Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3246▲ 704 respecto a la semana anterior
Críticas / altas1521▲ 136 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)235▲ 221 respecto a la semana anterior
2299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.2% | — | Apple Quicktime Pictureviewer | 2/5/2005 | 16/6/2026 | PictureViewer in QuickTime for Windows 6.5.2 allows remote attackers to cause a denial of service (application crash) via a GIF image with the maximum depth start value, possibly triggering an integer overflow. | |
| Modificada | Baja (2.6) | 2.1% | 💥 Exploit | Apple Quicktime Pictureviewer | 2/5/2005 | 16/6/2026 | Buffer overflow in QuickTime PictureViewer 6.5.1 allows remote attackers to cause a denial of service (application crash) via a JPEG file with crafted Huffman Table (marker DHT) data. | |
| Modificada | Baja (2.1) | 1.1% | 💥 Exploit | Runtime Software Getdataback FOR Ntfs | 2/5/2005 | 16/6/2026 | GetDataBack for NTFS 2.31 stores the username and license key in plaintext in the Name value in the License registry key, which may allow local users to obtain sensitive information. | |
| Modificada | Media (5) | 1.2% | — | Apple Quicktime | 1/3/2005 | 16/6/2026 | Integer overflow on Apple QuickTime before 6.5.2, when running on Windows systems, allows remote attackers to cause a denial of service (memory consumption) via certain inputs that cause a large memory operation. | |
| Modificada | Media (5) | 0.97% | — | Apple QuicktimeApple MAC OS XApple MAC OS X Server | 27/1/2005 | 16/6/2026 | AFP Server on Mac OS X 10.3.x to 10.3.5, under certain conditions, does not properly set the guest group ID, which causes AFP to change a write-only AFP Drop Box to be read-write when the Drop Box is on a share that is mounted by a guest, which allows attackers to read the Drop Box. | |
| Modificada | Alta (7.5) | 1.1% | — | Apple QuicktimeApple MAC OS XApple MAC OS X Server | 27/1/2005 | 16/6/2026 | AFP Server on Mac OS X 10.3.x to 10.3.5, when a guest has mounted an AFP volume, allows the guest to "terminate authenticated user mounts" via modified SessionDestroy packets. | |
| Modificada | Media (5) | 1.3% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 10/1/2005 | 16/6/2026 | Darwin Streaming Server 5.0.1, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via a DESCRIBE request with a location that contains a null byte. | |
| Modificada | Media (5) | 1.7% | — | 3DO Army MEN Real Time Strategy Game | 31/12/2004 | 16/6/2026 | Format string vulnerability in Army Men RTS 1.0 allows remote attackers to cause a denial of service (application crash) via a nickname that contains format strings. | |
| Modificada | Media (6.4) | 1.7% | — | Zonet Zsr1104we Wireless Router Runtime Code | 31/12/2004 | 16/6/2026 | The NAT implementation in Zonet ZSR1104WE Wireless Router Runtime Code Version 2.41 converts IP addresses of inbound connections to the IP address of the router, which allows remote attackers to bypass intended security restrictions. | |
| Modificada | Alta (7.2) | 0.40% | — | GNU Realtime Linux Security ModuleConectiva LinuxUbuntu Linux | 23/12/2004 | 16/6/2026 | The POSIX Capability Linux Security Module (LSM) for Linux kernel 2.6 does not properly handle the credentials of a process that is launched before the module is loaded, which allows local users to gain privileges. | |
| Modificada | Alta (10) | 74% | 💥 Exploit | Arush DevastationDreamforge TNN Outdoors PRO HunterEpic Games Unreal EngineEpic Games Unreal Tournament+10 | 6/12/2004 | 16/6/2026 | El Motor de Unreal, usado en in DeusEx 1.112fm y anteriores, , Devastation 390 y anteriores, Mobile Forces 20000 y anteriores, Nerf Arena Blast 1.2 y anteriores, Postal 2 1337 y anteriores, Rune 107 y anteriores, Tactical Ops 3.4.0 y anteriores, Unreal 1 226f y anteriores, Unreal II XMP 7710 y anteriores, Unreal… | |
| Modificada | Alta (7.5) | 1.9% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 3/12/2004 | 16/6/2026 | Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner, but the Apple HFS+ filesystem accesses files in a case insensitive manner, which allows remote attackers to read .DS_Store files and files beginning with ".ht" using alternate capitalization. | |
