Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2556▼ 314 respecto a la semana anterior
Críticas / altas1340▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

65 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)13%—Redhat DesktopRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Desktop Workstation+123/5/200816/6/2026
Buffer overflow in pattern.c in libxslt before 1.1.24 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via an XSL style sheet file with a long XSLT "transformation match" condition that triggers a large number of steps.
ModificadaAlta (7.2)80%—Debian LinuxOpenbsdRedhat Enterprise LinuxRedhat Linux Advanced Workstation+311/10/200716/6/2026
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some other dhcpd implementations based on ISC dhcp-2, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a DHCP request specifying a maximum message size smaller…
ModificadaBaja (3.8)1.5%—Mandrakesoft Mandrake Multi Network FirewallX.org LibxfontRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+86/4/200716/6/2026
Integer overflow in the FontFileInitTable function in X.Org libXfont before 20070403 allows remote authenticated users to execute arbitrary code via a long first line in the fonts.dir file, which results in a heap overflow.
ModificadaAlta (8.5)5.6%—Ubuntu LinuxX.org LibxfontXfree86 Project X11r6Rpath Linux+56/4/200716/6/2026
Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow.
ModificadaAlta (10)5.9%—GNU Privacy GuardGpg4winRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+57/12/200616/6/2026
A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory.
ModificadaMedia (5)2.3%—Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+2931/12/200516/6/2026
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
ModificadaMedia (5)3.4%—Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+2931/12/200516/6/2026
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
ModificadaAlta (10)3.8%—Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+2931/12/200516/6/2026
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
ModificadaBaja (2.6)2.9%—GNU TARRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Linux Advanced Workstation31/12/200516/6/2026
The original patch for a GNU tar directory traversal vulnerability (CVE-2002-0399) in Red Hat Enterprise Linux 3 and 2.1 uses an "incorrect optimization" that allows user-assisted attackers to overwrite arbitrary files via a crafted tar file, probably involving "/../" sequences with a leading "/".
ModificadaAlta (7.5)2.0%—Redhat SysreportRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Linux Advanced Workstation13/6/200516/6/2026
sysreport 1.3.15 and earlier includes contents of the up2date file in a report, which leaks the password for a proxy server in plaintext and allows local users to gain privileges.
ModificadaMedia (4.6)0.51%—Redhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Linux Advanced Workstation4/5/200516/6/2026
Stack-based buffer overflow in the ieee_putascii function for nasm 0.98 and earlier allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2004-1287.
ModificadaMedia (5)3.1%—LogwatchRedhat Enterprise LinuxRedhat Linux Advanced Workstation2/5/200516/6/2026
The secure script in LogWatch before 2.6-2 allows attackers to prevent LogWatch from detecting malicious activity via certain strings in the secure file that are later used as part of a regular expression, which causes the parser to crash, aka "logwatch log processing regular expression DoS."
ModificadaMedia (4.6)0.38%—Debian LinuxKDERedhat Enterprise LinuxRedhat Enterprise Linux Desktop+12/5/200516/6/2026
The KDE screen saver in KDE before 3.0.5 does not properly check the return value from a certain function call, which allows attackers with physical access to cause a crash and access the desktop session.
ModificadaBaja (3.7)0.66%—GNU GzipFreebsdGentoo LinuxRedhat Enterprise Linux+92/5/200516/6/2026
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
ModificadaAlta (7.5)3.0%—Ascii PtexCstex CstetexEasy Software Products CupsGnome Gpdf+1827/4/200516/6/2026
The patch for integer overflow vulnerabilities in Xpdf 2.0 and 3.0 (CVE-2004-0888) is incomplete for 64-bit architectures on certain Linux distributions such as Red Hat, which could leave Xpdf users exposed to the original vulnerabilities.
ModificadaMedia (5)1.7%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."
ModificadaAlta (7.5)3.1%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaMedia (5)2.5%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
ModificadaMedia (5)1.7%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.
ModificadaMedia (5)1.4%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."
ModificadaMedia (5)1.7%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.
ModificadaMedia (5)1.7%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."
ModificadaAlta (7.5)1.6%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
ModificadaAlta (7.5)1.8%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
ModificadaAlta (7.5)1.6%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.