Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2991▼ 71 respecto a la semana anterior
Críticas / altas1367▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)458▼ 52 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 3.8% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." | |
| Modificada | Media (5) | 3.4% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference. | |
| Modificada | Media (5) | 2.3% | — | Easy Software Products CupsKdegraphicsKDE KofficeKDE Kpdf+29 | 31/12/2005 | 16/6/2026 | The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows. | |
| Modificada | Baja (3.7) | 0.66% | — | GNU GzipFreebsdGentoo LinuxRedhat Enterprise Linux+9 | 2/5/2005 | 16/6/2026 | Race condition in gzip 1.2.4, 1.3.3, and earlier, when decompressing a gzipped file, allows local users to modify permissions of arbitrary files via a hard link attack on a file while it is being decompressed, whose permissions are changed by gzip after the decompression is complete. | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by triggering a null dereference. | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "a corrupt section header." | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service via "use of already freed memory." | |
| Modificada | Alta (7.5) | 1.6% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Multiple format string vulnerabilities in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. | |
| Modificada | Alta (7.5) | 1.6% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | fish.c in midnight commander allows remote attackers to execute arbitrary programs via "insecure filename quoting," possibly using shell metacharacters. | |
| Modificada | Alta (7.5) | 1.8% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Multiple buffer overflows in Midnight Commander (mc) 4.5.55 and earlier allow remote attackers to have an unknown impact. | |
| Modificada | Alta (7.5) | 3.1% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Buffer underflow in extfs.c in Midnight Commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code. | |
| Modificada | Media (5) | 1.4% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | direntry.c in Midnight Commander (mc) 4.5.55 and earlier allows attackers to cause a denial of service by "manipulating non-existing file handles." | |
| Modificada | Media (5) | 1.7% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service by causing mc to free unallocated memory. | |
| Modificada | Media (5) | 2.5% | — | Midnight CommanderDebian LinuxGentoo LinuxRedhat Enterprise Linux+4 | 14/4/2005 | 16/6/2026 | Midnight commander (mc) 4.5.55 and earlier allows remote attackers to cause a denial of service (infinite loop) via unknown attack vectors. | |
| Modificada | Alta (7.5) | 4.9% | — | Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+12 | 31/12/2004 | 16/6/2026 | Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file. | |
| Modificada | Media (5.1) | 3.4% | — | Enlightenment ImlibEnlightenment Imlib2ImagemagickSUN Java Desktop System+12 | 31/12/2004 | 16/6/2026 | Buffer overflow in the BMP loader in imlib2 before 1.1.2 allows remote attackers to execute arbitrary code via a specially-crafted BMP image, a different vulnerability than CVE-2004-0817. | |
| Modificada | Baja (2.1) | 0.36% | — | GNU A2psTurbolinux HomeTurbolinux ServerTurbolinux Workstation | 27/12/2004 | 16/6/2026 | The (1) fixps (aka fixps.in) and (2) psmandup (aka psmandup.in) scripts in a2ps before 4.13 allow local users to overwrite arbitrary files via a symlink attack on temporary files. | |
| Modificada | Alta (7.5) | 22% | — | Sendmail Advanced Message ServerSendmailSendmail PROSendmail Switch+10 | 6/10/2003 | 16/6/2026 | A "potential buffer overflow in ruleset parsing" for Sendmail 8.12.9, when using the nonstandard rulesets (1) recipient (2), final, or (3) mailer-specific envelope recipients, has unknown consequences. | |
| Modificada | Alta (10) | 66% | — | Sendmail Advanced Message ServerSendmailSendmail PROSendmail Switch+14 | 6/10/2003 | 16/6/2026 | The prescan function in Sendmail 8.12.9 allows remote attackers to execute arbitrary code via buffer overflow attacks, as demonstrated using the parseaddr function in parseaddr.c. | |
| Modificada | Alta (7.5) | 2.1% | — | Apple SafariKDE Konqueror EmbeddedKDERedhat Linux+2 | 16/6/2003 | 16/6/2026 | Konqueror Embedded and KDE 2.2.2 and earlier does not validate the Common Name (CN) field for X.509 Certificates, which could allow remote attackers to spoof certificates via a man-in-the-middle attack. |