Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
656 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.30% | — | Apple MAC OS XApple MAC OS X Server | 13/4/2017 | 16/6/2026 | Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges. | |
| Modificada | Alta (7.8) | 2.1% | — | Apple MAC OS XApple MAC OS X Server | 13/4/2017 | 16/6/2026 | Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image. | |
| Modificada | Media (5.3) | 1.8% | — | Apple MAC OS X Server | 24/3/2016 | 17/6/2026 | Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.0% | — | Apple MAC OS X Server | 24/3/2016 | 17/6/2026 | Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors. | |
| Modificada | Media (5.3) | 1.8% | — | Apple MAC OS X Server | 24/3/2016 | 17/6/2026 | Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtain sensitive configuration information via an HTTP request. | |
| Modificada | Media (5.3) | 1.7% | — | Apple MAC OS X Server | 24/3/2016 | 17/6/2026 | The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading backup data that lacks intended restrictions. | |
| Modificada | Media (5) | 2.0% | — | Apple MAC OS X Server | 23/10/2015 | 17/6/2026 | The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass intended access restrictions via unknown vectors. | |
| Modificada | Alta (10) | 2.0% | — | Apple MAC OS X Server | 18/9/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document. | |
| Modificada | Alta (7.1) | 26% | — | ISC BindApple MAC OS X Server | 5/9/2015 | 17/6/2026 | openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response. | |
| Modificada | Alta (7.8) | 34% | — | ISC BindApple MAC OS X Server | 5/9/2015 | 17/6/2026 | buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone. | |
| Modificada | Media (4.3) | 16% | — | Canonical Ubuntu LinuxApache Http ServerApple XcodeApple MAC OS X+1 | 20/7/2015 | 17/6/2026 | The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic… | |
| Modificada | Media (5) | 13% | — | Apache Http ServerApple MAC OS XApple MAC OS X ServerOracle Linux+1 | 20/7/2015 | 17/6/2026 | The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the… | |
| Modificada | Media (4.3) | 8.4% | — | Canonical Ubuntu LinuxDebian LinuxApple MAC OS X ServerPostgresql | 28/5/2015 | 17/6/2026 | Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence. | |
| Modificada | Media (5) | 16% | — | Apache Http ServerCanonical Ubuntu LinuxApple MAC OS XApple MAC OS X Server+1 | 8/3/2015 | 17/6/2026 | The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function. | |
| Modificada | Media (6.8) | 3.6% | — | Apple MAC OS XApple MAC OS X Server | 19/9/2014 | 17/6/2026 | Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIDI file. | |
| Modificada | Media (6.8) | 4.2% | — | Apple MAC OS XApple MAC OS X Server | 19/9/2014 | 17/6/2026 | QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding. | |
| Modificada | Alta (7.5) | 1.9% | — | Apple MAC OS XApple MAC OS X Server | 1/7/2014 | 17/6/2026 | Array index error in Dock in Apple OS X before 10.9.4 allows attackers to execute arbitrary code or cause a denial of service (incorrect function-pointer dereference and application crash) by leveraging access to a sandboxed application for sending a message. | |
| Modificada | Media (6.8) | 2.2% | — | Apple MAC OS XApple MAC OS X Server | 1/7/2014 | 17/6/2026 | The byte-swapping implementation in copyfile in Apple OS X before 10.9.4 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds memory access and application crash) via a crafted AppleDouble file in a ZIP archive. | |
| Modificada | Media (4.3) | 1.9% | — | Apple Iphone OSApple MAC OS XApple MAC OS X ServerApple Tvos | 23/4/2014 | 17/6/2026 | CFNetwork in Apple iOS before 7.1.1, Apple OS X through 10.9.2, and Apple TV before 6.1.1 does not ensure that a Set-Cookie HTTP header is complete before interpreting the header's value, which allows remote attackers to bypass intended access restrictions by triggering the closing of a TCP connection during… | |
| Modificada | Media (5) | 53% | — | Apache Http ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUSRedhat Enterprise Linux Server+11 | 15/4/2014 | 16/6/2026 | The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such." | |
| Modificada | Media (4.6) | 0.48% | — | Apple MAC OS XApple MAC OS X ServerPostgresql | 31/3/2014 | 17/6/2026 | The "make check" command for the test suites in PostgreSQL 9.3.3 and earlier does not properly invoke initdb to specify the authentication requirements for a database cluster to be used for the tests, which allows local users to gain privileges by leveraging access to this cluster. | |
| Modificada | Media (6.8) | 2.2% | — | Apple SafariApple WebkitApple MAC OS XApple MAC OS X Server | 27/2/2014 | 17/6/2026 | WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1269. | |
| Modificada | Media (6.8) | 2.2% | — | Apple SafariApple WebkitApple MAC OS XApple MAC OS X Server | 27/2/2014 | 17/6/2026 | WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1268 and CVE-2014-1270. | |
| Modificada | Media (6.8) | 1.9% | — | Apple SafariApple WebkitApple MAC OS XApple MAC OS X Server | 27/2/2014 | 17/6/2026 | WebKit, as used in Apple Safari before 6.1.2 and 7.x before 7.0.2, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than CVE-2014-1269 and CVE-2014-1270. | |
| Modificada | Media (4.6) | 0.34% | — | Apple MAC OS XApple MAC OS X Server | 27/2/2014 | 17/6/2026 | The systemsetup program in the Date and Time subsystem in Apple OS X before 10.9.2 allows local users to bypass intended access restrictions by changing the current time on the system clock. |