Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)3.1%—Debian Cfingerd14/3/201316/6/2026
Buffer overflow in the RFC1413 (ident) client in cfingerd 1.4.3-3 allows remote IDENT servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted response.
ModificadaMedia (5)1.8%—Evan Sims Effingerd31/12/200416/6/2026
Buffer overflow in the sockFinger_DataArrival function in efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a long finger command.
ModificadaMedia (5)1.2%—Evan Sims Effingerd31/12/200416/6/2026
efFingerD 0.2.12 allows remote attackers to cause a denial of service (daemon crash) via a packet with a single byte, which triggers a "Wrong protocol or connection state" error.
ModificadaMedia (5)1.4%—Akfingerd31/12/200216/6/2026
Akfingerd 0.5 and possibly earlier versions only allows one connection at a time and does not time out connections, which allows remote attackers to cause a denial of service (refused connections) by opening a connection and not closing it.
ModificadaBaja (2.1)0.23%—Akfingerd31/12/200216/6/2026
Akfingerd 0.5 and earlier versions allow local users to cause a denial of service (crash) via a .plan with a symlink to /dev/urandom or other device, then disconnecting while data is being transferred, which causes a SIGPIPE error that Akfingerd cannot handle.
ModificadaBaja (2.1)0.30%—Akfingerd31/12/200216/6/2026
akfingerd 0.5 allows local users to read arbitrary files as the akfingerd user (nobody) via a symlink attack on the .plan file.
ModificadaAlta (7.5)3.5%—Decfingerd31/12/200216/6/2026
Format string vulnerability in Deception Finger Daemon, decfingerd, 0.7 may allow remote attackers to execute arbitrary code via the username of a finger request.
ModificadaAlta (10)5.3%—Efingerd12/8/200216/6/2026
Buffer overflow in efingerd 1.5 and earlier, and possibly up to 1.61, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a finger request from an IP address with a long hostname that is obtained via a reverse DNS lookup.
ModificadaMedia (4.6)0.33%—Efingerd12/8/200216/6/2026
efingerd 1.61 and earlier, when configured without the -u option, executes .efingerd files as the efingerd user (typically "nobody"), which allows local users to gain privileges as the efingerd user by modifying their own .efingerd file and running finger.
ModificadaAlta (7.2)1.6%—Infodrom Cfingerd18/10/200116/6/2026
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute arbitrary code via a long line in the .nofinger file.
ModificadaCrítica (9.8)18%—Infodrom Cfingerd2/8/200116/6/2026
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.
ModificadaAlta (7.2)0.81%—Infodrom Cfingerd21/9/199916/6/2026
Buffer overflow in cfingerd allows local users to gain root privileges via a long GECOS field.
ModificadaAlta (7.2)0.47%—Infodrom Cfingerd10/8/199916/6/2026
Cfingerd with ALLOW_EXECUTION enabled does not properly drop privileges when it executes a program on behalf of the user, allowing local users to gain root privileges.
ModificadaAlta (7.2)0.46%—GNU Fingerd21/7/199916/6/2026
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.
ModificadaAlta (10)9.4%—FfingerdAI23/4/199916/6/2026
The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.
ModificadaAlta (10)1.6%—Linux CfingerdAI1/1/199916/6/2026
Linux cfingerd could be exploited to gain root access.
ModificadaAlta (7.5)4.0%—GNU Fingerd1/7/199716/6/2026
The Perl fingerd program allows arbitrary command execution from remote users.
ModificadaMedia (5)1.4%—Infodrom Cfingerd23/5/199716/6/2026
cfingerd lists all users on a system via search.**@target.
ModificadaBaja (0)68%—GNU Finger ServiceGNU FingerdMicrosoft Windows 2000Microsoft Windows NT1/3/199716/6/2026
A version of finger is running that exposes valid user information to any entity on the network.