Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.7% | — | Vizer WEB Server | 31/12/2004 | 16/6/2026 | Vizer Web Server 1.9.1 allows remote attackers to cause a denial of service (crash) via multiple malformed requests including (1) requests without GET, (2) GET requests without HTTP, (3) or long GET requests. | |
| Modificada | Media (5) | 1.6% | — | SUN Java System Application ServerSUN Java System WEB Server | 31/12/2004 | 16/6/2026 | Unknown vulnerability in Sun Java System Web Server 6.0 SP7 and earlier and 6.1 SP1 and earlier, and Application Server 7 Update 4 and earlier, allows remote attackers to cause a denial of service (crash) via a malformed client certificate. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Borland Software WEB Server FOR Corel Paradox | 31/12/2004 | 16/6/2026 | Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5c%2e%2e" (encoded "\..") sequences, in the URL. | |
| Modificada | Media (5) | 1.8% | — | Twilight Utilities WEB Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in postfile.exe for Twilight Utilities Web Server 2.0.0.0 allows remote attackers to write arbitrary files via a .. (dot dot) in the attfile parameter. | |
| Modificada | Alta (7.5) | 23% | — | Mozilla Network Security ServicesNetscape Certificate ServerNetscape Directory ServerNetscape Enterprise Server+6 | 31/12/2004 | 16/6/2026 | Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message. | |
| Modificada | Media (5) | 2.6% | — | Fizmez WEB Server | 31/12/2004 | 16/6/2026 | Early termination vulnerability in Fizmez Web Server 1.0 allows remote attackers to cause a denial of service (crash) by connecting to the server and then disconnecting without sending any data, which triggers a null pointer dereference. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Pwebserver WEB Server | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in PWebServer 0.3.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Alta (7.5) | 3.8% | — | Twilight Utilities WEB Server | 31/12/2004 | 16/6/2026 | Buffer overflow in postfile.exe for Twilight Utilities Web Server 2.0.0.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a URL request with a long attfile attribute. | |
| Modificada | Alta (7.5) | 9.5% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference. | |
| Modificada | Media (5) | 7.2% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. | |
| Modificada | Media (5) | 10% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+61 | 23/11/2004 | 16/6/2026 | The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read. | |
| Modificada | Media (5) | 17% | — | Apache Http ServerHP Secure WEB Server FOR Tru64Gentoo LinuxHp-ux+8 | 16/9/2004 | 16/6/2026 | The mod_dav module in Apache 2.0.50 and earlier allows remote attackers to cause a denial of service (child process crash) via a certain sequence of LOCK requests for a location that allows WebDAV authoring access. | |
| Modificada | Media (5) | 3.7% | 💥 Exploit | EFS Software EFS WEB Server | 24/8/2004 | 16/6/2026 | Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) via many large HTTP requests. | |
| Modificada | Media (5) | 1.7% | — | EFS Software EFS WEB Server | 24/8/2004 | 16/6/2026 | Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to view arbitrary files via an HTTP request for the disk_c virtual folder. | |
| Modificada | Alta (10) | 4.3% | 💥 Exploit | Fastream Netfile FTP WEB Server | 6/8/2004 | 16/6/2026 | Directory traversal vulnerability in Fastream NETFile FTP/Web Server 6.7.2.1085 and earlier allows remote attackers to create or delete arbitrary files via .. (dot dot) and // (double slash) sequences in the filename parameter. | |
| Modificada | Media (5) | 1.2% | — | Fastream Netfile FTP WEB Server | 6/8/2004 | 16/6/2026 | Fastream NETFile FTP Server 6.7.2.1085 and earlier allows remote attackers to cause a denial of service (temporary hang) via the cd command with an unusual argument, possibly due to multiple leading slashes and/or an access to the floppy drive ("A"). | |
| Modificada | Media (5) | 2.9% | — | Aldostools Aldo's WEB Server | 3/5/2004 | 16/6/2026 | Directory traversal vulnerability in Aldo's Web Server (aweb) 1.5 allows remote attackers to view arbitrary files via a .. (dot dot) in an HTTP GET request. | |
| Modificada | Media (5) | 2.0% | — | Fastream Netfile FTP WEB Server | 19/4/2004 | 16/6/2026 | Fastream NETFile FTP/Web Server 6.5.1.980 allows remote attackers to cause a denial of service via a username that does not exist. | |
| Modificada | Media (5) | 2.5% | — | Aldo Vargas Aldos WEB Server | 3/3/2004 | 16/6/2026 | Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Reptile WEB Server | 23/1/2004 | 16/6/2026 | Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET requests without the HTTP version. | |
| Modificada | Media (5) | 2.3% | — | EFS Software EFS WEB ServerAI | 31/12/2003 | 16/6/2026 | Easy File Sharing (EFS) Web Server 1.2 stores the (1) option.ini (aka options.ini) file and (2) log directory under the web root with insufficient access control, which allows remote attackers to obtain sensitive information including an SMTP account username and password hash, the server configuration, and server log… | |
| Modificada | Alta (8.5) | 7.9% | 💥 Exploit | Aprelium Technologies Abyss WEB Server | 31/12/2003 | 16/6/2026 | Aprelium Technologies Abyss Web Server 1.1.2, and possibly other versions before 1.1.4, allows remote attackers to cause a denial of service (crash) via an HTTP GET message with empty (1) Connection or (2) Range fields. | |
| Modificada | Media (5) | 2.0% | — | SUN ONE WEB Server | 31/12/2003 | 16/6/2026 | Unknown vulnerability in SunOne/iPlanet Web Server SP3 through SP5 on Windows platforms allows remote attackers to cause a denial of service. | |
| Modificada | Media (5) | 3.3% | 💥 Exploit | Plug AND Play Software Plug AND Play WEB Server | 31/12/2003 | 16/6/2026 | Multiple buffer overflows in the FTP service in Plug and Play Web Server 1.0002c allow remote attackers to cause a denial of service (crash) via long (1) dir, (2) ls, (3) delete, (4) mkdir, (5) DELE, (6) RMD, or (7) MKD commands. | |
| Modificada | Media (6.4) | 1.2% | — | Aprelium Technologies Abyss WEB Server | 31/12/2003 | 16/6/2026 | The remote web management interface of Aprelium Technologies Abyss Web Server 1.1.2 and earlier does not log connection attempts to the web management port (9999), which allows remote attackers to mount brute force attacks on the administration console without detection. |