Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
–

7 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)20%—Point-to-point Protocol Project Point-to-point ProtocolWago PFC FirmwareDebian LinuxCanonical Ubuntu Linux3/2/202017/6/2026
eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname buffer overflow in the eap_request and eap_response functions.
ModificadaCrítica (9.8)1.9%—Point-to-point Protocol Project Point-to-point ProtocolCanonical Ubuntu Linux14/6/201817/6/2026
Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the…
ModificadaMedia (4.3)5.4%—Canonical Ubuntu LinuxDebian LinuxPoint-to-point Protocol Project Point-to-point Protocol24/4/201517/6/2026
Buffer overflow in the rc_mksid function in plugins/radius/util.c in Paul's PPP Package (ppp) 2.4.6 and earlier, when the PID for pppd is greater than 65535, allows remote attackers to cause a denial of service (crash) via a start accounting message to the RADIUS server.
ModificadaAlta (7.5)3.5%—Point-to-point Protocol Project Point-to-point Protocol15/11/201417/6/2026
Integer overflow in the getword function in options.c in pppd in Paul's PPP Package (ppp) before 2.4.7 allows attackers to "access privileged options" via a long word in an options file, which triggers a heap-based buffer overflow that "[corrupts] security-relevant variables."
ModificadaAlta (7.2)0.40%—Point-to-point Protocol Project Point-to-point Protocol5/7/200616/6/2026
The winbind plugin in pppd for ppp 2.4.4 and earlier does not check the return code from the setuid function call, which might allow local users to gain privileges by causing setuid to fail, such as exceeding PAM limits for the maximum number of user processes, which prevents the winbind NTLM authentication helper…
ModificadaAlta (7.5)1.9%—Jelsoft VbulletinPoint-to-point Protocol Project Point-to-point Protocol31/12/200416/6/2026
SQL injection vulnerability in the Authorize.net callback code (subscriptions/authorize.php) in Jelsoft vBulletin 3.0 through 3.0.3 allows remote attackers to execute arbitrary SQL statements via the x_invoice_num parameter. NOTE: this issue might be related to CVE-2006-4267.
ModificadaMedia (6.9)0.66%—Freebsd Point-to-point Protocol Daemon12/8/200216/6/2026
BSD pppd allows local users to change the permissions of arbitrary files via a symlink attack on a file that is specified as a tty device.