Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3047▲ 440 respecto a la semana anterior
Críticas / altas1452▲ 212 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)365▲ 151 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.7) | 0.27% | — | GNU Inetutils | 16/3/2026 | 17/6/2026 | telnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR. | |
| Analizada | Crítica (9.8) | 2.4% | — | GNU Inetutils | 13/3/2026 | 17/6/2026 | telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption handler because add_slc does not check whether the buffer is full. | |
| Modificada | Alta (7.8) | 0.20% | — | GNU Inetutils | 27/2/2026 | 17/6/2026 | telnetd in GNU inetutils through 2.7 allows privilege escalation that can be exploited by abusing systemd service credentials support added to the login(1) implementation of util-linux in release 2.40. This is related to client control over the CREDENTIALS_DIRECTORY environment variable, and requires an unprivileged… | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | GNU InetutilsDebian Linux | 21/1/2026 | 30/9/2026 | telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment variable. | |
| Modificada | Alta (7.8) | 0.41% | — | GNU Inetutils | 14/8/2023 | 17/6/2026 | GNU inetutils before 2.5 may allow privilege escalation because of unchecked return values of set*id() family functions in ftpd, rcp, rlogin, rsh, rshd, and uucpd. This is, for example, relevant if the setuid system call fails when a process is trying to drop privileges before letting an ordinary user control the… | |
| Modificada | Alta (7.5) | 2.1% | — | GNU InetutilsMIT Kerberos 5Debian LinuxNetkit-telnet Project Netkit-telnet | 30/8/2022 | 17/6/2026 | telnetd in GNU Inetutils through 2.3, MIT krb5-appl through 1.0.3, and derivative works has a NULL pointer dereference via 0xff 0xf7 or 0xff 0xf8. In a typical installation, the telnetd application would crash but the telnet service would remain available through inetd. However, if the telnetd application has many… | |
| Modificada | Media (6.5) | 1.0% | — | GNU InetutilsDebian Linux | 3/9/2021 | 17/6/2026 | The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl. | |
| Modificada | Alta (10) | 95% | — | GNU InetutilsHeimdal Project HeimdalMIT Krb5-applFreebsd+6 | 25/12/2011 | 16/6/2026 | Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU inetutils, and possibly other products allows remote attackers to execute arbitrary code via a long encryption key, as exploited in the… | |
| Modificada | Alta (7.5) | 2.5% | — | GNU InetutilsAI | 31/12/2004 | 16/6/2026 | Buffer overflow in the TFTP client in InetUtils 1.4.2 allows remote malicious DNS servers to execute arbitrary code via a large DNS response that is handled by the gethostbyname function. |