Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

296 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6)0.31%—Symantec Norton AntivirusSymantec Norton Internet Security5/11/200716/6/2026
The Disk Mount scanner in Symantec AntiVirus for Macintosh 9.x and 10.x, Norton AntiVirus for Macintosh 10.0 and 10.1, and Norton Internet Security for Macintosh 3.x, uses a directory with weak permissions (group writable), which allows local admin users to gain root privileges by replacing unspecified files, which…
ModificadaCrítica (9.8)27%💥 ExploitBitdefender AntivirusBitdefender Internet SecurityBitdefender Total Security1/11/200716/6/2026
Unspecified vulnerability in BitDefender allows attackers to execute arbitrary code via unspecified vectors, aka EEYEB-20071024. NOTE: as of 20071029, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being assigned a CVE identifier for…
ModificadaMedia (6.6)0.39%—Trend Micro Pc-cillin Internet Security 2007Trend Micro Scan Engine30/10/200716/6/2026
The Trend Micro AntiVirus scan engine before 8.550-1001, as used in Trend Micro PC-Cillin Internet Security 2007, and Tmxpflt.sys 8.320.1004 and 8.500.0.1002, has weak permissions (Everyone:Write) for the \\.\Tmfilter device, which allows local users to send arbitrary content to the device via the IOCTL functionality.…
ModificadaAlta (9.3)3.9%—Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+95/10/200716/6/2026
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR archive file header.
ModificadaAlta (9.3)6.0%—Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Mail Security+95/10/200716/6/2026
Heap-based buffer overflow in the Decomposer component in multiple Symantec products allows remote attackers to execute arbitrary code via multiple crafted CAB archives.
ModificadaBaja (2.1)0.44%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security26/9/200716/6/2026
Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 125 do not properly validate certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, which allows local users to cause a denial of service (crash) via the (1) NtUserSendInput, (2) LoadLibraryA, (3) NtOpenProcess, (4)…
ModificadaAlta (7.2)0.33%—Symantec Norton Internet Security24/9/200716/6/2026
Norton Internet Security 2008 15.0.0.60 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the NtOpenSection kernel SSDT hook. NOTE: the NtCreateMutant and NtOpenEvent…
ModificadaMedia (4.4)0.32%—Kaspersky LAB Kaspersky Internet Security24/9/200716/6/2026
Kaspersky Internet Security 7.0.0.125 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to (1) cause a denial of service (crash) and possibly gain privileges via the NtCreateSection kernel SSDT hook or (2) cause a denial of service…
ModificadaAlta (7.2)0.89%💥 ExploitMicroworld Technologies Escan Anti-virusMicroworld Technologies Escan Internet SecurityMicroworld Technologies Escan Virus Control31/8/200716/6/2026
MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, which allows local users to gain privileges by replacing application files, as demonstrated by traysser.exe.
ModificadaMedia (6.9)0.42%—Trend Micro AntispywareTrend Micro Pc-cillin Internet Security 200722/8/200716/6/2026
Stack-based buffer overflow in vstlib32.dll 1.2.0.1012 in the SSAPI Engine 5.0.0.1066 through 5.2.0.1012 in Trend Micro AntiSpyware 3.5 and PC-Cillin Internet Security 2007 15.0 through 15.3, when the Venus Spy Trap (VST) feature is enabled, allows local users to cause a denial of service (service crash) or execute…
ModificadaMedia (6.8)4.0%—Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System Works9/8/200716/6/2026
Multiple unspecified "input validation error" vulnerabilities in multiple ActiveX controls in NavComUI.dll, as used in multiple Norton AntiVirus, Internet Security, and System Works products for 2006, allows remote attackers to execute arbitrary code via (1) the AnomalyList property to AxSysListView32 and (2) Anomaly…
ModificadaMedia (4.3)3.6%—Broadcom Anti-spywareBroadcom Anti-virus FOR THE EnterpriseBroadcom Anti Virus SDKBroadcom Antispyware FOR THE Enterprise+1926/7/200716/6/2026
arclib.dll before 7.3.0.9 in CA Anti-Virus (formerly eTrust Antivirus) 8 and certain other CA products allows remote attackers to cause a denial of service (infinite loop and loss of antivirus functionality) via an invalid "previous listing chunk number" field in a CHM file.
