Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

656 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.30%—Apple MAC OS XApple MAC OS X Server13/4/201716/6/2026
Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.
ModificadaAlta (7.8)2.1%—Apple MAC OS XApple MAC OS X Server13/4/201716/6/2026
Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image.
ModificadaMedia (5.3)1.8%—Apple MAC OS X Server24/3/201617/6/2026
Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.
ModificadaAlta (7.5)2.0%—Apple MAC OS X Server24/3/201617/6/2026
Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
ModificadaMedia (5.3)1.8%—Apple MAC OS X Server24/3/201617/6/2026
Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtain sensitive configuration information via an HTTP request.
ModificadaMedia (5.3)1.7%—Apple MAC OS X Server24/3/201617/6/2026
The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading backup data that lacks intended restrictions.
ModificadaMedia (5)2.0%—Apple MAC OS X Server23/10/201517/6/2026
The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass intended access restrictions via unknown vectors.
ModificadaAlta (10)2.0%—Apple MAC OS X Server18/9/201517/6/2026
Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document.
ModificadaAlta (7.1)26%—ISC BindApple MAC OS X Server5/9/201517/6/2026
openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.
ModificadaAlta (7.8)34%—ISC BindApple MAC OS X Server5/9/201517/6/2026
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
ModificadaMedia (4.3)16%—Canonical Ubuntu LinuxApache Http ServerApple XcodeApple MAC OS X+120/7/201517/6/2026
The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic…
ModificadaMedia (5)13%—Apache Http ServerApple MAC OS XApple MAC OS X ServerOracle Linux+120/7/201517/6/2026
The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the…
ModificadaMedia (4.3)8.4%—Canonical Ubuntu LinuxDebian LinuxApple MAC OS X ServerPostgresql28/5/201517/6/2026
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
ModificadaMedia (5)16%—Apache Http ServerCanonical Ubuntu LinuxApple MAC OS XApple MAC OS X Server+18/3/201517/6/2026
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.
ModificadaMedia (6.8)3.6%—Apple MAC OS XApple MAC OS X Server19/9/201417/6/2026
Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIDI file.
ModificadaMedia (6.8)4.2%—Apple MAC OS XApple MAC OS X Server19/9/201417/6/2026
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.
ModificadaAlta (7.5)1.9%—Apple MAC OS XApple MAC OS X Server1/7/201417/6/2026
Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandboxed application for sending a message.
ModificadaMedia (6.8)2.2%—Apple MAC OS XApple MAC OS X Server1/7/201417/6/2026
The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archive.
ModificadaMedia (4.3)1.9%—Apple Iphone OSApple MAC OS XApple MAC OS X ServerApple Tvos23/4/201417/6/2026
CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during…
ModificadaMedia (5)53%—Apache Http ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+1115/4/201416/6/2026
The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."
ModificadaMedia (4.6)0.48%—Apple MAC OS XApple MAC OS X ServerPostgresql31/3/201417/6/2026
The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster.
ModificadaMedia (6.8)2.2%—Apple SafariApple WebkitApple MAC OS XApple MAC OS X Server27/2/201417/6/2026
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269.
ModificadaMedia (6.8)2.2%—Apple SafariApple WebkitApple MAC OS XApple MAC OS X Server27/2/201417/6/2026
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1270.
ModificadaMedia (6.8)1.9%—Apple SafariApple WebkitApple MAC OS XApple MAC OS X Server27/2/201417/6/2026
WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1269 and CVE-2014-1270.
ModificadaMedia (4.6)0.34%—Apple MAC OS XApple MAC OS X Server27/2/201417/6/2026
The systemsetup program in the Date and Time subsystem in Apple OS X before 10.9.2 allows local users to bypass intended access restrictions by changing the current time on the system clock.