Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2500▼ 420 respecto a la semana anterior
Críticas / altas1284▲ 11 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
86 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.18% | — | Redhat Fedora Coreos | 3/11/2022 | 17/6/2026 | Fedora CoreOS supports setting a GRUB bootloader password using a Butane config. When this feature is enabled, GRUB requires a password to access the GRUB command-line, modify kernel command-line arguments, or boot non-default OSTree deployments. Recent Fedora CoreOS releases have a misconfiguration which allows… | |
| Modificada | Media (4.9) | 0.43% | — | Fedoraproject Fedora CoreLinux KernelRedhat Enterprise Linux | 30/6/2008 | 16/6/2026 | Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a denial of service (oops), as demonstrated by a crash when running the GNU GDB testsuite, a different vulnerability than CVE-2008-2365. | |
| Modificada | Media (4.9) | 0.42% | — | Fedoraproject Fedora CoreRedhat Enterprise LinuxOracle LinuxCentos+5 | 18/12/2007 | 16/6/2026 | Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named. | |
| Modificada | Baja (2.1) | 0.41% | — | Redhat Fedora Core | 26/11/2007 | 16/6/2026 | buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files. | |
| Modificada | Alta (7.2) | 0.46% | — | QemuFedoraproject FedoraFedoraproject Fedora CoreDebian Linux | 30/10/2007 | 16/6/2026 | Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used… | |
| Modificada | Media (5) | 13% | — | Apache Http ServerFedoraproject FedoraFedoraproject Fedora CoreCanonical Ubuntu Linux | 23/8/2007 | 16/6/2026 | The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read. | |
| Modificada | Media (5.8) | 2.5% | — | Redhat Fedora Core | 27/7/2007 | 16/6/2026 | Buffer overflow in the wpa_printf function in the debugging code in wpa_supplicant in the Fedora NetworkManager package before 0.6.5-3.fc7 allows user-assisted remote attackers to execute arbitrary code via malformed frames on a WPA2 network. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (6.2) | 0.90% | — | Fedoraproject Fedora CoreRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Linux | 15/7/2007 | 16/6/2026 | The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the /tmp/.font-unix temporary file. | |
| Modificada | Alta (7.2) | 0.49% | — | QemuFedoraproject FedoraFedoraproject Fedora CoreOpensuse+1 | 2/5/2007 | 16/6/2026 | Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt"… | |
| Modificada | Media (4.9) | 0.36% | — | Redhat Enterprise LinuxRedhat Fedora Core | 16/4/2007 | 16/6/2026 | lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked. | |
| Modificada | Baja (3.8) | 1.5% | — | Mandrakesoft Mandrake Multi Network FirewallX.org LibxfontRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+8 | 6/4/2007 | 16/6/2026 | Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow. | |
| Modificada | Alta (10) | 5.9% | — | GNU Privacy GuardGpg4winRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+5 | 7/12/2006 | 16/6/2026 | A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory. | |
| Modificada | Media (4.9) | 0.86% | — | Linux KernelRedhat Fedora Core | 3/11/2006 | 16/6/2026 | Double free vulnerability in squashfs module in the Linux kernel 2.6.x, as used in Fedora Core 5 and possibly other distributions, allows local users to cause a denial of service by mounting a crafted squashfs filesystem. | |
| Modificada | Alta (7.5) | 4.1% | — | Fedoraproject Fedora CoreRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux FOR IBM Z Systems+4 | 10/10/2006 | 16/6/2026 | pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server responds with a PasswordPolicyResponse control response, which causes the pam_authenticate function to return a success code even if… | |
| Modificada | Alta (7.2) | 1.1% | — | X.org X11r6X.org X11r7Mandrakesoft Mandrake LinuxRedhat Fedora Core+2 | 21/3/2006 | 16/6/2026 | X.Org server (xorg-server) 1.0.0 and later, X11R6.9.0, and X11R7.0 inadvertently treats the address of the geteuid function as if it is the return value of a call to geteuid, which allows local users to bypass intended restrictions and (1) execute arbitrary code via the -modulepath command line option or (2) overwrite… | |
| Modificada | Alta (7.8) | 1.9% | — | Redhat Fedora Core | 14/2/2006 | 16/6/2026 | The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite. | |
| Modificada | Media (5) | 1.6% | — | Redhat Fedora Core | 14/2/2006 | 16/6/2026 | dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of "," (comma) characters, which results in a large amount of recursion, as demonstrated using the ProtoVer… | |
| Modificada | Media (5) | 1.6% | — | Redhat Fedora Core | 14/2/2006 | 16/6/2026 | Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the… | |
| Modificada | Media (5) | 2.3% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. | |
| Modificada | Media (5) | 1.4% | — | Redhat Fedora Core | 31/12/2005 | 16/6/2026 | Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives. | |
| Modificada | Media (5) | 3.4% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | |
| Modificada | Alta (10) | 3.8% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | |
| Modificada | Media (5) | 14% | — | Apache Http ServerCanonical Ubuntu LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+2 | 25/10/2005 | 16/6/2026 | Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, which prevents the memory for the transaction pool from being reused for other connections. | |
| Modificada | Media (5) | 14% | — | LBL TcpdumpGentoo LinuxMandrakesoft Mandrake LinuxRedhat Fedora Core+1 | 10/6/2005 | 16/6/2026 | The bgp_update_print function in tcpdump 3.x does not properly handle a -1 return value from the decode_prefix4 function, which allows remote attackers to cause a denial of service (infinite loop) via a crafted BGP packet. | |
| Modificada | Media (6.8) | 2.3% | — | HtdigMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate ServerRedhat Fedora Core+1 | 27/4/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message. |