Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
722 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.20% | — | Symantec Encryption DesktopSymantec PGP Desktop | 21/6/2014 | 17/6/2026 | Symantec PGP Desktop 10.x, and Encryption Desktop Professional 10.3.x before 10.3.2 MP2, on OS X uses world-writable permissions for temporary files, which allows local users to bypass intended restrictions on file reading, modification, creation, and permission changes via unspecified vectors. | |
| Modificada | Baja (2.3) | 1.7% | — | Symantec WEB Gateway | 18/6/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the management console in Symantec Web Gateway (SWG) before 5.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified report parameters. | |
| Modificada | Media (5.8) | 2.0% | — | Symantec WEB Gateway | 18/6/2014 | 17/6/2026 | SQL injection vulnerability in clientreport.php in the management console in Symantec Web Gateway (SWG) before 5.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (5.2) | 1.4% | — | Symantec WEB Gateway | 18/6/2014 | 17/6/2026 | SQL injection vulnerability in user.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Crítica (9.8) | 7.0% | — | Symantec WEB Gateway | 18/6/2014 | 16/6/2026 | SNMPConfig.php in the management console in Symantec Web Gateway (SWG) before 5.2.1 allows remote attackers to execute arbitrary commands via unspecified vectors. | |
| Modificada | Alta (7.9) | 42% | 💥 Exploit | Symantec Workspace Streaming | 16/5/2014 | 17/6/2026 | The server in Symantec Workspace Streaming (SWS) before 7.5.0.749 allows remote attackers to access files and functionality by sending a crafted XMLRPC request over HTTPS. | |
| Modificada | Alta (7.6) | 2.4% | — | Broadcom Symantec Critical System Protection | 8/5/2014 | 16/6/2026 | Symantec Critical System Protection (SCSP) before 5.2.9, when installed on an unpatched Windows Server 2003 R2 platform, allows remote attackers to bypass policy settings via unspecified vectors. | |
| Modificada | Baja (2.6) | 0.71% | — | Symantec PGP DesktopSymantec Encryption Desktop | 23/4/2014 | 17/6/2026 | Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform block-data moves, which allows remote attackers to cause a denial of service (read access violation and application crash) via a malformed certificate. | |
| Modificada | Baja (2.6) | 0.71% | — | Symantec Encryption DesktopSymantec PGP Desktop | 23/4/2014 | 17/6/2026 | Symantec PGP Desktop 10.0.x through 10.2.x and Encryption Desktop Professional 10.3.x before 10.3.2 MP1 do not properly perform memory copies, which allows remote attackers to cause a denial of service (read access violation and application crash) via a malformed certificate. | |
| Modificada | Media (4.3) | 2.1% | — | Symantec Messaging Gateway | 23/4/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in brightmail/setting/compliance/DlpConnectFlow$view.flo in the management console in Symantec Messaging Gateway 10.x before 10.5.2 allows remote attackers to inject arbitrary web script or HTML via the displayTab parameter. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | OpensslFilezilla-project Filezilla ServerSiemens Application Processing Engine FirmwareSiemens CP 1543-1 Firmware+24 | 7/4/2014 | 17/6/2026 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to… | |
| Modificada | Alta (7.5) | 1.4% | — | Symantec Liveupdate Administrator | 29/3/2014 | 17/6/2026 | SQL injection vulnerability in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.7% | — | Symantec Liveupdate Administrator | 29/3/2014 | 17/6/2026 | The forgotten-password feature in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to reset arbitrary passwords by providing the e-mail address associated with a user account. | |
| Modificada | Media (6.5) | 29% | 💥 Exploit | Symantec Endpoint Protection ManagerSymantec Protection Center | 14/2/2014 | 16/6/2026 | SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows remote authenticated users to execute arbitrary SQL commands via… | |
| Modificada | Alta (7.5) | 68% | 💥 Exploit | Symantec Endpoint Protection ManagerSymantec Protection Center | 14/2/2014 | 16/6/2026 | The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows remote attackers to read arbitrary files via XML data containing an external entity declaration in… | |
| Modificada | Media (4.3) | 2.0% | — | Symantec WEB Gateway | 11/2/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote attackers to inject arbitrary web script or HTML via (1) vectors involving PHP scripts and (2) unspecified other vectors. | |
| Modificada | Media (6.5) | 1.5% | — | Symantec WEB Gateway | 11/2/2014 | 16/6/2026 | Multiple SQL injection vulnerabilities in the management console on the Symantec Web Gateway (SWG) appliance before 5.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4) | 0.75% | — | Symantec Encryption Management Server | 7/2/2014 | 17/6/2026 | The Web Email Protection component in Symantec Encryption Management Server (aka PGP Universal Server) before 3.3.2 allows remote authenticated users to read the stored outbound e-mail messages of arbitrary users via a modified URL. | |
| Modificada | Alta (7.2) | 0.47% | — | Symantec Endpoint Protection | 10/1/2014 | 16/6/2026 | Unquoted Windows search path vulnerability in the client in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 allows local users to gain privileges via a crafted program in the %SYSTEMDRIVE% directory. | |
| Modificada | Media (4.6) | 0.35% | — | Symantec Endpoint Protection | 10/1/2014 | 16/6/2026 | The Application/Device Control (ADC) component in the client in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 does not properly handle custom polices, which allows local users to bypass intended policy… | |
| Modificada | Alta (7.4) | 0.78% | — | Symantec Endpoint Protection | 10/1/2014 | 16/6/2026 | The Management Console in Symantec Endpoint Protection (SEP) 11.x before 11.0.7.4 and 12.x before 12.1.2 RU2 and Endpoint Protection Small Business Edition 12.x before 12.1.2 RU2 does not properly perform authentication, which allows remote authenticated users to gain privileges by leveraging access to a limited-admin… | |
| Modificada | Media (4.6) | 0.22% | — | Symantec Management Platform | 10/10/2013 | 16/6/2026 | The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used in certain Altiris products, use the same registry-entry encryption key across different customers' installations, which makes it easier for local users to obtain sensitive information about… | |
| Modificada | Media (6.6) | 1.0% | 💥 Exploit | Symantec Workspace Virtualization | 5/8/2013 | 16/6/2026 | Symantec Workspace Virtualization before 6.x before 6.4.1953.0, when a virtual application layer is configured, allows local users to gain privileges via an application that performs crafted interaction with the operating system. | |
| Modificada | Media (4.3) | 0.32% | — | Symantec Backup Exec | 5/8/2013 | 16/6/2026 | Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 uses weak permissions (Everyone: Read and Everyone: Change) for backup data files, which allows local users to obtain sensitive information or modify the outcome of a restore via direct access to these files. | |
| Modificada | Baja (2.7) | 0.54% | — | Symantec Backup Exec | 5/8/2013 | 16/6/2026 | The NDMP protocol implementation in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allows remote authenticated users to obtain sensitive host-version information via unspecified vectors. |