Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

667 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.30%—Apple MAC OS XApple MAC OS X Server13/4/201716/6/2026
Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows local users to obtain system privileges.
ModificadaAlta (7.8)2.1%—Apple MAC OS XApple MAC OS X Server13/4/201716/6/2026
Buffer overflow in ImageIO in Apple Mac OS X 10.6 through 10.6.3 and Mac OS X Server 10.6 through 10.6.3 allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a crafted image.
ModificadaAlta (7.5)2.0%—Apple OS X Server25/9/201617/6/2026
ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
ModificadaCrítica (9.1)1.3%—Apple MAC OS XApple OS X Server25/9/201617/6/2026
The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP…
ModificadaMedia (5.3)1.8%—Apple MAC OS X Server24/3/201617/6/2026
Wiki Server in Apple OS X Server before 5.1 allows remote attackers to obtain sensitive information from Wiki pages via unspecified vectors.
ModificadaAlta (7.5)2.0%—Apple MAC OS X Server24/3/201617/6/2026
Web Server in Apple OS X Server before 5.1 supports the RC4 algorithm, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
ModificadaMedia (5.3)1.8%—Apple MAC OS X Server24/3/201617/6/2026
Web Server in Apple OS X Server before 5.1 does not properly restrict access to .DS_Store and .htaccess files, which allows remote attackers to obtain sensitive configuration information via an HTTP request.
ModificadaMedia (5.3)1.7%—Apple MAC OS X Server24/3/201617/6/2026
The Time Machine server in Server App in Apple OS X Server before 5.1 does not notify the user about ignored permissions during a backup, which makes it easier for remote attackers to obtain sensitive information in opportunistic circumstances by reading backup data that lacks intended restrictions.
ModificadaMedia (5)2.0%—Apple MAC OS X Server23/10/201517/6/2026
The Web Service component in Apple OS X Server before 5.0.15 omits an unspecified HTTP header configuration, which allows remote attackers to bypass intended access restrictions via unknown vectors.
ModificadaAlta (10)2.0%—Apple MAC OS X Server18/9/201517/6/2026
Multiple unspecified vulnerabilities in Twisted in Wiki Server in Apple OS X Server before 5.0.3 allow attackers to have an unknown impact via an XML document.
ModificadaAlta (7.1)26%—ISC BindApple MAC OS X Server5/9/201517/6/2026
openpgpkey_61.c in named in ISC BIND 9.9.7 before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via a crafted DNS response.
ModificadaAlta (7.8)34%—ISC BindApple MAC OS X Server5/9/201517/6/2026
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.
ModificadaMedia (4.3)16%—Canonical Ubuntu LinuxApache Http ServerApple XcodeApple MAC OS X+120/7/201517/6/2026
The ap_some_auth_required function in server/request.c in the Apache HTTP Server 2.4.x before 2.4.14 does not consider that a Require directive may be associated with an authorization setting rather than an authentication setting, which allows remote attackers to bypass intended access restrictions in opportunistic…
ModificadaMedia (5)13%—Apache Http ServerApple MAC OS XApple MAC OS X ServerOracle Linux+120/7/201517/6/2026
The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the…
ModificadaMedia (4.3)8.4%—Canonical Ubuntu LinuxDebian LinuxApple MAC OS X ServerPostgresql28/5/201517/6/2026
Double free vulnerability in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 allows remote attackers to cause a denial of service (crash) by closing an SSL session at a time when the authentication timeout will expire during the session shutdown sequence.
ModificadaMedia (5)1.8%—Apple OS X Server28/4/201517/6/2026
Wiki Server in Apple OS X Server before 4.1 allows remote attackers to bypass intended restrictions on Activity and People pages by connecting from an iPad client.
ModificadaMedia (5)2.0%—Apple OS X Server28/4/201517/6/2026
The Firewall component in Apple OS X Server before 4.1 uses an incorrect pathname in configuration files, which allows remote attackers to bypass network-access restrictions by sending packets for which custom-rule blocking was intended.
ModificadaMedia (5)16%—Apache Http ServerCanonical Ubuntu LinuxApple MAC OS XApple MAC OS X Server+18/3/201517/6/2026
The lua_websocket_read function in lua_request.c in the mod_lua module in the Apache HTTP Server through 2.4.12 allows remote attackers to cause a denial of service (child-process crash) by sending a crafted WebSocket Ping frame after a Lua script has called the wsupgrade function.
ModificadaMedia (5)11%—Apple MAC OS XApple OS X ServerApache Http ServerCanonical Ubuntu Linux15/12/201417/6/2026
The handle_headers function in mod_proxy_fcgi.c in the mod_proxy_fcgi module in the Apache HTTP Server 2.4.10 allows remote FastCGI servers to cause a denial of service (buffer over-read and daemon crash) via long response headers.
ModificadaBaja (1.9)0.34%—Apple OS X Server18/10/201417/6/2026
Profile Manager in Apple OS X Server before 4.0 allows local users to discover cleartext passwords by reading a file after a (1) profile setup or (2) profile edit occurs.
ModificadaBaja (2.1)1.4%—Apple OS X Server18/10/201417/6/2026
Mail Service in Apple OS X Server before 4.0 does not enforce SACL changes until after a service restart, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a change made by an administrator.
ModificadaAlta (7.5)2.4%—Apple OS X Server19/9/201417/6/2026
SQL injection vulnerability in Wiki Server in CoreCollaboration in Apple OS X Server before 2.2.3 and 3.x before 3.2.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.1)1.4%—Apple OS X Server19/9/201417/6/2026
Cross-site scripting (XSS) vulnerability in Xcode Server in CoreCollaboration in Apple OS X Server before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (6.8)3.6%—Apple MAC OS XApple MAC OS X Server19/9/201417/6/2026
Buffer overflow in QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MIDI file.
ModificadaMedia (6.8)4.2%—Apple MAC OS XApple MAC OS X Server19/9/201417/6/2026
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.