles." | |
| Modificada | Alta (7.5) | 1.8% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Múltiples desbordamientos de búfer en Midnight Commander (mc) 4.5.55 y versiones anteriores, permiten a atacantes remotos ejecutar acciones de impacto desconocido. | |
| Modificada | Alta (7.2) | 0.51% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+4 | 10/1/2005 | 16/6/2026 | El cargador binfmt_loader (binfmt_elf.c) del kernel de Linux 2.4.x a 2.4.27, y 2.6.x a 2.6.8 no maneja adecuadamente una llamada fallida a la función nmap, lo que produce una imagen incorrectamente mapeada y puede permitir a usuarios locales ejecutar código de su elección. | |
| Modificada | Baja (2.1) | 0.81% | 💥 Exploit | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+4 | 10/1/2005 | 16/6/2026 | La función open_exec en la funcionalidad execve (exec.c) en el kernel de Linux 2.4.x hasta 2.3.27, y 2.6.x hasta 2.6.8, permite a usuarios locales leer binarios ELF no legibles usando la funcionalidad de intérprete (PT_INTERP).. | |
| Modificada | Alta (7.2) | 0.56% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+4 | 10/1/2005 | 16/6/2026 | El cargador binfmt_elf (binfmt_elf.c) del kernel de Linux 2.4.x hasta 2.4.27, y 2.6.x a 2.6.8 puede crear una cadena de nombre de intérprete sin terminador nulo, lo que podría causarf que cadenas más largas que PATH_MAX sean usadas, conduciendo a desbordamientos de búfer que permiten a usuarios locales causar una… | |
| Modificada | Alta (7.2) | 0.51% | — | Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+4 | 10/1/2005 | 16/6/2026 | El cargador binfmt_elf (binfmt_elf.c) del kernel de Linux 2.4x a 2.4.27, y 2.6.x a 2.6.8 no verifica adecuadamente los valores de retorno de llamadas a la función kernel_read, lo que puede permitir a usuarios locales modificar información sensible en un programa setuid y ejecutar código de su elección. | |
| Modificada | Media (5.1) | 3.4% | — | Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+12 | 31/12/2004 | 16/6/2026 | Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817. | |
| Modificada | Alta (7.5) | 4.9% | — | Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+12 | 31/12/2004 | 16/6/2026 | Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file. | |
| Modificada | Baja (2.1) | 0.36% | — | GNU A2psTurbolinux HomeTurbolinux ServerTurbolinux Workstation | 27/12/2004 | 16/6/2026 | The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 8.3% | — | MIT Kerberos 5Debian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 28/9/2004 | 16/6/2026 | Vulnerabilidades de liberación doble en el código de manejo de errores de ASN.1 en (1) la librería del Centro de Distribución de Claves (KDC) y (2) librería de cliente de MIT Kerberos 5 (krb5) 1.3.4 y anteriores puede permitir a atacantes remotos ejecutar código arbitrario. | |
| Modificada | Media (4.6) | 8.9% | — | MIT Kerberos 5Debian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 28/9/2004 | 16/6/2026 | Vulnerabilidad de doble liberación de memoria en la función krb5_rd_cred de MIT Kerberos 5 (krb5) 1.3.1 y anteriores pueden permitir a usuarios locales ejecutar código de su elección. | |
| Modificada | Media (5) | 17% | — | Apache Http ServerHP Secure WEB Server FOR Tru64Gentoo LinuxHp-ux+8 | 16/9/2004 | 16/6/2026 | The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access. | |
| Modificada | Alta (7.5) | 38% | — | Apache Http ServerDebian LinuxRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 7/7/2004 | 16/6/2026 | Desbordamiento de búfer basado en la pila en la función ssl_util_uuencode_binary en ssl_util.c de mod_ssl de Apache cuando se configura mod_ssl para que confie en la Autoridad Certificadora emisora, puede permitir a atacantes remotos ejecutar código arbitrario mediante un certificado de cliente con un DN de asunto… | |
| Modificada | Media (5) | 2.1% | — | Caldera Openlinux ServerCaldera Openlinux WorkstationCaldera OpenserverSCO Unixware | 20/10/2003 | 16/6/2026 | Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules. |