Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
281 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.3% | — | F-secure Anti-virusKaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Anti-virus Personal | 18/11/2005 | 16/6/2026 | Heap-based buffer overflow in Kaspersky Anti-Virus Engine, as used in Kaspersky Personal 5.0.227, Anti-Virus On-Demand Scanner for Linux 5.0.5, and F-Secure Anti-Virus for Linux 4.50 allows remote attackers to execute arbitrary code via a crafted CHM file. | |
| Modificada | Alta (10) | 2.2% | — | Clam Anti-virus Clamav | 16/11/2005 | 16/6/2026 | Improper boundary checks in petite.c in Clam AntiVirus (ClamAV) before 0.87.1 allows attackers to perform unknown attacks via unknown vectors. | |
| Modificada | Alta (7.2) | 0.80% | 💥 Exploit | F-secure Anti-virusF-secure Internet Gatekeeper | 16/11/2005 | 16/6/2026 | suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2.16 are installed SUID with world-executable permissions, which allows local users to gain privilege. | |
| Modificada | Alta (7.5) | 6.9% | — | Clam Anti-virus Clamav | 5/11/2005 | 16/6/2026 | The FSG unpacker (fsg.c) in Clam AntiVirus (ClamAV) 0.80 through 0.87 allows remote attackers to cause "memory corruption" and execute arbitrary code via a crafted FSG 1.33 file. | |
| Modificada | Media (5) | 4.0% | — | Clam Anti-virus Clamav | 5/11/2005 | 16/6/2026 | The tnef_attachment function in tnef.c for Clam AntiVirus (ClamAV) before 0.87.1 allows remote attackers to cause a denial of service (infinite loop and memory exhaustion) via a crafted value in a CAB file that causes ClamAV to repeatedly scan the same block. | |
| Modificada | Media (5) | 2.1% | — | F-secure Anti-virusF-secure Internet Gatekeeper | 2/11/2005 | 16/6/2026 | Directory traversal vulnerability in F-Secure Anti-Virus for Microsoft Exchange 6.40 and Internet Gatekeeper 6.40 to 6.42 allows limited remote attackers to bypass Web Console authentication and read files. | |
| Modificada | Media (5.1) | 1.4% | — | Kaspersky LAB Kaspersky Anti-virus | 30/10/2005 | 16/6/2026 | Multiple interpretation error in Kaspersky 5.0.372 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by… | |
| Modificada | Media (5) | 4.5% | — | Sophos Anti-virus | 30/10/2005 | 16/6/2026 | Multiple interpretation error in Sophos 3.91 with the 2.28.4 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a… | |
| Modificada | Alta (7.8) | 4.5% | — | Clam Anti-virus Clamav | 14/10/2005 | 16/6/2026 | The OLE2 unpacker in clamd in Clam AntiVirus (ClamAV) 0.87-1 allows remote attackers to cause a denial of service (segmentation fault) via a DOC file with an invalid property tree, which triggers an infinite recursion in the ole2_walk_property_tree function. | |
| Modificada | Media (5.1) | 1.7% | — | Kaspersky LAB Kaspersky Anti-virus | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of Kaspersky Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… | |
| Modificada | Media (5.1) | 4.6% | — | Sophos Anti-virus | 14/10/2005 | 16/6/2026 | Multiple interpretation error in unspecified versions of Sophos Antivirus allows remote attackers to bypass virus detection via a malicious executable in a specially crafted RAR file with malformed central and local headers, which can still be opened by products such as Winrar and PowerZip, even though they are… | |
| Modificada | Alta (10) | 42% | — | Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Anti-virus PersonalKaspersky LAB Kaspersky Anti-virus Personal PROKaspersky LAB Kaspersky Personal Security Suite | 5/10/2005 | 16/6/2026 | Heap-based buffer overflow in Kaspersky Antivirus (KAV) 5.0 and Kaspersky Personal Security Suite 1.1 allows remote attackers to execute arbitrary code via a CAB file with large records after the header. | |
