Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 2.1% | — | Netkit | 14/7/2023 | 17/6/2026 | netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778. | |
| Modificada | Alta (7.5) | 2.1% | — | GNU InetutilsMIT Kerberos 5Debian LinuxNetkit-telnet Project Netkit-telnet | 30/8/2022 | 17/6/2026 | telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many… | |
| Modificada | Crítica (9.8) | 74% | — | Netkit Telnet Project Netkit TelnetFedoraproject FedoraDebian LinuxArista EOS+2 | 6/3/2020 | 17/6/2026 | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions. | |
| Modificada | Alta (7.4) | 1.8% | — | NetkitDebian Linux | 31/1/2019 | 17/6/2026 | An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server (or Man-in-The-Middle attacker) can overwrite arbitrary files in a… | |
| Modificada | Media (5.9) | 2.1% | — | NetkitDebian LinuxFedoraproject Fedora | 31/1/2019 | 17/6/2026 | In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685. | |
| Modificada | Alta (10) | 1.7% | — | Netkit-ftp Netkit FTP | 6/12/2007 | 16/6/2026 | Double free vulnerability in the getreply function in ftp.c in netkit ftp (netkit-ftp) 0.17 20040614 and later allows remote FTP servers to cause a denial of service (application crash) and possibly have unspecified other impact via some types of FTP protocol behavior. NOTE: the netkit-ftpd issue is covered by… | |
| Modificada | Alta (9.3) | 2.5% | — | Netkit-ftp Netkit FTP | 6/12/2007 | 16/6/2026 | The dataconn function in ftpd.c in netkit ftpd (netkit-ftpd) 0.17, when certain modifications to support SSL have been introduced, calls fclose on an uninitialized file stream, which allows remote attackers to cause a denial of service (daemon crash) and possibly have unspecified other impact via some types of FTP… | |
| Modificada | Media (6.5) | 2.1% | — | Netkit | 21/11/2006 | 16/6/2026 | ftpd in Linux Netkit (linux-ftpd) 0.17, and possibly other versions, does not check the return status of certain seteuid, setgid, and setuid calls, which might allow remote authenticated users to gain privileges if these calls fail in cases such as PAM failures or resource limits, a different vulnerability than… | |
| Modificada | Media (6.2) | 0.36% | — | Linux NetkitLinux-vserverLinux Kernel | 7/3/2005 | 16/6/2026 | Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores. | |
| Modificada | Media (5) | 2.6% | — | Debian Netkit | 3/11/2004 | 16/6/2026 | telnetd for netkit 0.17 and earlier, and possibly other versions, on Debian GNU/Linux allows remote attackers to cause a denial of service (free of an invalid pointer), a different vulnerability than CVE-2001-0554. | |
| Modificada | Alta (10) | 4.5% | — | Linux NetkitSsltelnetd Secure Telnet | 6/8/2004 | 16/6/2026 | Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (10) | 39% | — | MIT KerberosMIT Kerberos 5Linux NetkitSGI Irix+7 | 14/8/2001 | 16/6/2026 | Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function. | |
| Modificada | Alta (10) | 3.1% | — | Debian NetkitIBM AIXNEC ASL UX 4800NEC Ews-ux V+1 | 27/1/1997 | 16/6/2026 | Talkd, when given corrupt DNS information, can be used to execute arbitrary commands with root privileges. |