Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
374 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 4.3% | — | Iplanet WEB Server | 23/7/2002 | 16/6/2026 | Buffer overflow in the search component for iPlanet Web Server (iWS) 4.1 and Sun ONE Web Server 6.0 allows remote attackers to execute arbitrary code via a long argument to the NS-rel-doc-name parameter. | |
| Modificada | Media (5) | 3.5% | 💥 Exploit | Goahead Software Goahead WebserverOrange Software Orange WEB ServerMontavista Software Hard HAT Linux | 23/7/2002 | 16/6/2026 | Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL with an encoded / (%5C) in a .. (dot dot) sequence. NOTE: it is highly likely that this candidate will be REJECTED because it has been reported to be a duplicate of CVE-2001-0228. | |
| Modificada | Media (5) | 9.8% | 💥 Exploit | Aprelium Technologies Abyss WEB Server | 3/7/2002 | 16/6/2026 | Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read files outside the web root, including the abyss.conf file, via URL-encoded .. (dot dot) sequences in the HTTP request. | |
| Modificada | Alta (7.2) | 0.79% | 💥 Exploit | Aprelium Technologies Abyss WEB Server | 3/7/2002 | 16/6/2026 | Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.conf file, which allows local users with access to the file to gain privileges. | |
| Modificada | Media (5) | 2.1% | — | Essentia WEB Server | 25/6/2002 | 16/6/2026 | Directory traversal vulnerability in Essentia Web Server 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in a URL. | |
| Modificada | Alta (7.5) | 9.8% | 💥 Exploit | Essentia WEB Server | 25/6/2002 | 16/6/2026 | Buffer overflow in Essentia Web Server 2.1 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long URL. | |
| Modificada | Media (5) | 2.4% | — | Blueface Falcon WEB Server | 31/5/2002 | 16/6/2026 | Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL. | |
| Modificada | Media (5) | 21% | 💥 Exploit | Cyberstop WEB Server | 16/5/2002 | 16/6/2026 | Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request, possibly triggering a buffer overflow. | |
| Modificada | Media (5) | 7.3% | 💥 PoC | Cyberstop WEB Server | 16/5/2002 | 16/6/2026 | Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service via an HTTP request for an MS-DOS device name. | |
| Modificada | Alta (7.5) | 3.3% | — | MDG Computer Services WEB Server 4D Ecommerce | 25/3/2002 | 16/6/2026 | MDG Computer Services Web Server 4D WS4D/eCommerce 3.0 and earlier, and possibly 3.5.3, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long HTTP request. | |
| Modificada | Media (5) | 2.0% | — | MDG Computer Services WEB Server 4D Ecommerce | 25/3/2002 | 16/6/2026 | MDG Computer Services Web Server 4D/eCommerce 3.5.3 allows remote attackers to exploit directory traversal vulnerability via a ../ (dot dot) containing URL-encoded slashes in the HTTP request. | |
| Modificada | Media (5) | 3.4% | 💥 Exploit | Novell WEB Server | 15/1/2002 | 28/9/2026 | Vulnerability in files.pl script in Novell WebServer Examples Toolkit 2 allows remote attackers to read arbitrary files. | |
| Modificada | Alta (7.5) | 2.4% | — | Lotus Domino WEB Server | 6/12/2001 | 16/6/2026 | Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID. | |
| Modificada | Alta (10) | 15% | 💥 Exploit | Iplanet WEB Server | 18/10/2001 | 16/6/2026 | Buffer overflow in Web Publisher in iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a request for a long URI with (1) GETPROPERTIES, (2) GETATTRIBUTENAMES, or other methods. | |
| Modificada | Alta (7.5) | 2.6% | — | Iplanet WEB Server | 18/10/2001 | 16/6/2026 | Buffer overflow in iPlanet Web Server (iWS) Enterprise Edition 4.1, service packs 3 through 7, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long method name in an HTTP request. | |
| Modificada | Media (5) | 2.2% | — | HP VirtualvaultSUN Iplanet WEB Server | 22/8/2001 | 16/6/2026 | Vulnerability in iPlanet Web Server 4.X in HP-UX 11.04 (VVOS) with VirtualVault A.04.00 allows a remote attacker to create a denial of service via the HTTPS service. | |
| Modificada | Media (5) | 11% | 💥 Exploit | T. Hauck Jana WEB Server | 14/8/2001 | 16/6/2026 | T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack which is URL encoded (%2e%2e). | |
| Modificada | Media (5) | 7.3% | 💥 Exploit | T. Hauck Jana WEB Server | 14/8/2001 | 16/6/2026 | T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request which includes a MS-DOS device name (i.e. GET /aux HTTP/1.0). | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | Orange Software Orange WEB Server | 6/8/2001 | 16/6/2026 | Orange Web Server 2.1, based on GoAhead, allows a remote attacker to perform a denial of service via an HTTP GET request that does not include the HTTP version. | |
| Modificada | Alta (10) | 1.5% | — | Iplanet WEB Server | 2/7/2001 | 16/6/2026 | Vulnerability in iPlanet Web Server Enterprise Edition 4.x. | |
| Modificada | Media (5) | 3.1% | — | Iplanet WEB Server | 2/7/2001 | 16/6/2026 | iPlanet Web Server Enterprise Edition 4.1 and earlier allows remote attackers to retrieve sensitive data from memory allocation pools, or cause a denial of service, via a URL-encoded Host: header in the HTTP request, which reveals memory in the Location: header that is returned by the server. | |
| Modificada | Media (5) | 2.3% | — | Netcruiser Software Netcruiser WEB Server | 27/6/2001 | 16/6/2026 | Netcruiser Web server version 0.1.2.8 and earlier allows remote attackers to determine the physical path of the server via a URL containing (1) con, (2) com2, or (3) com3. | |
| Modificada | Media (5) | 3.6% | 💥 Exploit | Spencer Christensen Perl WEB Server | 27/6/2001 | 16/6/2026 | Directory traversal vulnerability in Perl web server 0.3 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URL. | |
| Modificada | Media (5) | 0.97% | — | Iplanet WEB Server | 11/6/2001 | 16/6/2026 | Vulnerability in iPlanet Web Server 4 included in Virtualvault Operating System (VVOS) 4.0 running HP-UX 11.04 could allow attackers to corrupt data. | |
| Modificada | Media (5) | 2.4% | — | Free Java WEB Server | 3/5/2001 | 16/6/2026 | Directory traversal vulnerability in Free Java Web Server 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack. |