| Modificada | Media (5) | 3.6% | — | Clam Anti-virus Clamav | 20/9/2005 | 16/6/2026 | libclamav/fsg.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to cause a denial of service (infinite loop) via a crafted FSG packed executable. | |
| Modificada | Alta (7.5) | 8.2% | — | Clam Anti-virus Clamav | 20/9/2005 | 16/6/2026 | Buffer overflow in libclamav/upx.c in Clam AntiVirus (ClamAV) before 0.87 allows remote attackers to execute arbitrary code via a crafted UPX packed executable. | |
| Modificada | Alta (7.5) | 13% | — | Sophos Anti-virus | 2/9/2005 | 16/6/2026 | Heap-based buffer overflow in the Sophos Antivirus Library, as used by Sophos Antivirus, PureMessage, MailMonitor, and other products, allows remote attackers to execute arbitrary code via a Visio file with a crafted sub record length. | |
| Modificada | Baja (3.6) | 0.42% | — | Kaspersky LAB Kaspersky Anti-virus | 16/8/2005 | 16/6/2026 | Kaspersky Anti-Virus for Unix/Linux File Servers 5.0-5 uses world-writable permissions for the (1) log and (2) license directory, which allows local users to delete log files, append to arbitrary files via a symlink attack on kavmonitor.log, or delete license keys and prevent keepup2date from properly executing. | |
| Modificada | Alta (7.5) | 3.9% | — | Clam Anti-virus Clamav | 3/8/2005 | 16/6/2026 | Multiple integer overflows in the (1) TNEF, (2) CHM, or (3) FSG file format processors in libclamav for Clam AntiVirus (ClamAV) 0.86.1 and earlier allow remote attackers to gain privileges via a crafted e-mail message. | |
| Modificada | Media (5) | 6.2% | — | Sophos Anti-virusSophos MailmonitorSophos Mailmonitor FOR Notes DominoSophos Puremessage Anti-virus+1 | 19/7/2005 | 16/6/2026 | Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value. | |
| Modificada | Media (5) | 2.5% | — | Clam Anti-virus Clamav | 5/7/2005 | 16/6/2026 | The MS-Expand file handling in Clam AntiVirus (ClamAV) before 0.86 allows remote attackers to cause a denial of service (file descriptor and memory consumption) via a crafted file that causes repeated errors in the cli_msexpand function. | |
| Modificada | Baja (2.6) | 1.6% | — | Clam Anti-virus Clamav | 5/7/2005 | 16/6/2026 | The ENSURE_BITS macro in mszipd.c for Clam AntiVirus (ClamAV) 0.83, and other versions vefore 0.86, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a cabinet (CAB) file with the cffile_FolderOffset field set to 0xff, which causes a zero-length read. | |
| Modificada | Baja (2.6) | 2.3% | — | Clam Anti-virus Clamav | 29/6/2005 | 16/6/2026 | The Quantum archive decompressor in Clam AntiVirus (ClamAV) before 0.86.1 allows remote attackers to cause a denial of service (application crash) via a crafted Quantum archive. | |
| Modificada | Alta (7.2) | 0.73% | 💥 Exploit | Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Anti-virus Personal | 9/6/2005 | 16/6/2026 | The klif.sys driver in Kaspersky Labs Anti-Virus 5.0.227, 5.0.228, and 5.0.335 on Windows 2000 allows local users to gain privileges by modifying certain critical code addresses that are later accessed by privileged programs. | |
| Modificada | Media (4.3) | 3.1% | 💥 Exploit | Clam Anti-virus Clamav | 28/5/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Jaws Glossary gadget 0.4 to 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the term parameter in a view or ViewTerm action to index.php. | |
| Modificada | Alta (7.5) | 3.6% | — | Clam Anti-virus Clamav | 27/5/2005 | 16/6/2026 | The filecopy function in misc.c in Clam AntiVirus (ClamAV) before 0.85, on Mac OS, allows remote attackers to execute arbitrary code via a virus in a filename that contains shell metacharacters, which are not properly handled when HFS permissions prevent the file from being deleted and ditto is invoked. | |
| Modificada | Alta (7.5) | 1.0% | — | Clam Anti-virus ClamavGibraltar FirewallSquid | 24/5/2005 | 16/6/2026 | Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses from being detected. |