Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.23% | — | Celestialsoftware Absolutetelnet | 7/2/2026 | 17/6/2026 | AbsoluteTelnet 11.12 contains a denial of service vulnerability in the SSH2 username input field that allows local attackers to crash the application. Attackers can overwrite the username field with a 1000-byte buffer, causing the application to become unresponsive and terminate. | |
| Analizada | Media (6.7) | 0.24% | — | Celestialsoftware Absolutetelnet | 7/2/2026 | 17/6/2026 | AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license name field to trigger an application crash. | |
| Analizada | Media (6.7) | 0.24% | — | Celestialsoftware Absolutetelnet | 7/2/2026 | 17/6/2026 | AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license entry field to trigger an application crash. | |
| Aplazada | Media (4.6) | 0.42% | — | Mocha Telnet LiteAI | 29/1/2026 | 17/6/2026 | Mocha Telnet Lite for iOS 4.2 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the user configuration input. Attackers can overwrite the 'User' field with 350 bytes of repeated characters to trigger an application crash and prevent normal functionality. | |
| Modificada | Media (6.7) | 0.20% | — | Celestialsoftware Absolutetelnet | 15/1/2026 | 17/6/2026 | AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating username and error report fields. Attackers can trigger the crash by inserting 1000 characters into the username or email address fields, causing the application to become unresponsive. | |
| Modificada | Media (6.7) | 0.20% | — | Celestialsoftware Absolutetelnet | 15/1/2026 | 17/6/2026 | AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating DialUp connection and license name fields. Attackers can generate a 1000-character payload and paste it into specific input fields to trigger application crashes and force unexpected… | |
| Aplazada | Crítica (9.2) | 0.36% | — | Ncsa TelnetAI | 7/1/2026 | 17/6/2026 | An attacker with access to the system's internal network can cause a denial of service on the system by making two concurrent connections through the Telnet service. | |
| Modificada | Alta (7.5) | 2.1% | — | GNU InetutilsMIT Kerberos 5Debian LinuxNetkit-telnet Project Netkit-telnet | 30/8/2022 | 17/6/2026 | telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many… | |
| Modificada | Crítica (9.8) | 74% | — | Netkit Telnet Project Netkit TelnetFedoraproject FedoraDebian LinuxArista EOS+2 | 6/3/2020 | 17/6/2026 | utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions. | |
| Modificada | Crítica (9.8) | 4.6% | — | Mac-telnet Project Mac-telnet | 30/8/2016 | 17/6/2026 | Buffer overflow in the handle_packet function in mactelnet.c in the client in MAC-Telnet 0.4.3 and earlier allows remote TELNET servers to execute arbitrary code via a long string in an MT_CPTYPE_PASSSALT control packet. | |
| Modificada | Media (4.3) | 1.9% | — | Seattle LAB Software Slnet RF Telnet Server | 9/1/2008 | 16/6/2026 | SLnet.exe in SeattleLab SLNet RF Telnet Server 4.1.1.3758 and earlier allows user-assisted remote attackers to cause a denial of service (crash) via unspecified telnet options, which triggers a NULL pointer dereference. NOTE: the crash is not user-assisted when the server is running in debug mode. | |
| Modificada | Media (5) | 13% | — | Pragma Systems Pragma Telnetserver | 9/1/2008 | 16/6/2026 | telnetd.exe in Pragma TelnetServer 7.0.4.589 allows remote attackers to cause a denial of service (process crash and resource exhaustion) via a crafted TELOPT PRAGMA LOGON telnet option, which triggers a NULL pointer dereference. | |
| Modificada | Media (4) | 1.2% | — | Telnet FTP Server | 3/12/2006 | 16/6/2026 | Sorin Chitu Telnet-FTP Server 1.0 allows remote authenticated users to cause a denial of service (crash) via consecutive RETR commands. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (4) | 1.3% | — | Telnet FTP Server | 3/12/2006 | 16/6/2026 | Directory traversal vulnerability in Sorin Chitu Telnet-FTP Server 1.0 allows remote authenticated users to list contents of arbitrary directories and download arbitrary files via a .. (dot dot) sequence in an FTP command argument, as demonstrated by RETR (GET) or STOR (PUT). NOTE: The provenance of this information… | |
| Modificada | Alta (7.8) | 3.2% | — | Furukawa Electric FitelnetFurukawa Electric Mucho-ev PK | 27/4/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in multiple FITELnet products, including FITELnet-F40, F80, F100, F120, F1000, and E20/E30, allow remote attackers to cause a denial of service via crafted DNS messages that trigger errors in (1) ProxyDNS or (2) PKI-Resolver, as demonstrated by the OUSPG PROTOS DNS test suite. | |
| Modificada | Media (5) | 2.8% | — | Telnetd | 20/6/2005 | 16/6/2026 | Multiple buffer overflows in the getterminaltype function in telnetd for Heimdal before 0.6.5 may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2005-0468 and CVE-2005-0469. | |
| Modificada | Media (5) | 17% | — | Microsoft Telnet ClientMIT Kerberos 5Sunos | 14/6/2005 | 16/6/2026 | Certain BSD-based Telnet clients, including those used on Solaris and SuSE Linux, allow remote malicious Telnet servers to read sensitive environment variables via the NEW-ENVIRON option with a SEND ENV_USERVAR command. | |
| Modificada | Media (4.3) | 1.2% | — | Pragma Systems Pragma Telnetserver | 7/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Pragma Systems Telnetserver 6.0 allows remote attackers to inject arbitrary web script or HTML, and hide activities in log files, via a "<!--" (HTML comment) in a session. | |
| Modificada | Alta (7.5) | 1.9% | — | Hp-uxAIHP RemshdAIHP TelnetAI | 31/5/2005 | 16/6/2026 | Unknown vulnerability in HP-UX trusted systems B.11.00 through B.11.23 allows remote attackers to gain unauthorized access, possibly involving remshd and/or telnet -t. | |
| Modificada | Alta (10) | 60% | — | Goodtech Systems Goodtech Telnet Server | 2/5/2005 | 16/6/2026 | Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions before 5.0.7, allows remote attackers to execute arbitrary code via a long string to port 2380. | |
| Modificada | Alta (7.5) | 27% | — | Ncsa Telnet | 2/5/2005 | 16/6/2026 | Heap-based buffer overflow in the env_opt_add function in telnet.c for various BSD-based Telnet clients allows remote attackers to execute arbitrary code via responses that contain a large number of characters that require escaping, which consumers more memory than allocated. | |
| Modificada | Alta (7.5) | 8.9% | — | Ncsa Telnet | 2/5/2005 | 16/6/2026 | Buffer overflow in the slc_add_reply function in various BSD-based Telnet clients, when handling LINEMODE suboptions, allows remote attackers to execute arbitrary code via a reply with a large number of Set Local Character (SLC) commands. | |
| Modificada | Alta (7.5) | 1.6% | — | BAY Technical Associates Rpc3 Telnet | 31/3/2005 | 16/6/2026 | Bay Technical Associates RPC-3 Telnet Host 3.05 allows remote attackers to bypass authentication by pressing the escape and enter keys at the username prompt. | |
| Modificada | Alta (7.5) | 5.5% | — | TelnetdTelnetd-ssl | 23/12/2004 | 16/6/2026 | Format string vulnerability in telnetd-ssl 0.17 and earlier allows remote attackers to execute arbitrary code. | |
| Modificada | Alta (10) | 4.5% | — | Linux NetkitSsltelnetd Secure Telnet | 6/8/2004 | 16/6/2026 | Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code. |