Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
237 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (10) | 5.5% | — | Tibco RtworksTibco Smartsockets RtserverTibco Enterprise Message Service | 16/1/2008 | 16/6/2026 | TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointers. | |
| Modificada | Alta (10) | 5.5% | — | Tibco RtworksTibco Smartsockets RtserverTibco Enterprise Message Service | 16/1/2008 | 16/6/2026 | TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointer offsets. | |
| Modificada | Alta (9.3) | 4.1% | — | Tibco Smart PGM FX | 18/10/2007 | 16/6/2026 | Multiple stack-based buffer overflows in TIBCO SmartPGM FX allow remote attackers to execute arbitrary code or cause a denial of service (service stop and file-transfer outage) via unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it… | |
| Modificada | Alta (7.5) | 2.5% | — | Tibco Smart PGM FX | 18/10/2007 | 16/6/2026 | Format string vulnerability in TIBCO SmartPGM FX allows remote attackers to execute arbitrary code via format string specifiers in unspecified vectors. NOTE: as of 20071016, the only disclosure is a vague pre-advisory with no actionable information. However, since it is from a well-known researcher, it is being… | |
| Modificada | Media (4.3) | 1.4% | — | Tibco Rendezvous | 3/8/2007 | 16/6/2026 | rvd in TIBCO Rendezvous (RV) 7.5.2, when -no-lead-wc is omitted, might allow remote attackers to cause a denial of service (network instability) via a subject name with a leading (1) '*' (asterisk) or (2) '>' (greater than) wildcard character. | |
| Modificada | Alta (7.8) | 2.4% | — | Tibco Rendezvous | 3/8/2007 | 16/6/2026 | Memory leak in TIBCO Rendezvous (RV) daemon (rvd) 7.5.2, 7.5.3 and 7.5.4 allows remote attackers to cause a denial of service (memory consumption) via a packet with a length field of zero, a different vulnerability than CVE-2006-2830. | |
| Modificada | Media (5) | 1.3% | — | Tibco Rendezvous | 3/8/2007 | 16/6/2026 | index.html in the HTTP administration interface in certain daemons in TIBCO Rendezvous (RV) 7.5.2 allows remote attackers to obtain sensitive information, such as a user name and IP addresses, via a direct request. | |
| Modificada | Media (5) | 1.4% | — | Tibco Rendezvous | 3/8/2007 | 16/6/2026 | The default configuration of TIBCO Rendezvous (RV) 7.5.2 clients, when -no-multicast is omitted, uses a multicast group as the destination for a network message, which might make it easier for remote attackers to capture message contents by sniffing the network. | |
| Modificada | Alta (7.8) | 1.3% | — | Tibco Rendezvous | 3/8/2007 | 16/6/2026 | TIBCO Rendezvous (RV) 7.5.2 does not protect confidentiality or integrity of inter-daemon communication, which allows remote attackers to capture and spoof traffic. | |
| Modificada | Baja (1.2) | 0.73% | 💥 Exploit | Tibco Rendezvous | 11/9/2006 | 16/6/2026 | TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to obtain sensitive information by decoding the log file. | |
| Modificada | Alta (7.5) | 6.0% | — | Tibco HawkTibco RendezvousTibco Runtime Agent | 5/6/2006 | 16/6/2026 | Buffer overflow in TIBCO Rendezvous before 7.5.1, TIBCO Runtime Agent (TRA) before 5.4, and Hawk before 4.6.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via the HTTP administrative interface. | |
| Modificada | Media (6.8) | 0.47% | — | Tibco HawkTibco Hawk Monitoring AgentTibco Runtime Agent | 5/6/2006 | 16/6/2026 | Buffer overflow in Hawk Monitoring Agent (HMA) for TIBCO Hawk before 4.6.1 and TIBCO Runtime Agent (TRA) before 5.4 allows authenticated users to execute arbitrary code via the configuration for tibhawkhma. |