Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.1) | 0.35% | — | Andries Brouwer Util-linux | 4/3/2007 | 16/6/2026 | login in util-linux-2.12a skips pam_acct_mgmt and chauth_tok when authentication is skipped, such as when a Kerberos krlogin session has been established, which might allow users to bypass intended access policies that would be enforced by pam_acct_mgmt and chauth_tok. | |
| Modificada | Alta (7.2) | 0.43% | — | Andries Brouwer Util-linux | 13/9/2005 | 16/6/2026 | umount in util-linux 2.8 to 2.12q, 2.13-pre1, and 2.13-pre2, and other packages such as loop-aes-utils, allows local users with unmount permissions to gain privileges via the -r (remount) option, which causes the file system to be remounted with just the read-only flag, which effectively clears the nosuid, nodev, and… | |
| Modificada | Media (5) | 3.3% | — | Andries Brouwer Util-linux | 3/3/2004 | 16/6/2026 | The login program in util-linux 2.11 and earlier uses a pointer after it has been freed and reallocated, which could cause login to leak sensitive data. | |
| Modificada | Media (4.6) | 0.74% | — | Andries Brouwer MAN | 27/8/2003 | 16/6/2026 | man-db 2.3.12 and 2.3.18 to 2.4.1 uses certain user-controlled DEFINE directives from the ~/.manpath file, even when running setuid, which could allow local users to gain privileges. | |
| Modificada | Media (4.6) | 0.80% | — | Andries Brouwer MAN | 27/8/2003 | 16/6/2026 | Multiple buffer overflows in man-db 2.4.1 and earlier, when installed setuid, allow local users to gain privileges via (1) MANDATORY_MANPATH, MANPATH_MAP, and MANDB_MAP arguments to add_to_dirlist in manp.c, (2) a long pathname to ult_src in ult_src.c, (3) a long .so argument to test_for_include in ult_src.c, (4) a… | |
| Modificada | Media (4.6) | 1.5% | — | Andries Brouwer MAN | 18/3/2003 | 16/6/2026 | man before 1.5l allows attackers to execute arbitrary code via a malformed man file with improper quotes, which causes the my_xsprintf function to return a string with the value "unsafe," which is then executed as a program via a system call if it is in the search path of the user who runs man. | |
| Modificada | Media (5) | 1.6% | — | Andries Brouwer Util-linux | 3/3/2003 | 16/6/2026 | A patch for mcookie in the util-linux package for Mandrake Linux 8.2 and 9.0 uses /dev/urandom instead of /dev/random, which causes mcookie to use an entropy source that is more predictable than expected, which may make it easier for certain types of attacks to succeed. | |
| Modificada | Alta (7.2) | 0.43% | — | Andries Brouwer Util-linux | 1/4/2002 | 16/6/2026 | vipw in the util-linux package before 2.10 causes /etc/shadow to be world-readable in some cases, which would make it easier for local users to perform brute force password guessing. | |
| Modificada | Alta (7.2) | 0.43% | — | Andries Brouwer Util-linux | 8/10/2001 | 16/6/2026 | The PAM implementation in /bin/login of the util-linux package before 2.11 causes a password entry to be rewritten across multiple PAM calls, which could provide the credentials of one user to a different user, when used in certain PAM modules such as pam_limits. |