| Modificada | Baja (2.1) | 0.34% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | Human Interface Toolbox (HIToolBox) for Apple Mac 0S X 10.3.6 allows local users to exit applications via the force-quit key combination, even when the system is running in kiosk mode. | |
| Modificada | Alta (7.5) | 3.4% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | Buffer overflow in PSNormalizer for Apple Mac OS X 10.3.6 allows remote attackers to execute arbitrary code via a crafted PostScript input file. | |
| Modificada | Media (4.6) | 0.34% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | Unknown vulnerability in Apple Mac OS X 10.3.6 server, when using Kerberos authentication and Cyrus IMAP allows local users to access mailboxes of other users. | |
| Modificada | Baja (2.1) | 0.34% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | The Application Framework (AppKit) for Apple Mac OS X 10.2.8 and 10.3.6 does not properly restrict access to a secure text input field, which allows local users to read keyboard input from other applications within the same window session. | |
| Modificada | Alta (7.5) | 1.7% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | Postfix server for Apple Mac OS X 10.3.6, when using CRAM-MD5, allows remote attackers to send mail without authentication by replaying authentication information. | |
| Modificada | Media (5) | 1.6% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | Apache for Apple Mac OS X 10.2.8 and 10.3.6 allows remote attackers to read files and resource fork content via HTTP requests to certain special file names related to multiple data streams in HFS+, which bypass Apache file handles. | |
| Modificada | Baja (2.1) | 0.35% | — | Apple Darwin Streaming ServerApple Quicktime Streaming ServerApple MAC OS XApple MAC OS X Server | 2/12/2004 | 16/6/2026 | Terminal for Apple Mac OS X 10.3.6 may indicate that "Secure Keyboard Entry" is enabled even when it is not, which could result in a false sense of security for the user. | |
| Modificada | Media (5.1) | 3.2% | — | Apple Quicktime | 7/7/2004 | 16/6/2026 | Desbordamiento de enteros en Apple QuickTime (QuickTime.qts) anteriores a 6.5.1 permite a atacantes ejecutar código de se elección mediante un "número de entradas" grande en la tabla de datos sample-to-chunk de un fichero de película .mov, lo que lleva un desbordamiento de búfer basado en el montón. | |
| Modificada | Media (4.3) | 1.2% | — | Apple Darwin Streaming ServerApple Quicktime Streaming Server | 31/12/2003 | 16/6/2026 | parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Apple Darwin Streaming ServerApple Quicktime Streaming Server | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in parse_xml.cg Apple Darwin Streaming Server 4.1.2 and Apple Quicktime Streaming Server 4.1.1 allows remote attackers to read arbitrary files via a ... (triple dot) in the filename parameter. | |
| Modificada | Alta (7.5) | 6.4% | 💥 Exploit | Apple QuicktimeAIApple Darwin Streaming ServerAI | 31/12/2003 | 16/6/2026 | Integer overflow in MP3Broadcaster for Apple QuickTime/Darwin Streaming Server 4.1.3 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed ID3 tags in MP3 files. | |
| Modificada | Media (5) | 8.6% | — | Hitachi Groupmax Mail - Security OptionHitachi PKI Runtime Library | 1/12/2003 | 16/6/2026 | Múltiples vulnerabilidades en múltiples implementaciones de fabricantes del protocolo S/MIME (Secure/Multiporpouse Internet Mail Extensions) permiten a atacantes remotos causar una denegación de servicio y posiblemente ejecutar código arbitrario mediante un mensaje de correo electrónico S/MIME conteniendo ciertas… | |
| Modificada | Media (5) | 2.9% | — | KDE KonquerorKDE Konqueror EmbeddedRedhat Analog Real-time SynthesizerRedhat Kdebase+4 | 27/8/2003 | 16/6/2026 | KDE Konqueror de KDE 3.1.2 y anteriores no elimina los credenciales de autenticación de URLs de la forma "usuario:contraseña@máquina" en la cabecera HTTP-Referer, lo que podría permitir a sitios web remotos robar las credenciales de páginas que enlazan a esos sitios. |