Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
363 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.29% | — | Bitdefender Total Security | 12/3/2018 | 17/6/2026 | BitDefender Total Security 2018 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of an "insecurely created named pipe". Ensures full access to Everyone users group. | |
| Modificada | Media (6.7) | 0.97% | — | Gdata-software Totalprotection | 1/2/2018 | 17/6/2026 | The MiniIcpt.sys driver in G Data TotalProtection 2014 24.0.2.1 and earlier allows local users with administrator rights to execute arbitrary code with SYSTEM privileges via a crafted 0x83170180 call. | |
| Modificada | Media (5.5) | 0.29% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | In K7 Antivirus Premium before 15.1.0.53, user-controlled input to the K7Sentry device is not sufficiently authenticated: a local user with a LOW integrity process can access a raw hard disk by sending a specific IOCTL. | |
| Modificada | Alta (7) | 0.27% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way. | |
| Modificada | Media (5.5) | 0.27% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | In K7 Antivirus Premium before 15.1.0.53, user-controlled input can be used to allow local users to write to arbitrary memory locations. | |
| Modificada | Alta (7) | 0.27% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way. | |
| Modificada | Alta (7.8) | 0.33% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls. | |
| Modificada | Alta (7) | 0.27% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way. | |
| Modificada | Alta (7.8) | 0.33% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls. | |
| Modificada | Alta (7) | 0.27% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to gain privileges by sending a specific IOCTL after setting the memory in a particular way. | |
| Modificada | Alta (7.8) | 0.33% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls. | |
| Modificada | Alta (7.8) | 0.33% | — | K7computing AntivirusK7computing EndpointK7computing Internet SecurityK7computing Total Security+1 | 16/1/2018 | 17/6/2026 | K7 Antivirus Premium before 15.1.0.53 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a specific set of IOCTL calls. | |
| Modificada | Alta (7.1) | 1.2% | 💥 Exploit | K7computing Total Security | 4/1/2018 | 17/6/2026 | In K7 Total Security before 15.1.0.305, user-controlled input to the K7Sentry device is not sufficiently sanitized: the user-controlled input can be used to compare an arbitrary memory address with a fixed value, which in turn can be used to read the contents of arbitrary memory. Similarly, the product crashes upon a… | |
| Modificada | Alta (7.5) | 1.7% | — | Cisco Yesmax HD FirmwareCisco Yesmaxtotal FirmwareCisco Yesquattro Firmware | 7/9/2017 | 17/6/2026 | A vulnerability in the HTTP remote procedure call (RPC) service of set-top box (STB) receivers manufactured by Cisco for Yes could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the firmware of an affected device fails to… | |
| Modificada | Alta (7) | 0.34% | — | Bitdefender Total Security | 29/8/2017 | 17/6/2026 | This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Bitdefender Total Security 21.0.24.62. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within processing of… | |
| Modificada | Alta (7.8) | 2.0% | 💥 Exploit | 360totalsecurity 360 Total Security | 7/8/2017 | 17/6/2026 | 360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 directory. | |
| Modificada | Media (6.5) | 1.3% | — | Cisco Smart NET Total Care Collector Appliance | 7/8/2017 | 17/6/2026 | A vulnerability in the web-based management interface of the Cisco Smart Net Total Care (SNTC) Software Collector Appliance 3.11 could allow an authenticated, remote attacker to perform a read-only, blind SQL injection attack, which could allow the attacker to compromise the confidentiality of the system through SQL… | |
| Modificada | Media (5.5) | 0.67% | — | Virustotal Yara | 17/7/2017 | 17/6/2026 | Heap buffer overflow in the yr_object_array_set_item() function in object.c in YARA 3.x allows a denial-of-service attack by scanning a crafted .NET file. | |
| Modificada | Alta (7.1) | 1.2% | — | Virustotal Yara | 6/6/2017 | 17/6/2026 | The yr_arena_write_data function in YARA 3.6.1 allows remote attackers to cause a denial of service (buffer over-read and application crash) or obtain sensitive information from process memory via a crafted file that is mishandled in the yr_re_fast_exec function in libyara/re.c and the _yr_scan_match_callback function… | |
| Modificada | Alta (7.5) | 2.5% | — | Virustotal Yara | 5/6/2017 | 17/6/2026 | libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule (involving hex strings) that is mishandled in the _yr_re_emit function, a different vulnerability than CVE-2017-9304. | |
| Modificada | Alta (7.5) | 1.8% | — | Virustotal Yara | 31/5/2017 | 17/6/2026 | libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is mishandled in the _yr_re_emit function. | |
| Modificada | Alta (7.5) | 1.8% | — | Virustotal Yara | 14/5/2017 | 17/6/2026 | The sized_string_cmp function in libyara/sizedstr.c in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule. | |
| Modificada | Alta (7.5) | 0.93% | — | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 4/5/2017 | 17/6/2026 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 have approximately 165 PE files in the default installation that do not use ASLR/DEP protection mechanisms that provide sufficient defense against directed attacks against the product. | |
| Modificada | Crítica (9.8) | 1.2% | — | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 4/5/2017 | 17/6/2026 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file. | |
| Modificada | Crítica (9.8) | 1.2% | — | Quickheal Antivirus PROQuickheal Internet SecurityQuickheal Total Security | 4/5/2017 | 17/6/2026 | Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file. |