Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 3.1% | — | Debian Cfingerd | 14/3/2013 | 16/6/2026 | Buffer overflow in the RFC1413 (ident) client in cfingerd 1.4.3-3 allows remote IDENT servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted response. | |
| Modificada | Media (5) | 1.8% | — | Evan Sims Effingerd | 31/12/2004 | 16/6/2026 | Buffer overflow in the sockFinger_DataArrival function in efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a long finger command. | |
| Modificada | Media (5) | 1.2% | — | Evan Sims Effingerd | 31/12/2004 | 16/6/2026 | efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a packet with a single byte, which triggers a "Wrong protocol or connection state" error. | |
| Modificada | Media (5) | 1.4% | — | Akfingerd | 31/12/2002 | 16/6/2026 | Akfingerd 0.5 and possibly earlier versions only allows one connection at a time and does not time out connections, which allows remote attackers to cause a denial of service (refused connections) by opening a connection and not closing it. | |
| Modificada | Baja (2.1) | 0.23% | — | Akfingerd | 31/12/2002 | 16/6/2026 | Akfingerd 0.5 and earlier versions allow local users to cause a denial of service (crash) via a .plan with a symlink to /dev/urandom or other device, then disconnecting while data is being transferred, which causes a SIGPIPE error that Akfingerd cannot handle. | |
| Modificada | Baja (2.1) | 0.30% | — | Akfingerd | 31/12/2002 | 16/6/2026 | akfingerd 0.5 allows local users to read arbitrary files as the akfingerd user (nobody) via a symlink attack on the .plan file. | |
| Modificada | Alta (7.5) | 3.5% | — | Decfingerd | 31/12/2002 | 16/6/2026 | Format string vulnerability in Deception Finger Daemon, decfingerd, 0.7 may allow remote attackers to execute arbitrary code via the username of a finger request. | |
| Modificada | Alta (10) | 5.3% | — | Efingerd | 12/8/2002 | 16/6/2026 | Buffer overflow in efingerd 1.5 and earlier, and possibly up to 1.61, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a finger request from an IP address with a long hostname that is obtained via a reverse DNS lookup. | |
| Modificada | Media (4.6) | 0.33% | — | Efingerd | 12/8/2002 | 16/6/2026 | efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger. | |
| Modificada | Alta (7.2) | 1.6% | — | Infodrom Cfingerd | 18/10/2001 | 16/6/2026 | Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file. | |
| Modificada | Crítica (9.8) | 18% | — | Infodrom Cfingerd | 2/8/2001 | 16/6/2026 | Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function. | |
| Modificada | Alta (7.2) | 0.81% | — | Infodrom Cfingerd | 21/9/1999 | 16/6/2026 | Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field. | |
| Modificada | Alta (7.2) | 0.47% | — | Infodrom Cfingerd | 10/8/1999 | 16/6/2026 | Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges. | |
| Modificada | Alta (7.2) | 0.46% | — | GNU Fingerd | 21/7/1999 | 16/6/2026 | GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files. | |
| Modificada | Alta (10) | 9.4% | — | FfingerdAI | 23/4/1999 | 16/6/2026 | The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses. | |
| Modificada | Alta (10) | 1.6% | — | Linux CfingerdAI | 1/1/1999 | 16/6/2026 | Linux cfingerd could be exploited to gain root access. | |
| Modificada | Alta (7.5) | 4.0% | — | GNU Fingerd | 1/7/1997 | 16/6/2026 | The Perl fingerd program allows arbitrary command execution from remote users. | |
| Modificada | Media (5) | 1.4% | — | Infodrom Cfingerd | 23/5/1997 | 16/6/2026 | cfingerd lists all users on a system via search.**@target. | |
| Modificada | Baja (0) | 68% | — | GNU Finger ServiceGNU FingerdMicrosoft Windows 2000Microsoft Windows NT | 1/3/1997 | 16/6/2026 | A version of finger is running that exposes valid user information to any entity on the network. |