ModificadaMedia (6.9)1.1%💥 ExploitSymantec Client SecuritySymantec Norton AntispamSymantec Norton AntivirusSymantec Norton Internet Security+215/7/200716/6/2026
Symantec symtdi.sys before 7.0.0, as distributed in Symantec AntiVirus Corporate Edition 9 through 10.1 and Client Security 2.0 through 3.1, Norton AntiSpam 2005, and Norton AntiVirus, Internet Security, Personal Firewall, and System Works 2005 and 2006; allows local users to gain privileges via a crafted Interrupt…
ModificadaAlta (9.3)3.7%—F-secure Anti-virusF-secure Anti-virus Linux Client SecurityF-secure Anti-virus Linux Server SecurityF-secure Internet Security+220/6/200716/6/2026
Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
ModificadaAlta (9.3)50%💥 ExploitBroadcom Anti-virus FOR THE EnterpriseBroadcom Brightstor Arcserve BackupBroadcom Common ServicesBroadcom Etrust Antivirus+96/6/200716/6/2026
Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.
ModificadaAlta (7.2)0.35%—F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus Linux Client SecurityF-secure Anti-virus Linux Server Security+331/5/200716/6/2026
Unspecified vulnerability in the Real-time Scanning component in multiple F-Secure products, including Internet Security 2005, 2006 and 2007; Anti-Virus 2005, 2006 and 2007; and Solutions based on F-Secure Protection Service for Consumers 6.40 and earlier allows local users to gain privileges via a crafted I/O request…
ModificadaAlta (10)4.8%—F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus Linux Client SecurityF-secure Anti-virus Linux Server Security+331/5/200716/6/2026
Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070522 allow remote attackers to cause a denial of service (file scanning infinite loop) via certain crafted (1) ARJ archives or (2) FSG packed files.
ModificadaAlta (7.5)5.2%—F-secure Anti-virusF-secure Anti-virus Client SecurityF-secure Anti-virus Linux Client SecurityF-secure Anti-virus Linux Server Security+331/5/200716/6/2026
Buffer overflow in the LHA decompression component in F-Secure anti-virus products for Microsoft Windows and Linux before 20070529 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted LHA archive, related to an integer wrap, a similar issue to CVE-2006-4335.
ModificadaAlta (10)65%💥 ExploitSymantec Norton Internet SecuritySymantec Norton Personal Firewall16/5/200716/6/2026
Buffer overflow in the ISAlertDataCOM ActiveX control in ISLALERT.DLL for Norton Personal Firewall 2004 and Internet Security 2004 allows remote attackers to execute arbitrary code via long arguments to the (1) Get and (2) Set functions.
ModificadaAlta (8.5)3.9%—Symantec Norton AntivirusSymantec Norton Internet SecuritySymantec Norton System Works11/5/200716/6/2026
The Symantec NAVOPTS.DLL ActiveX control (aka Symantec.Norton.AntiVirus.NAVOptions) 12.2.0.13, as used in Norton AntiVirus, Internet Security, and System Works 2005 and 2006, is designed for use only in application-embedded web browsers, which allows remote attackers to "crash the control" via unspecified vectors…
ModificadaAlta (7.8)3.0%—Panda ActivescanPanda AntivirusPanda Platinum 2006 Internet SecurityPanda Platinum 2007 Internet Security+29/5/200716/6/2026
Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
ModificadaAlta (10)8.9%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security6/4/200716/6/2026
Heap-based buffer overflow in the arj.ppl module in the OnDemand Scanner in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to execute arbitrary code via crafted ARJ archives.
ModificadaAlta (10)4.9%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security6/4/200716/6/2026
Kaspersky Anti-Virus 6.0 and Internet Security 6.0 exposes unsafe methods in the (a) AXKLPROD60Lib.KAV60Info (AxKLProd60.dll) and (b) AXKLSYSINFOLib.SysInfo (AxKLSysInfo.dll) ActiveX controls, which allows remote attackers to "download" or delete arbitrary files via crafted arguments to the (1) DeleteFile, (2)…
ModificadaAlta (9.3)3.3%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security6/4/200716/6/2026
The StartUploading function in KL.SysInfo ActiveX control (AxKLSysInfo.dll) in Kaspersky Anti-Virus 6.0 and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers to read arbitrary files by triggering an outbound anonymous FTP session that invokes the PUT command. NOTE: this issue…
ModificadaMedia (6.6)0.42%—Kaspersky LAB Kaspersky Anti-virusKaspersky LAB Kaspersky Internet Security6/4/200716/6/2026
Integer overflow in the _NtSetValueKey function in klif.sys in Kaspersky Anti-Virus, Anti-Virus for Workstations, Anti-Virus for File Server 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows context-dependent attackers to execute arbitrary code via a large, unsigned "data size argument,"…
Orbitaley — Vulnerabilidades