Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)3.4%—Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+2931/12/200516/6/2026
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
ModificadaAlta (10)3.8%—Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+2931/12/200516/6/2026
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins."
ModificadaMedia (5)2.3%—Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+2931/12/200516/6/2026
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
ModificadaBaja (3.7)0.66%—GNU GzipFreebsdGentoo LinuxRedhat Enterprise Linux+92/5/200516/6/2026
Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete.
ModificadaMedia (5)1.7%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference.
ModificadaMedia (5)1.7%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header."
ModificadaMedia (5)1.7%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory."
ModificadaAlta (7.5)1.8%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
ModificadaAlta (7.5)3.1%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code.
ModificadaMedia (5)1.4%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles."
ModificadaAlta (7.5)1.6%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact.
ModificadaMedia (5)1.7%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory.
ModificadaAlta (7.5)1.6%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters.
ModificadaMedia (5)2.5%—Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+414/4/200516/6/2026
Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors.
ModificadaBaja (2.1)0.81%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+410/1/200516/6/2026
The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.
ModificadaAlta (7.2)0.51%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+410/1/200516/6/2026
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly handle a failed call to the mmap function, which causes an incorrect mapped image and may allow local users to execute arbitrary code.
ModificadaAlta (7.2)0.56%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+410/1/200516/6/2026
The binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, may create an interpreter name string that is not NULL terminated, which could cause strings longer than PATH_MAX to be used, leading to buffer overflows that allow local users to cause a denial of service (hang) and…
ModificadaAlta (7.2)0.51%—Linux KernelRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Fedora Core+410/1/200516/6/2026
The load_elf_binary function in the binfmt_elf loader (binfmt_elf.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, does not properly check return values from calls to the kernel_read function, which may allow local users to modify sensitive memory in a setuid program and execute arbitrary code.
ModificadaAlta (7.5)4.9%—Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+1231/12/200416/6/2026
Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.
ModificadaMedia (5.1)3.4%—Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+1231/12/200416/6/2026
Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817.
ModificadaBaja (2.1)0.36%—GNU A2psTurbolinux HomeTurbolinux ServerTurbolinux Workstation27/12/200416/6/2026
The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files.
ModificadaMedia (5)17%—Apache Http ServerHP Secure WEB Server FOR Tru64Gentoo LinuxHp-ux+816/9/200416/6/2026
The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access.
ModificadaAlta (7.5)22%—Sendmail Advanced Message ServerSendmailSendmail PROSendmail Switch+106/10/200316/6/2026
A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences.
ModificadaAlta (10)66%—Sendmail Advanced Message ServerSendmailSendmail PROSendmail Switch+146/10/200316/6/2026
The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c.
ModificadaAlta (7.5)2.1%—Apple SafariKDE Konqueror EmbeddedKDERedhat Linux+216/6/200316/6/2026
Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack.