Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.1% | — | Caldera Openlinux ServerCaldera Openlinux WorkstationCaldera OpenserverSCO Unixware | 20/10/2003 | 16/6/2026 | Docview before 1.1-18 in Caldera OpenLinux 3.1.1, SCO Linux 4.0, OpenServer 5.0.7, configures the Apache web server in a way that allows remote attackers to read arbitrary publicly readable files via a certain URL, possibly related to rewrite rules. | |
| Modificada | Baja (2.6) | 22% | — | Info-zip UnzipSCO Openlinux ServerSCO Openlinux Workstation | 16/6/2003 | 16/6/2026 | Directory traversal vulnerability in UnZip 5.50 allows attackers to overwrite arbitrary files via invalid characters between two . (dot) characters, which are filtered and result in a ".." sequence. | |
| Modificada | Media (5) | 2.2% | — | Caldera OpenlinuxSCO OpenserverSUN SolarisSunos | 28/10/2002 | 16/6/2026 | The getdbm procedure in ypxfrd allows local users to read arbitrary files, and remote attackers to read databases outside /var/yp, via a directory traversal and symlink attack on the domain and map arguments. | |
| Modificada | Media (5) | 6.9% | — | Caldera Openlinux ServerCaldera Openlinux WorkstationRedhat Pre-execution EnvironmentHP Secure OS | 4/10/2002 | 16/6/2026 | Preboot eXecution Environment (PXE) server allows remote attackers to cause a denial of service (crash) via certain DHCP packets from Voice-Over-IP (VOIP) phones. | |
| Modificada | Media (4.6) | 0.33% | — | Caldera Openlinux ServerCaldera Openlinux Workstation | 12/8/2002 | 16/6/2026 | startkde in KDE for Caldera OpenLinux 2.3 through 3.1.1 sets the LD_LIBRARY_PATH environment variable to include the current working directory, which could allow local users to gain privileges of other users running startkde via Trojan horse libraries. | |
| Modificada | Media (4.6) | 0.43% | — | Caldera Openlinux ServerCaldera Openlinux Workstation | 15/3/2002 | 16/6/2026 | Vulnerability in the MIT-SHM extension of the X server on Linux (XFree86) 4.2.1 and earlier allows local users to read and write arbitrary shared memory, possibly to cause a denial of service or gain privileges. | |
| Modificada | Alta (7.2) | 1.3% | — | Caldera Openlinux ServerCaldera Openlinux WorkstationDebian LinuxFreebsd+5 | 27/2/2002 | 16/6/2026 | Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution time, which causes at to free the same memory twice. | |
| Modificada | Alta (7.5) | 3.0% | — | Caldera Openlinux WorkstationRedhat Linux PowertoolsCaldera Openlinux EserverRedhat Linux+1 | 21/12/2001 | 16/6/2026 | Format string vulnerability in the default logging callback function _sasl_syslog in common.c in Cyrus SASL library (cyrus-sasl) may allow remote attackers to execute arbitrary commands. | |
| Modificada | Alta (10) | 2.3% | — | Caldera Openlinux | 6/12/2001 | 16/6/2026 | A configuration error in the libdb1 package in OpenLinux 3.1 uses insecure versions of the snprintf and vsnprintf functions, which could allow local or remote users to exploit those functions with a buffer overflow. | |
| Modificada | Media (5) | 3.1% | — | Caldera Openlinux ServerCaldera Openlinux WorkstationCaldera OpenlinuxCaldera Openlinux Edesktop+3 | 6/12/2001 | 16/6/2026 | Linux kernel 2.0, 2.2 and 2.4 with syncookies enabled allows remote attackers to bypass firewall rules by brute force guessing the cookie. | |
| Modificada | Alta (7.5) | 2.1% | — | Caldera Openlinux EdesktopCaldera Openlinux Eserver | 31/8/2001 | 16/6/2026 | telnet daemon (telnetd) from the Linux netkit package before netkit-telnet-0.16 allows remote attackers to bypass authentication when telnetd is running with the -L command line option. | |
