Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
552 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 3.7% | — | Apache Http Server | 5/2/2010 | 16/6/2026 | The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as… | |
| Modificada | Media (6.8) | 43% | — | Apache Http Server | 2/2/2010 | 16/6/2026 | Integer overflow in the ap_proxy_send_fb function in proxy/proxy_util.c in mod_proxy in the Apache HTTP Server before 1.3.42 on 64-bit platforms allows remote origin servers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a large chunk size that triggers a heap-based buffer overflow. | |
| Modificada | Media (5) | 24% | — | Libexpat Project LibexpatApache Http Server | 4/12/2009 | 16/6/2026 | The big2_toUtf8 function in lib/xmltok.c in libexpat in Expat 2.0.1, as used in the XML-Twig module for Perl, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with malformed UTF-8 sequences that trigger a buffer over-read, related to the doProlog function in… | |
| Modificada | Media (5) | 4.8% | 💥 Exploit | Javascript Xerver Http Server | 29/11/2009 | 16/6/2026 | CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via certain byte sequences at the end of a URL. NOTE: some of these details are obtained from third party information. | |
| Modificada | Crítica (9.8) | 87% | 💥 Exploit | Apache Http ServerGnutlsMozilla NSSOpenssl+4 | 9/11/2009 | 16/6/2026 | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and… | |
| Modificada | Media (5) | 28% | — | Libexpat Project LibexpatApache Http Server | 3/11/2009 | 20/7/2026 | The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different… | |
| Modificada | Alta (7.5) | 14% | — | Apache Http ServerApache Portable Runtime | 13/10/2009 | 16/6/2026 | The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via… | |
| Modificada | Media (5) | 14% | — | Apache Http ServerFedoraproject FedoraDebian LinuxOpensuse+3 | 8/9/2009 | 16/6/2026 | The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. | |
| Modificada | Baja (2.6) | 8.6% | — | Apache Http ServerFedoraproject FedoraDebian Linux | 8/9/2009 | 16/6/2026 | The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command. | |
| Modificada | Alta (7.1) | 17% | — | Apache Http ServerDebian LinuxFedoraproject FedoraCanonical Ubuntu Linux+5 | 10/7/2009 | 16/6/2026 | The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU consumption). | |
| Modificada | Alta (7.1) | 16% | — | Apache Http ServerFedoraproject FedoraDebian LinuxCanonical Ubuntu Linux+5 | 5/7/2009 | 16/6/2026 | The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption)… | |
| Modificada | Media (6.4) | 12% | — | Apache Apr-utilApache Http ServerCanonical Ubuntu Linux | 8/6/2009 | 16/6/2026 | Off-by-one error in the apr_brigade_vprintf function in Apache APR-util before 1.3.5 on big-endian platforms allows remote attackers to obtain sensitive information or cause a denial of service (application crash) via crafted input. | |
| Modificada | Alta (7.5) | 53% | 💥 Exploit | Apache Apr-utilApple MAC OS XSuse Linux Enterprise ServerDebian Linux+4 | 8/6/2009 | 16/6/2026 | The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav and mod_dav_svn modules in the Apache HTTP Server, allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document containing a large number of nested entity… | |
| Modificada | Media (4.3) | 8.5% | — | Apache Apr-utilApache Http Server | 8/6/2009 | 16/6/2026 | The apr_strmatch_precompile function in strmatch/apr_strmatch.c in Apache APR-util before 1.3.5 allows remote attackers to cause a denial of service (daemon crash) via crafted input involving (1) a .htaccess file used with the Apache HTTP Server, (2) the SVNMasterURI directive in the mod_dav_svn module in the Apache… | |
| Modificada | Media (4.9) | 2.0% | — | Apache Http Server | 28/5/2009 | 16/6/2026 | The Apache HTTP Server 2.2.11 and earlier 2.2 versions does not properly handle Options=IncludesNOEXEC in the AllowOverride directive, which allows local users to gain privileges by configuring (1) Options Includes, (2) Options +Includes, or (3) Options +IncludesNOEXEC in a .htaccess file, and then inserting an exec… | |
| Modificada | Media (5) | 12% | — | Apache Http ServerCanonical Ubuntu Linux | 23/4/2009 | 16/6/2026 | mod_proxy_ajp.c in the mod_proxy_ajp module in the Apache HTTP Server 2.2.11 allows remote attackers to obtain sensitive response data, intended for a client that sent an earlier POST request with no request body, via an HTTP request. | |
| Modificada | Media (4.3) | 39% | — | Apache Http ServerApple MAC OS XCanonical Ubuntu LinuxOpensuse | 6/8/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in proxy_ftp.c in the mod_proxy_ftp module in Apache 2.0.63 and earlier, and mod_proxy_ftp.c in the mod_proxy_ftp module in Apache 2.2.9 and earlier 2.2 versions, allows remote attackers to inject arbitrary web script or HTML via a wildcard in the last directory component in… | |
| Modificada | Media (4.3) | 1.1% | — | Oracle Application ServerOracle Application ServerOracle Http Server Component | 15/7/2008 | 16/6/2026 | Unspecified vulnerability in the Oracle HTTP Server component in Oracle Application Server 9.0.4.3, 10.1.2.3, and 10.1.3.3 has unknown impact and remote attack vectors. | |
| Modificada | Media (5) | 13% | — | Apache Http ServerCanonical Ubuntu LinuxFedoraproject FedoraRedhat Enterprise Linux Desktop+3 | 13/6/2008 | 16/6/2026 | The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses. | |
| Modificada | Media (4.3) | 55% | 💥 Exploit | Apache Http Server | 13/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded URLs that are not properly handled when displaying the 403 Forbidden error page. | |
| Modificada | Media (4.3) | 65% | 💥 Exploit | Apache Http ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 25/1/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary web script or HTML by uploading a file with a… | |
| Modificada | Baja (2.6) | 19% | — | Apache Http ServerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 25/1/2008 | 16/6/2026 | CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and earlier in the 2.2.x series, 2.0.61 and earlier in the 2.0.x series, and 1.3.39 and earlier in the 1.3.x series allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks… | |
| Modificada | Media (5) | 2.8% | 💥 Exploit | Miniweb Http Server | 17/1/2008 | 16/6/2026 | Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI. | |
| Modificada | Alta (7.5) | 5.4% | 💥 Exploit | Miniweb Http Server | 17/1/2008 | 16/6/2026 | Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to execute arbitrary code via a long URI. | |
| Modificada | Alta (7.8) | 3.9% | — | Apache Http Server | 12/1/2008 | 16/6/2026 | Unspecified vulnerability in mod_proxy_balancer for Apache HTTP Server 2.2.x before 2.2.7-dev, when running on Windows, allows remote attackers to trigger memory corruption via a long URL. NOTE: the vendor could not reproduce this issue |