Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2661▼ 437 respecto a la semana anterior
Críticas / altas1284▼ 85 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.19% | — | Tunnelblick | 5/5/2026 | 25/7/2026 | Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local user can read arbitrary root-owned files by exploiting a symlink following vulnerability in tunnelblick-helper, reachable through the world-accessible tunnelblickd Unix socket. The socket is… | |
| Aplazada | Alta (8.1) | 0.18% | — | TunnelblickAI | 5/7/2025 | 17/6/2026 | Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upon the next boot) by dragging a crafted Tunnelblick.app file into /Applications. | |
| Modificada | Media (4.4) | 0.15% | — | Google Tunnelblick | 26/8/2012 | 16/6/2026 | Tunnelblick 3.3beta20 and earlier allows local users to gain privileges by using a crafted Info.plist file to control the gOkIfNotSecure value. | |
| Modificada | Baja (1.2) | 0.19% | — | Google Tunnelblick | 26/8/2012 | 16/6/2026 | The errorExitIfAttackViaString function in Tunnelblick 3.3beta20 and earlier allows local users to delete arbitrary files by constructing a (1) symlink or (2) hard link, a different vulnerability than CVE-2012-3485. | |
| Modificada | Baja (1.2) | 0.12% | — | Google Tunnelblick | 26/8/2012 | 16/6/2026 | Race condition in Tunnelblick 3.3beta20 and earlier allows local users to kill unintended processes by waiting for a specific PID value to be assigned to a target process. | |
| Modificada | Media (6.9) | 0.28% | — | Google Tunnelblick | 26/8/2012 | 16/6/2026 | Tunnelblick 3.3beta20 and earlier allows local users to gain privileges via an OpenVPN configuration file that specifies execution of a script upon occurrence of an OpenVPN event. | |
| Modificada | Alta (7.2) | 3.8% | — | Google Tunnelblick | 26/8/2012 | 16/6/2026 | Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname or (2) executable file pathname, which allows local users to gain privileges via an execl system call. | |
| Modificada | Alta (7.2) | 0.18% | — | Google Tunnelblick | 26/8/2012 | 16/6/2026 | Tunnelblick 3.3beta20 and earlier relies on a test for specific ownership and permissions to determine whether a program can be safely executed, which allows local users to bypass intended access restrictions and gain privileges via a (1) user-mountable image or (2) network share. | |
| Modificada | Media (6.2) | 0.26% | — | Google Tunnelblick | 26/8/2012 | 16/6/2026 | Race condition in the runScript function in Tunnelblick 3.3beta20 and earlier allows local users to gain privileges by replacing a script file. |