| Modificada | Baja (2.6) | 1.2% | — | U WINCaldera Openlinux | 21/7/2001 | 16/6/2026 | Some telnet clients allow remote telnet servers to request environment variables from the client that may contain sensitive information, or remote web servers to obtain the information via a telnet: URL. | |
| Modificada | Alta (7.5) | 2.0% | — | Caldera Openlinux ServerImmunixMandrakesoft Mandrake Single Network FirewallSquid WEB Proxy+4 | 18/7/2001 | 16/6/2026 | Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning. | |
| Modificada | Alta (7.5) | 2.4% | — | Caldera Openlinux ServerCaldera Openlinux Workstation | 17/7/2001 | 16/6/2026 | docview before 1.0-15 allows remote attackers to execute arbitrary commands via shell metacharacters that are processed when converting a man page to a web page. | |
| Modificada | Baja (2.1) | 0.36% | — | Conectiva LinuxCaldera Openlinux EdesktopMandrakesoft Mandrake LinuxMandrakesoft Mandrake Linux Corporate Server+1 | 26/3/2001 | 16/6/2026 | kdesu program in KDE2 (KDE before 2.2.0-6) does not properly verify the owner of a UNIX socket that is used to send a password, which allows local users to steal passwords and gain privileges. | |
| Modificada | Alta (10) | 5.2% | — | Caldera Openlinux DesktopCaldera Openlinux EdesktopCaldera Openlinux Eserver | 26/3/2001 | 16/6/2026 | Format string vulnerability in the error logging code of DHCP server and client in Caldera Linux allows remote attackers to execute arbitrary commands. | |
| Modificada | Baja (1.2) | 0.34% | — | Caldera Openlinux DesktopImmunixCaldera Openlinux EdesktopCaldera Openlinux Eserver+3 | 12/3/2001 | 16/6/2026 | inn 2.2.3 allows local users to overwrite arbitrary files via a symlink attack in some configurations. | |
| Modificada | Alta (7.2) | 1.4% | — | ImmunixConectiva LinuxCaldera OpenlinuxCaldera Openlinux Edesktop+5 | 9/1/2001 | 16/6/2026 | Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when processing << redirects (aka here-documents or in-here documents), which allows local users to overwrite files of other users via a symlink attack. | |
| Modificada | Alta (10) | 79% | — | Caldera Openlinux EbuilderCaldera OpenlinuxCaldera Openlinux EdesktopCaldera Openlinux Eserver+2 | 19/12/2000 | 23/9/2026 | Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary commands. | |
| Modificada | Alta (10) | 16% | — | Caldera Openlinux EbuilderImmunixConectiva LinuxSGI Irix+12 | 14/11/2000 | 16/6/2026 | Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which allows local attackers to execute arbitrary commands via functions such as gettext and catopen. | |
| Modificada | Alta (7.2) | 0.36% | — | Caldera Openlinux | 12/7/2000 | 16/6/2026 | Vulnerability in Caldera rmt command in the dump package 0.4b4 allows a local user to gain root privileges. | |
| Modificada | Media (5) | 9.9% | — | Caldera Openlinux DesktopCaldera Openlinux EbuilderCaldera Openlinux EdesktopCaldera Openlinux Eserver+2 | 4/7/2000 | 16/6/2026 | BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial of service via an invite to a channel whose name includes special formatting characters. | |
| Modificada | Alta (7.2) | 0.40% | — | Caldera OpenlinuxMandrakesoft Mandrake LinuxRedhat Linux | 3/7/2000 | 16/6/2026 | makewhatis in Linux man package allows local users to overwrite files via a symlink attack. | |
| Modificada | Alta (7.2) | 1.2% | — | Caldera OpenlinuxKDE | 31/5/2000 | 16/6/2026 | The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitrary files. | |
| Modificada | Alta (10) | 18% | — | Gnome GDMCaldera OpenlinuxSuse Linux | 24/5/2000 | 16/6/2026 | Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request. |