Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2629▼ 216 respecto a la semana anterior
Críticas / altas1378▲ 154 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

184 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)1.1%—UAC Unix Like Artifacts CollectorAI21/8/202624/9/2026
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreach command output lines are substituted directly into command strings via sed without proper escaping before being evaluated with eval. Attackers can exploit this by…
AplazadaAlta (8.5)1.0%—UAC Unix Like Artifacts CollectorAI21/8/202624/9/2026
UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attackers to execute arbitrary commands by injecting shell metacharacters into untrusted data such as usernames, process names, or filenames. Attackers can exploit this…
AnalizadaAlta (7.8)0.18%—Opengroup Unix13/3/202617/6/2026
In UNIX Fourth Research Edition (v4), the su command is vulnerable to a buffer overflow due to the 'password' variable having a fixed size of 100 bytes. A local user can exploit this to gain root privileges. It is unlikely that UNIX v4 is running anywhere outside of a very small number of lab environments. NOTE: This…
AplazadaAlta (8.4)0.11%—IBM Sterling Connect Direct FOR UnixAI20/1/202617/6/2026
IBM Sterling Connect:Direct for UNIX Container 6.3.0.0 through 6.3.0.6 Interim Fix 016, and 6.4.0.0 through 6.4.0.3 Interim Fix 019 IBM® Sterling Connect:Direct for UNIX contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to…
AplazadaAlta (8.5)0.59%—Broadcom Automic Automation Agent UnixAI20/5/202517/6/2026
Broadcom Automic Automation Agent Unix versions < 24.3.0 HF4 and < 21.0.13 HF1 allow low privileged users who have execution rights on the agent executable to escalate their privileges.
AplazadaAlta (7.8)0.21%—Sunix Parallel DriverAI7/1/202517/6/2026
A vulnerability exits in driver snxppamd.sys in SUNIX Parallel Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These…
AplazadaAlta (7.8)0.21%—Sunix Serial DriverAI7/1/202517/6/2026
A vulnerability exits in driver snxpsamd.sys in SUNIX Serial Driver x64 - 10.1.0.0, which allows low-privileged users to read and write arbitary i/o port via specially crafted IOCTL requests . This can be exploited for privilege escalation, code execution under high privileges, and information disclosure. These signed…
AplazadaAlta (8.8)0.40%—Sunix Multi I O CardAI7/1/202517/6/2026
An issue in the snxpcamd.sys component of SUNIX Multi I/O Card v10.1.0.0 allows attackers to perform arbitrary read and write actions via supplying crafted IOCTL requests.
ModificadaAlta (7.8)0.28%—Unixodbc18/3/202417/6/2026
An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian architectures can be broken.
ModificadaCrítica (9.8)1.1%—Unix4lyfe Darkhttpd22/1/202417/6/2026
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which makes it easier for remote attackers to bypass authentication via a timing side channel.
ModificadaMedia (5.5)0.24%—Unix4lyfe Darkhttpd22/1/202417/6/2026
darkhttpd through 1.15 allows local users to discover credentials (for --auth) by listing processes and their arguments.
ModificadaAlta (7.5)0.91%—Protocol Go-unixfsnode9/2/202317/6/2026
github.com/ipfs/go-unixfsnode is an ADL IPLD prime node that wraps go-codec-dagpb's implementation of protobuf to enable pathing. In versions priot to 1.5.2 trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger…
ModificadaAlta (7.5)0.68%—Protocol Go-unixfs9/2/202317/6/2026
go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger a panic. This is caused by bogus `fanout` parameter in the HAMT…
ModificadaAlta (7.5)1.3%—Unix4lyfe Darkhttpd1/4/202217/6/2026
A flaw was found in darkhttpd. Invalid error handling allows remote attackers to cause denial-of-service by accessing a file with a large modification date. The highest threat from this vulnerability is to system availability.
AnalizadaAlta (7.8)100%⚠ Explotación activaSudo Project SudoFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+2026/1/202117/6/2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
ModificadaAlta (7.8)0.45%—UnixodbcDebian LinuxOpensuseRedhat Enterprise Linux14/11/201916/6/2026
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
ModificadaCrítica (9.8)3.0%—Unixodbc26/2/201817/6/2026
The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.
ModificadaCrítica (9.8)2.5%—Unixodbc22/2/201817/6/2026
In unixODBC before 2.3.5, there is a buffer overflow in the unicode_to_ansi_copy() function in DriverManager/__info.c.
ModificadaCrítica (9.8)42%—Quest Privilege Manager FOR Unix29/4/201717/6/2026
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory corruption in the pmmasterd daemon.
ModificadaCrítica (9.8)3.0%—LHA FOR Unix Project LHA FOR Unix23/1/201717/6/2026
Integer underflow in header.c in lha allows remote attackers to have unspecified impact via a large header size value for the (1) level0 or (2) level1 header in a lha archive, which triggers a buffer overflow.
ModificadaAlta (7.2)0.84%—IBM Monitoring Agent FOR Unix LogsIBM Monitoring Server (ms) AND Shared Libraries (ax)29/8/201416/6/2026
Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM) on UNIX allow…
ModificadaAlta (7.2)0.39%—Nvidia Unix Graphic Driver19/11/201216/6/2026
NVIDIA UNIX graphics driver before 295.71 and before 304.32 allows local users to write to arbitrary physical memory locations and gain privileges by modifying the VGA window using /dev/nvidia0.
ModificadaMedia (6.9)0.40%—Attachmate Reflection FOR HPAttachmate Reflection FOR IBMAttachmate Reflection FOR Regis Graphics ServerAttachmate Reflection FOR Unix AND Openvms+16/9/201216/6/2026
Untrusted search path vulnerability in Attachmate Reflection before 14.1 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, a related issue to CVE-2011-0107. NOTE: some of these details are obtained from third party information.
ModificadaBaja (2.1)0.51%—Unixodbc31/8/201216/6/2026
Buffer overflow in the SQLDriverConnect function in unixODBC 2.3.1 allows local users to cause a denial of service (crash) via a long string in the DRIVER option. NOTE: this issue might not be a vulnerability, since the ability to set this option typically implies that the attacker already has legitimate access to…
ModificadaBaja (2.1)0.44%—Unixodbc31/8/201216/6/2026
Buffer overflow in the SQLDriverConnect function in unixODBC 2.0.10, 2.3.1, and earlier allows local users to cause a denial of service (crash) via a long string in the FILEDSN option. NOTE: this issue might not be a vulnerability, since the ability to set this option typically implies that the attacker already has…