Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

367 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.6%—Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript23/10/201016/6/2026
The gs_type2_interpret function in Ghostscript allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) via crafted font data in a compressed data stream, aka bug 691043.
ModificadaAlta (9.3)6.8%—Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript26/8/201016/6/2026
Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer…
ModificadaAlta (7.2)0.51%—Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript22/7/201016/6/2026
Ghostscript 8.71 and earlier reads initialization files from the current working directory, which allows local users to execute arbitrary PostScript commands via a Trojan horse file, related to improper support for the -P- option to the gs program, as demonstrated using gs_init.ps, a different vulnerability than…
ModificadaAlta (9.3)6.6%—Artifex Afpl GhostscriptArtifex Ghostscript FontsArtifex GPL Ghostscript22/7/201016/6/2026
Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
ModificadaAlta (9.3)4.0%—Artifex GPL Ghostscript19/5/201016/6/2026
Ghostscript 8.64, 8.70, and possibly other versions allows context-dependent attackers to execute arbitrary code via a PostScript file containing unlimited recursive procedure invocations, which trigger memory corruption in the stack of the interpreter.
ModificadaAlta (9.3)9.2%💥 ExploitArtifex GPL Ghostscript12/5/201016/6/2026
Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file.
ModificadaMedia (5)2.5%💥 ExploitThe-ghost AR WEB Content Manager23/3/201016/6/2026
AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for control/db_backup.php.
ModificadaAlta (9.3)6.9%—Ghostscript21/12/200916/6/2026
Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.
ModificadaMedia (6.8)4.1%💥 ExploitThe-ghost AR WEB Content Manager16/9/200916/6/2026
Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the a parameter.
ModificadaMedia (6.8)2.0%💥 ExploitThe-ghost AR WEB Content Manager16/9/200916/6/2026
SQL injection vulnerability in control/login.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaMedia (4.3)6.6%💥 ExploitSymantec Norton Ghost4/5/200916/6/2026
Multiple insecure method vulnerabilities in the Symantec.EasySetup.1 ActiveX control in EasySetupInt.dll 14.0.4.30167 in the EasySetup wizard in Symantec Norton Ghost 14.0 allow remote attackers to cause a denial of service (browser crash) and possibly execute arbitrary code via unspecified input to the (1)…
ModificadaAlta (9.3)7.4%—Ghostscript16/4/200916/6/2026
Heap-based buffer overflow in the big2_decode_symbol_dict function (jbig2_symbol_dict.c) in the JBIG2 decoding library (jbig2dec) in Ghostscript 8.64, and probably earlier versions, allows remote attackers to execute arbitrary code via a PDF file with a JBIG2 symbol dictionary segment with a large run length value.
ModificadaAlta (9.3)4.0%—GhostscriptArgyllcms14/4/200916/6/2026
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application…
ModificadaMedia (5)4.5%—Ghostscript8/4/200916/6/2026
Buffer overflow in the BaseFont writer module in Ghostscript 8.62, and possibly other versions, allows remote attackers to cause a denial of service (ps2pdf crash) and possibly execute arbitrary code via a crafted Postscript file.
ModificadaAlta (7.5)4.8%—Ghostscript8/4/200916/6/2026
The CCITTFax decoding filter in Ghostscript 8.60, 8.61, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file that triggers a buffer underflow in the cf_decode_2d function.
ModificadaAlta (9.3)4.1%—Argyllcms CMSGhostscript23/3/200916/6/2026
icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using a device…
ModificadaAlta (9.3)4.7%—GhostscriptArgyllcms23/3/200916/6/2026
Multiple integer overflows in icc.c in the International Color Consortium (ICC) Format library (aka icclib), as used in Ghostscript 8.64 and earlier and Argyll Color Management System (CMS) 1.0.3 and earlier, allow context-dependent attackers to cause a denial of service (heap-based buffer overflow and application…
ModificadaMedia (6.8)15%💥 ExploitGhostscript28/2/200816/6/2026
Stack-based buffer overflow in the zseticcspace function in zicc.c in Ghostscript 8.61 and earlier allows remote attackers to execute arbitrary code via a postscript (.ps) file containing a long Range array in a .seticcspace operator.
ModificadaAlta (10)2.9%—Symantec Ghost Solutions Suite8/2/200816/6/2026
Symantec Ghost Solution Suite 1.1 before 1.1 patch 2, 2.0.0, and 2.0.1 does not authenticate connections between the console and the Ghost Management Agent, which allows remote attackers to execute arbitrary commands via unspecified RPC requests in conjunction with ARP spoofing.
ModificadaBaja (2.1)0.31%—Ghostsecurity Ghost Security Suite24/9/200716/6/2026
Ghost Security Suite beta 1.110 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtDeleteValueKey, (3) NtQueryValueKey, (4)…
ModificadaBaja (2.1)0.30%—Ghostsecurity Ghost Security Suite24/9/200716/6/2026
Ghost Security Suite alpha 1.200 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreateKey, (2) NtCreateThread, (3) NtDeleteValueKey, (4) NtQueryValueKey,…
ModificadaMedia (5)1.5%—Symantec Norton Ghost10/7/200716/6/2026
Multiple unspecified vulnerabilities in FileBackup.DLL in Symantec Norton Ghost 12.0 allow remote attackers to cause a denial of service via unspecified vectors involving the UpdateCatalog and other functions.
ModificadaAlta (7.5)3.0%—Symantec Norton Ghost10/7/200716/6/2026
Buffer overflow in RemoteCommand.DLL in Symantec Norton Ghost 12.0 allows remote attackers to execute arbitrary code via the Connect function.
ModificadaMedia (5)2.2%—Symantec Ghost Solutions SuiteSymantec Norton Ghost8/6/200716/6/2026
Multiple vulnerabilities in Symantec Ghost Solution Suite 2.0.0 and earlier, with Ghost 8.0.992 and possibly other versions, allow remote attackers to cause a denial of service (client or server crash) via malformed requests to the daemon port, 1346/udp or 1347/udp.
ModificadaMedia (6.8)0.34%—Symantec Backupexec System RecoverySymantec Livestate RecoverySymantec Norton GhostSymantec Norton Save AND Recovery30/4/200716/6/2026
Symantec Norton Ghost, Norton Save & Recovery, LiveState Recovery, and BackupExec System Recovery before 20070426, when remote backups of restore point images are configured, encrypt network share credentials with a key formed by a hash of the username, which allows local users to obtain the credentials by calculating…